Module 3: Types of Intelligence

Strategic, Operational, and Tactical CTI

Learn the difference between high-level trends and ground-level technical indicators.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Identify which type of intelligence is most appropriate for a given audience.

Strategic, Operational, and Tactical CTI

Understanding the different audiences and purposes for CTI.

One Size Does Not Fit All

When you are producing intelligence, knowing your audience is everything. If you hand a CISO a list of malicious IP addresses, they won’t know what to do with it. If you hand a Security Operations Center (SOC) analyst a 50-page report on the geopolitical motivations of a nation-state actor, they will be equally frustrated.

To solve this, Cyber Threat Intelligence is generally described at three decision levels:

  1. Strategic Intelligence
  2. Operational Intelligence
  3. Tactical Intelligence

Let’s break down what each of these means and who consumes them.

The Three Levels of CTI

Strategic Intelligence is the “big picture.” It focuses on broad trends, financial impacts, and long-term risks. It asks questions like, “Are threat actors targeting our industry more this year than last year?” or “How does a new data privacy law affect our risk exposure?”

  • Audience: Executives, the Board of Directors, CISOs, and other high-level decision-makers.
  • Format: Whitepapers, executive summaries, risk assessments, and briefings.

Operational Intelligence zooms in a bit closer. It focuses on the specific capabilities, infrastructure, and campaigns of threat actors. It asks questions like, “What vulnerabilities is this specific ransomware group currently exploiting?” or “What techniques do they use to move laterally inside a network?”

  • Audience: Security managers, incident response leads, and threat hunters.
  • Format: Adversary profiles, campaign reports, and threat models.

Tactical Intelligence is ground-level data. It is highly technical and highly actionable, often with a very short lifespan. This is the realm of Indicators of Compromise (IoCs) - the specific IP addresses, domain names, file hashes, and registry keys associated with a threat.

  • Audience: Security Operations Center (SOC) analysts, firewall administrators, and automated security tools (SIEMs, SOARs).
  • Format: Data feeds (like STIX/TAXII), YARA rules, and alert signatures.