CTI Wednesdays Vol. 1: The Requirements-Driven Approach
Introduction to Cyber Threat Intelligence
Cyber Threat Intelligence (CTI) is the systematic study of adversary capabilities, intent, motivations, and opportunities. It identifies the specific Tactics, Techniques, and Procedures (TTPs) utilized by threat actors to achieve objectives. As a proactive risk reduction methodology, CTI enables an organization to optimize resource allocation by identifying and mitigating high-probability threats before detonation. The discipline integrates diverse data streams, including Open Source Intelligence (OSINT), social media intelligence (SOCMINT), Human Intelligence (HUMINT), technical telemetry, and primary threat research.
Standard industry frameworks define the CTI lifecycle through a linear progression of planning, collection, processing, analysis, dissemination, and feedback. While this provides a high-level conceptual model, the traditional lifecycle often fails to address the specific operational requirements of a threat intelligence analyst. At Bluewave Cyberdefense, we reject the generic lifecycle in favor of a requirements-driven approach. This methodology ensures that intelligence operations are dictated by specific organizational needs rather than the passive consumption of generalized threat data.
The Requirements-Driven Approach
The standard CTI lifecycle remains an abstraction that fails to define the functional mechanics of intelligence production. A requirements-driven approach replaces passive data consumption with the fulfillment of tangible organizational objectives. This methodology ensures that intelligence is both actionable and relevant, providing stakeholders with the data necessary for informed decision-making. CTI programs lacking clear direction often produce high-quality reports that function only as academic reading; they fail to deliver measurable results or influence the organization’s security posture. By centering operations on specific requirements, the CTI function transitions from an interesting internal news feed to a critical component of risk management.

Stakeholders and the Threat Profile
Stakeholders are the primary drivers of a mature CTI program. A stakeholder is any individual or group within the organization whose operational success is influenced by CTI output. Consistent engagement with stakeholders is mandatory to align intelligence products with their specific expectations and decision-making cycles.
The CTI team must identify and document the intelligence use cases for each stakeholder group to ensure the delivery of timely and relevant data.
| Stakeholder | Intelligence Use Case |
| CISO / Executive Leadership | Strategic intelligence to justify security investments, manage organizational risk, and align cyber strategy with business objectives. |
| Incident Response (IR) | Contextual data on adversary TTPs to facilitate the thorough eradication of threat actors during and after a compromise. |
| Threat Hunting | Technical intelligence regarding the specific behaviors of actors targeting the organization to drive proactive, hypothesis-based investigations. |
| Vulnerability Management | Prioritization of patching efforts based on evidence of active exploitation or the availability of functional proof-of-concept (PoC) code. |
| Red Teaming | Adversary emulation based on the organization’s threat profile to test defensive controls and identify architectural weaknesses. |
| GRC (Governance, Risk, Compliance) | Industry-specific threat landscape analysis to assess regulatory impact and ensure risk-appropriate security controls. |
| Security Architecture | Identification of high-probability target zones within the network to guide “Secure by Design” infrastructure hardening. |
Parallel to stakeholder engagement, the team must establish the organization’s Threat Profile. This involves identifying and analyzing the specific threat actors, campaigns, and TTPs that statistically target the organization’s specific industry, sector, and geographic footprint. The threat profile limits the scope of intelligence collection to the most probable and impactful risks, preventing resource exhaustion on irrelevant data.
Stage 1: Strategic Planning and Requirements
The primary objective of the initial phase is the identification, development, and implementation of core CTI requirements. This step is the most critical component of the intelligence cycle, as it aligns all subsequent technical activity with leadership directives and business needs.
The Cyber Threat Profile
Within the first cycle, the CTI team must establish a Cyber Threat Profile. This profile evolves alongside the organization’s infrastructure and the shifting global threat landscape. It serves as the baseline for what constitutes a relevant threat, ensuring that the team ignores noise and focuses on high-impact adversaries.
Stakeholder Assessment and Consumption
To provide actionable intelligence, the CTI team must conduct an assessment of how stakeholders consume intelligence products. This assessment must be performed at least annually to verify that the CTI program’s output remains aligned with stakeholder requirements.
