Skip to content

Cyber intelligence · 3 September 2026

Cyber intelligence to anticipate decisions, not merely threats

Intelligence is what changes a decision this week. A feed of alerts that nobody uses is noise with a letterhead.

By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.

Original text in Spanish. Read the original Spanish version

Six-stage cyber-intelligence flow: signal, context, scenario, decision, action and review

In Latin America a great deal of threat information is bought and few anticipated decisions are taken. The problem is not a scarcity of data. It is a scarcity of questions. Cyber intelligence that does not change a decision is internal journalism with worse prose.

A framework of my own: from signal to review

I use a short cycle. It is not a standard. It is a discipline so that the report fits on a page a CEO can use:

  1. Signal: what was observed, where it comes from and with what confidence.
  2. Context: what it means for this organisation, not for “the sector” in the abstract.
  3. Scenario: what may happen if the signal is true, and what happens if it is not.
  4. Decision: which option is enabled now —accept, mitigate, transfer, rehearse, wait.
  5. Action: who does what, before when, with what evidence of closure.
  6. Review: what we learned and what we should stop measuring.

Three uses that do justify the budget

  • Prioritise: which asset, which supplier and which process deserve attention this week, not this year.
  • Anticipate: which campaigns are being rehearsed against industry peers and what would need to be rehearsed internally.
  • Explain: translate an adversary’s move into business impact, so that the board does not have to learn jargon.

Anonymised example

A services organisation receives, in one week, three distinct signals: a critical supplier appears in a credentials market; an industry peer reports ransomware with the same remote-access vector; and an employee pastes a contract into a public AI model. No signal, alone, justifies a crisis committee. Together, they change the week’s decision: the supplier’s access is rotated, restoration of the process that supplier supports is rehearsed, and an honest inventory of Shadow AI is opened. The product was not a 40-page report. It was a dated decision.

Indicators a leader can in fact request

  • Number of signals that ended in a decision, not number of alerts received.
  • Time between the signal and the first option presented to the person who decides.
  • Critical suppliers with a recent signal and no continuity rehearsal.
  • Reports that ended in “there is no useful signal this week” —informed silence counts.

Common errors

  • Collecting indicators of compromise as if they were strategy.
  • Theatricalising distant threats to justify budget.
  • Delivering reports that the board cannot repeat in a sentence.
  • Confusing volume of sources with quality of question.
  • Hiding uncertainty. A dated “we do not know” is more useful than a decorative certainty.

Realistic frequency, not theatrical. Comparison with peers. Relation to the risks the board itself already approved. That is the cyber intelligence a board can govern.

References

  • NIST SP 800-150: Guide to Cyber Threat Information Sharing. NIST. Accessed: 2026-09-04. El artículo usa el marco de compartir información de amenaza para distinguir inteligencia útil para decidir de la acumulación de indicadores. No presenta el SP 800-150 como obligación ni como aval del autor.

Related articles

Crises do not book an appointment. Preparation can start today.