What is CTI?

By Krassimir Tzvetanov
Monday, September 28, 2026

Cyber Threat Intelligence (CTI) has become a well-established part of the cybersecurity industry. Yet, ask ten practitioners to define CTI and you may still receive ten different answers.

Some will describe threat feeds. Others will point to malware analysis, indicators of compromise, threat actor tracking, vulnerability intelligence, or reports on nation-state activity. All of these can be components of CTI, but none of them individually define the field.

This problem is not entirely surprising. CTI did not emerge as a branch of the traditional intelligence profession. It grew largely from incident response and information security, borrowing concepts and terminology from government and military intelligence along the way. As the commercial market expanded, vendors introduced their own terminology, methodologies, and definitions. The result has been a field that has matured considerably in capability while still lacking consistency in how we describe what we do.

Our new white paper, What Is Cyber Threat Intelligence? Defining the Field, Its Disciplines, and Its Intelligence Cycle, attempts to establish a clearer foundation.

At its core, CTI is not a feed, a report, or a collection of indicators. It is a process.

The FIRST CTI SIG defines Cyber Threat Intelligence as the systematic collection, analysis, and dissemination of information pertaining to a company's operations in cyberspace and, to an extent, physical space, designed to inform decision makers at all levels. This definition highlights several important characteristics. CTI exists to support decisions. It serves consumers at the strategic, operational, and tactical levels. Most importantly, intelligence is created through a process that transforms raw data into information and ultimately into an intelligence product.

The paper also proposes an important distinction between CTI disciplines and functional roles. Disciplines describe bodies of knowledge, skills, and methods, including network analysis, system analysis, malware analysis, threat data processing, digital forensics, document and media exploitation, and others. Functional roles describe how those capabilities are applied organizationally and legally. This distinction becomes particularly important in cyberspace because the same technical capability may be legitimate or unlawful depending upon authorization and context.

Perhaps the most important observation, however, concerns where we currently spend our time. Much of today's commercial CTI effort remains concentrated in processing and exploitation rather than analysis. We have become exceptionally good at ingesting feeds, extracting indicators, normalizing formats, enriching records, deduplicating data, and moving enormous quantities of information between systems. These are necessary functions, but they are not themselves the analytical process that turns information into intelligence.

This distinction becomes even more important as automation, machine learning, and LLM-based systems become increasingly integrated into CTI workflows. Automation is particularly well suited to processing and exploitation. Analysis, however, requires structured reasoning, evaluation of evidence, consideration of alternative hypotheses, assessment of source reliability, and disciplined communication of uncertainty.

Moving CTI forward therefore requires more than better tools. It requires a common vocabulary, consistent analyst training, structured analytic methods, and a clear understanding of where automation ends and analytical judgment begins.

The goal of this white paper is not simply to provide another definition of CTI. It is to establish a common framework for discussing the field, its disciplines, its practitioners, and the process through which information becomes intelligence.

If we cannot agree on what Cyber Threat Intelligence is, it becomes very difficult to agree on how to teach it, practice it, measure it, or improve it. You can download the white paper here.