Cyber intelligence · 3 September 2026
Cyber intelligence to anticipate decisions, not merely threats
Intelligence is what changes a decision this week. A feed of alerts that nobody uses is noise with a letterhead.
By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.
Original text in Spanish. Read the original Spanish version

In Latin America a great deal of threat information is bought and few anticipated decisions are taken. The problem is not a scarcity of data. It is a scarcity of questions. Cyber intelligence that does not change a decision is internal journalism with worse prose.
A framework of my own: from signal to review
I use a short cycle. It is not a standard. It is a discipline so that the report fits on a page a CEO can use:
- Signal: what was observed, where it comes from and with what confidence.
- Context: what it means for this organisation, not for “the sector” in the abstract.
- Scenario: what may happen if the signal is true, and what happens if it is not.
- Decision: which option is enabled now —accept, mitigate, transfer, rehearse, wait.
- Action: who does what, before when, with what evidence of closure.
- Review: what we learned and what we should stop measuring.
Three uses that do justify the budget
- Prioritise: which asset, which supplier and which process deserve attention this week, not this year.
- Anticipate: which campaigns are being rehearsed against industry peers and what would need to be rehearsed internally.
- Explain: translate an adversary’s move into business impact, so that the board does not have to learn jargon.
Anonymised example
A services organisation receives, in one week, three distinct signals: a critical supplier appears in a credentials market; an industry peer reports ransomware with the same remote-access vector; and an employee pastes a contract into a public AI model. No signal, alone, justifies a crisis committee. Together, they change the week’s decision: the supplier’s access is rotated, restoration of the process that supplier supports is rehearsed, and an honest inventory of Shadow AI is opened. The product was not a 40-page report. It was a dated decision.
Indicators a leader can in fact request
- Number of signals that ended in a decision, not number of alerts received.
- Time between the signal and the first option presented to the person who decides.
- Critical suppliers with a recent signal and no continuity rehearsal.
- Reports that ended in “there is no useful signal this week” —informed silence counts.
Common errors
- Collecting indicators of compromise as if they were strategy.
- Theatricalising distant threats to justify budget.
- Delivering reports that the board cannot repeat in a sentence.
- Confusing volume of sources with quality of question.
- Hiding uncertainty. A dated “we do not know” is more useful than a decorative certainty.
Realistic frequency, not theatrical. Comparison with peers. Relation to the risks the board itself already approved. That is the cyber intelligence a board can govern.
References
- NIST SP 800-150: Guide to Cyber Threat Information Sharing. NIST. Accessed: 2026-09-04. El artículo usa el marco de compartir información de amenaza para distinguir inteligencia útil para decidir de la acumulación de indicadores. No presenta el SP 800-150 como obligación ni como aval del autor.