Interview question
You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days?
A senior question that separates people who would start by buying a feed from people who would start by asking who the customer is.
What a strong answer covers
- Starts with stakeholders and requirements, not with tooling or feeds.
- Identifies who the consumers are and what decisions they actually make.
- Establishes the organisation's own threat model — sector, geography, crown jewels, exposure.
- Audits existing telemetry and visibility before buying anything external.
- Delivers something useful early to build credibility rather than disappearing for a quarter.
- Defers tooling and feed procurement until requirements justify a specific gap.
- Sets up a feedback mechanism so requirements can be refined.
Expert answer
The first thirty days are conversations, not tooling. I would identify who the consumers are — SOC lead, IR, detection engineering, the CISO, and whoever owns risk — and ask each of them what decisions they are making that better information would improve. That produces a draft set of intelligence requirements. Most first CTI hires skip this and start by evaluating feeds, which is how you end up producing reports nobody reads.
In parallel I would build the organisation's own threat picture: what sector and geography we are in, what an attacker would actually want here, what is internet-facing, and what the crown jewels are. Intelligence that is not scoped to this organisation is just news.
The second thirty days are about visibility. What telemetry do we have, what retention, and where are the blind spots? This matters because it determines what I can actually assess. It also tends to produce the first genuinely valuable finding, which is usually a gap nobody had articulated.
Alongside that I would want one early deliverable — a short profile of the two or three intrusion sets most relevant to our sector, mapped to ATT&CK, with the hunt hypotheses and detection gaps that fall out of it. Small, useful, and it gives stakeholders something concrete to react to, which sharpens the requirements far faster than another round of interviews.
The last thirty days are about making it repeatable: a standing reporting rhythm pitched at the right audiences, a feedback loop so I find out what was used, and only now a view on whether a commercial feed or a platform fills a gap I can actually name. Buying tooling before you can state the requirement it satisfies is the classic failure.
Mistakes that cost candidates points
- Starting with feed or platform procurement.
- Never mentioning stakeholders or requirements.
- Planning ninety days of research with no deliverable until the end.
- Ignoring internal telemetry in favour of external sources.
- No feedback mechanism, so requirements never improve.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide?
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle?
- What is cyber threat intelligence, and how is it different from a threat feed?