skip to content

What distinguishes strategic, operational and tactical threat intelligence products, and who is each one written for?

level: juniorimportance: must knowfreq 68%

answer

  1. three readers, not three depths
  2. executive, incident lead, detection engineer
  3. horizon: quarters, weeks, days
  4. the decision picks the tier

basics

~20 s

They differ by reader and time horizon. Strategic products tell executives how the threat picture is shifting so they can fund decisions. Operational products tell an incident lead about a specific campaign. Tactical products give defenders the behaviours and artefacts to detect.

solid answer

~50 s

The three tiers are the same finding written for three different readers who take three different decisions. A **strategic** product is for executives and risk owners: it says how the threat picture has changed and what that means for money and priority — for example, that extortion crews hitting retail have stopped encrypting systems and now steal data and threaten to publish, so the loss lands on disclosure rather than on downtime. An **operational** product is for the incident lead and SOC manager: which campaign, which of our assets it goes after, what the crew does once inside, and what we must be ready to do. A **tactical** product is for the detection engineer and hunter: the specific behaviours, technique identifiers and artefacts to write rules and hunts against. The tiers also differ in shelf life — a strategic judgement holds for quarters, a hostname holds for days.

go deeper

for a junior

Be ready to name all three tiers, the reader of each, and one example of what each contains. Interviewers ask this as a screener for any intelligence-facing role, so have a concrete finding you can split three ways.

for a middle

Explain why the tiers exist rather than listing them: different readers hold different decision authority, and artefacts and judgements decay at completely different rates. Mention the four-tier variant that splits technical from tactical and say what the split buys.

for a senior

Show you pick the tier from the decision, not from the material. Be able to say what you deliberately leave out of each product and why, and what changes in an incident playbook when an operational product lands.

for a principal

Own the question of which tiers your team should publish at all. A team producing tactical output nobody consumes, or strategic output no risk owner has asked for, is spending analyst time on documents rather than decisions.

## The tiers are readers, not difficulty levels The most common mistake with this model is to read it as a scale of technical depth — strategic meaning vague, tactical meaning detailed. That is not what it is. **Each tier is defined by the reader and the decision that reader is about to take.** The depth follows from the decision; it is not the thing being graded. A worked case makes it concrete. Suppose you have three pieces of input: a peer retailer's public disclosure, a sector letter from your regulator, and two of your own closed cases from the last year. Read together they support one judgement: **an extortion crew targeting retailers has abandoned encryption entirely and now works by exfiltrating data and threatening to publish it.** That single judgement becomes three different artefacts. ### Strategic **Reader:** the executive, the divisional VP, the board risk committee, the risk owner who controls a budget line. **What it says:** the shape of the risk has changed. Previously the loss model was downtime and recovery, and the controls that mattered were backups and restore speed. Now the loss model is disclosure of customer and commercial data, and the controls that matter are knowing what sits on the file shares, who can reach it, and whether large volumes leaving would be noticed. It ends with a recommendation an owner can act on, with a rough cost and a date. **Horizon:** quarters to years. The judgement survives a change of tooling on either side. ### Operational **Reader:** the incident response lead, the SOC manager, the person who owns the playbook. **What it says:** this crew, this campaign, against assets of this kind. How they typically get in, how long they sit, what they collect, how they make contact. Crucially, what it changes about our readiness — here, that the incident does not end when systems are restored, because there was nothing to restore; the incident ends only when you can say what left and can argue the crew has no path back. **Horizon:** weeks to months. It tracks a campaign, and campaigns end. ### Tactical **Reader:** the detection engineer, the threat hunter, the analyst working a queue. **What it says:** the observable behaviours and artefacts. Staging data into an archive before upload, the file-transfer utilities the crew brings with it, unusual breadth of access to a file share by a single account, and the artefacts that go with them — named technique identifiers such as `T1560` for archiving collected data are the durable half, hostnames and hashes the perishable half. It is written as a list, not as prose, because its reader turns it into rules and hunts. **Horizon:** the behaviours last months; the artefacts may be dead within days of publication. ## Some frameworks split four ways You will meet a four-tier version that separates **technical** intelligence — atomic artefacts such as addresses, hashes and hostnames — from **tactical** intelligence meaning behaviour and technique. Both models are in circulation. In an interview, name the three tiers, then say that some organisations split the fourth out, and be able to say why the split exists: artefacts and behaviours decay at wildly different rates, so treating them as one product means the whole thing goes stale at the speed of its shortest-lived line. ## The test that decides the tier Ask: **what decision does the reader take after reading this, and do they have the authority to take it?** Fund a control programme is strategic. Change a playbook or stand up readiness for a specific campaign is operational. Write a rule or run a hunt is tactical. If you cannot name the decision, you have not chosen a tier yet — you have written a summary of your research, which is a fourth thing and nobody's product. ## Where candidates lose the question The answer that fails is the one that describes the tiers as long, medium and short documents. The answer that succeeds names the reader, the decision and the shelf life for each, and can take one finding and say out loud what each of the three versions would contain. Interviewers ask this early because everything else in intelligence writing — leading with the judgement, naming an action, deciding what to leave out — depends on knowing who is on the other side of the page.

  • Where does a list of the crew's hostnames and file hashes fit in that scheme?
    At the tactical end, and it is the shortest-lived thing you will publish — an artefact an adversary can change in an afternoon. It belongs in a list for the detection engineer, with the behaviour it evidences stated alongside it, because the behaviour is what still holds when the hostnames are dead.
  • Does a strategic product need technical detail at all?
    Enough to show the judgement is grounded — one or two concrete cases, briefly — and no more. The body of a strategic product is the implication and the recommended decision. The technical detail lives in the tactical companion, and pointing to it is better than pasting it in, because the executive cannot act on it and it costs you the page.

The same weather finding becomes a shipping forecast, a flight plan and a decision to cancel the harbour festival — one observation, three readers, three different actions.

saying these in an interview costs you the question

  • Treats the tiers as difficulty levels rather than different readers
  • Sends the board a table of indicators of compromise
  • Claims tactical intelligence has the longest useful life
  • Cannot name the decision each reader takes
  • Describes strategic intelligence as simply a shorter version of the technical report

context