Interview question
What is cyber threat intelligence, and how is it different from a threat feed?
Almost every CTI interview opens here. The question looks trivial and is not — it is checking whether you understand that intelligence is defined by process and purpose, not by data.
What a strong answer covers
- Intelligence is data that has been collected against a requirement, evaluated, analysed and delivered to support a decision.
- A feed is raw or lightly enriched data with no requirement behind it and no assessment attached.
- The defining elements are a consumer, a decision, and an analytic judgement — not volume or freshness.
- Names the intelligence cycle or an equivalent process: direction, collection, processing, analysis, dissemination, feedback.
- Distinguishes the tactical, operational and strategic levels, and notes that the audience differs at each.
- Notes that intelligence carries confidence and sourcing; a feed does not.
Expert answer
Cyber threat intelligence is information that has been collected against a defined requirement, evaluated for reliability, analysed, and delivered to a specific consumer so they can make a better decision. The distinguishing features are the requirement it answers, the analytic judgement attached to it, and the confidence and sourcing that come with that judgement.
A threat feed is data — indicators, often with some enrichment. It has no requirement behind it, makes no assessment, and is not aimed at anyone in particular. It can be an input to intelligence, but on its own it is not intelligence, which is why organisations that buy several feeds and no analysis are usually disappointed.
The practical test is whether someone can act on it. A list of IP addresses tells a SOC to block things; an assessment that a particular intrusion set is targeting your sector through edge appliances, at moderate confidence, tells a security leader what to prioritise and why.
It is also worth separating the levels. Tactical intelligence serves the SOC and detection engineering and has a shelf life of days. Operational intelligence serves incident response and hunting and describes campaigns and TTPs over months. Strategic intelligence serves leadership and describes the threat landscape and risk over quarters. Job descriptions often blur these, and knowing which one a role means is a useful thing to establish early.
Mistakes that cost candidates points
- Defining intelligence as "information about threats" without mentioning requirements, analysis or a consumer.
- Treating IOCs as the deliverable, which signals indicator thinking.
- Confusing intelligence with incident response or with vulnerability management.
- Reciting the intelligence cycle as a list without explaining what it is for.
- Not distinguishing tactical, operational and strategic.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- Why do you want to work in threat intelligence rather than another security discipline?
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?