Interview question
Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
A definitional question that becomes diagnostic the moment you are asked for examples — most candidates produce three tactical examples.
What a strong answer covers
- Tactical: serves the SOC and detection engineering, concerns indicators and specific behaviours, shelf life of days to weeks.
- Operational: serves IR, hunting and security management, concerns campaigns, intrusion sets and TTPs, shelf life of months.
- Strategic: serves leadership and risk, concerns landscape, intent, capability trends and sector risk, shelf life of quarters to years.
- Gives a genuinely distinct example at each level rather than three variations of an indicator list.
- Identifies the audience at each level, not just the content.
- Notes that a common failure is producing one level for an audience that needs another.
Expert answer
The levels differ by audience, content and shelf life.
Tactical intelligence serves the SOC and detection engineering. It is concerned with specific observables and behaviours — the command line pattern a loader uses, the URI structure of a C2 protocol, a set of indicators with context on how they were obtained. Its shelf life is days to weeks because the underlying artefacts are cheap for the adversary to change. Example: a note to detection engineering describing how a particular loader establishes persistence, which telemetry would reveal it, and the benign software that would produce false positives.
Operational intelligence serves incident response, threat hunting and security management. It is concerned with campaigns and intrusion sets — how a particular actor operates across an intrusion, what they tend to do after initial access, which sectors they are hitting. Shelf life is months, because tradecraft changes more slowly than infrastructure. Example: a profile of an intrusion set targeting your sector, mapped to ATT&CK, with the hunt hypotheses it generates.
Strategic intelligence serves leadership, risk and the board. It is concerned with the landscape: who is likely to target this organisation and why, how capability is trending, what regulatory or geopolitical shifts change the picture. Shelf life is quarters to years. Example: an assessment that ransomware operators are increasingly targeting the organisation's sector through third-party suppliers, and what that implies for the supplier assurance programme and its budget.
The most common failure in practice is mismatching level to audience — sending an indicator list to a CFO, or sending a general statement about an elevated threat environment to engineers who needed a query.
Mistakes that cost candidates points
- Giving three examples that are all really tactical.
- Defining the levels by how technical they are rather than by audience and decision.
- Omitting shelf life, which is what makes the distinction operationally useful.
- Treating strategic intelligence as "executive summaries of tactical reporting".
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide?
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days?
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle?
- What is cyber threat intelligence, and how is it different from a threat feed?