Interview question
What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
The second half is the real question. Anyone can list sources; the interviewer wants to know whether you read them critically.
What a strong answer covers
- Names categories of source rather than only brands: own telemetry, government advisories, vendor research, sharing communities, independent researchers.
- Applies reliability and credibility as separate judgements.
- Judges a report on whether it shows its evidence, not on the reputation of the publisher.
- Identifies circular reporting — several outlets citing one original source is one source.
- Notes the commercial incentive vendors have to publish and to emphasise novelty.
- Distinguishes what the report observed from what it concluded.
Expert answer
On sources, the useful answer describes a spread rather than a brand list: your own telemetry first because it is the only thing scoped to your environment, national CERT and government advisories, vendor research teams, sector sharing communities, and a handful of independent researchers.
On believing a report, the test is what evidence it shows. A report that publishes its observables, explains how it collected them, and separates what it saw from what it concluded can be evaluated. One that asserts an attribution without showing the reasoning can only be trusted or not, which is a much weaker position.
I grade the source and the claim separately. Source reliability is a track-record judgement — has this team been right before, do they show their working, do they correct themselves. Credibility is about this specific claim — is it corroborated by genuinely independent reporting, and is it internally consistent. A very reliable vendor can publish a claim nobody else can corroborate, and that combination should lower confidence even though the source is good.
The failure to watch for is circular reporting. Four articles referencing a claim, three of which cite the fourth, is one source. So is two vendors who both draw on the same telemetry partner. I trace claims back to the earliest publication that presents original evidence.
I also read for incentive. Vendors publish partly to demonstrate capability, which biases toward novelty and toward "sophisticated" framing. That does not make the technical content wrong, but it does mean the emphasis is not neutral.
Mistakes that cost candidates points
- Listing vendor names with no criteria for evaluating them.
- Treating brand reputation as a substitute for evidence.
- Missing circular reporting entirely.
- Grading reliability and credibility as one judgement.
- Not mentioning own telemetry as a source at all.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response.
- Explain the Admiralty source grading scale. How would you grade a well-regarded vendor's report making a claim that no other source has corroborated?
- Four separate publications report the same breach claim. How do you decide whether that counts as corroboration?
- What is cyber threat intelligence, and how is it different from a threat feed?
- Why do you want to work in threat intelligence rather than another security discipline?