Evaluate intelligence for relevance and confidence.
Connect indicators to defensive action.
Choose metrics that reflect risk reduction rather than activity alone.
Threat intelligence can describe actors, techniques, indicators, vulnerabilities, and campaigns. An indicator without context has limited value; assess source reliability, freshness, confidence, affected technology, and actionability. Map useful intelligence to controls, detections, blocking, hunting, or awareness.
Metrics should support decisions. Counting blocked events can encourage noise; measuring remediation age, control coverage, detection quality, and recovery performance better reflects enterprise risk. Report trends, thresholds, uncertainty, and outcomes.
Exercises
Evaluate three intelligence reports.
Map one technique to prevention and detection.
Replace vanity metrics with risk-relevant measures.
Self-check
What makes intelligence actionable?
Why freshness matters?
What does MTTR measure?
Self-Check Quiz
1. Is an IP address alone proof of malicious activity?
AnswerNo. It needs context, confidence, time, behavior, and affected assets.
2. Why measure control outcomes?
AnswerActivity counts do not show whether exposure or recovery capability improved; outcome measures support better decisions.
Homework
Design a threat-intelligence workflow for an enterprise SOC.
Define six risk-relevant metrics.
Explain one metric's limitation.
Sample answerIngest relevant, fresh intelligence, validate it, map techniques to detections and controls, assign owners, and retire stale indicators. Metrics may include critical vulnerability age, MFA coverage, MTTD, MTTR, privileged review completion, and restore-test success; each needs scope and interpretation.