-
Growth and Adaptation: As the organization scales, the team must identify new or modified use cases for existing stakeholders.
-
Service Integration: Following analysis, the CTI team determines if these new requirements can be absorbed into existing services or if the development of new intelligence products is required.
-
Traceability: Every use case and intelligence requirement must trace back to a specific business or operational need.
Strategic, Operational, and Tactical Alignment
A mature CTI program manages and responds to threats across three distinct levels of utility. The ability to influence outcomes at all three levels simultaneously is a primary metric for measuring program maturity.
| Level | Focus and Objective | Deliverables |
| Strategic | Long-term planning and risk management. Informs senior leadership on global trends to guide policy and resource allocation. | High-level risk assessments, industry trend reports, white papers. |
| Operational | Support for specific defensive campaigns. Provides context on adversary infrastructure and behavior to assist SOC and IR functions. | Campaign analysis, actor profiles, TTP mapping (MITRE ATT&CK). |
| Tactical | Immediate threat mitigation and detection. Focuses on real-time support for security operations to block or identify active attacks. | Technical indicators, attack patterns, detection signatures (YARA/Sigma). |
Standardizing these definitions within the organization is mandatory to prevent cross-departmental confusion and to ensure that intelligence products meet the specific expectations of their intended audience.
Upcoming: Capability Building
In the next entry of this series, we will examine Capability Building, the functional bridge between planning and execution. This phase, which we will detail in our next blog, covers the procurement of data sources, CTI architecture engineering, and the integration of specialized toolsets required to actualize intelligence requirements.
CTI Architecture and Execution
The next installment will break down how CTI architecture provides the technical infrastructure and automated workflows necessary to normalize raw telemetry into actionable products.
-
Architecture Strategy: Establishing the structured environments required for the collection and analysis of diverse data types.
-
Automation: Implementing the workforce automation capabilities needed to standardize formats for efficient dissemination.
Data and Resource Procurement
We will also explore how the capability building phase ensures the CTI team possesses the specific data access and skills required to support identified service lines.
-
Source Identification: Defining the collection mechanisms for internal telemetry and external feeds to support tactical cycles.
-
Integration: Engineering the pipelines that support immediate response while maintaining data integrity for long-term strategic analysis.
Strategic Partnerships and Service Offerings
Bluewave Cyberdefense provides the infrastructure and expertise required to transition from generic security monitoring to a requirements-driven CTI posture.
Insurance and Sector Intelligence
Through a strategic partnership with PCFG Insurance Services, Bluewave gains a broad, cross-sector perspective on active claims and emerging attack vectors. This partnership enhances our CTI program by:
-
Sector-Wide Visibility: Utilizing anonymized data from insurance claims to identify trends across various industries and geographic regions.
-
Enhanced Risk Assessment: Integrating actuarial-level risk data into our CTI threat profiles to provide clients with a more accurate understanding of their financial and operational exposure.
Identity Threat Detection and Response (ITDR)
Bluewave has launched an ITDR service powered by Vectra. This capability focuses on the most critical component of modern intrusions: Identity.
-
Behavioral Baselining: Monitoring for account anomalies and deviations from established user patterns to identify credential theft in real-time.
-
Identity Monitoring: Continuous surveillance of account permissions and privilege escalations to prevent lateral movement.
Managed CTI Services
The Vectra CTI Platform is currently under development as a dedicated software solution, but is immediately available as a managed service.
-
Company-Specific Intelligence: We perform targeted monitoring for intelligence relevant to your specific domain, infrastructure, and personnel.
-
Proactive Threat Analysis: Providing human-led analysis of external threats to ensure that defensive controls are updated before an adversary targets the organization.
Conclusion
A CTI program is only as effective as the requirements that drive it. By prioritizing the needs of stakeholders and establishing a robust threat profile during the planning phase, organizations can move away from reactive, tool-centric security. Next week, we will provide a technical deep-dive into the capability building phase, focusing on the engineering of intelligence pipelines and the specific data types required to support a modern CTI architecture.