How to Build a Cyber Threat Intelligence Collection Plan in 2026

How do you make your intelligence requirements actionable? How do you go from broad questions about threats to operational tasks your cyber threat intelligence team can complete? You need an intelligence collection plan.

An intelligence collection plan is a systematic approach to tracking your intelligence requirements, the data sources that support your team in fulfilling them, and the daily tasks that lead to their completion. It is a key piece of documentation that all cyber threat intelligence teams require to move from the planning stage to the collection stage of the threat intelligence lifecycle.

This guide will teach you how to build an intelligence collection plan. It will start by highlighting the key features a collection plan must include, show you a four-step process for creating it, and conclude with advice on building a collection Wiki to support your strategy.

Let’s jump in and start making your intelligence requirements actionable!

Want to listen on the go? Check out this article in podcast form!


What is an Intelligence Collection Plan?

Intelligence requirements should drive all the intelligence you produce for your organization. They are the foundations on which you build all your cyber threat intelligence (CTI) work and are the output on which your success is measured.

That’s great. I need intelligence requirements. But what are the practical steps to doing this?

This is where a collection plan comes in. Collection planning is the process of systematically tracking your intelligence requirements, breaking them down into actionable Request for Information (RFI) tasks, and mapping these tasks to data sources that can be used to answer them.

Your collection plan is the key piece of documentation created through collection planning, outlining how you plan to fulfill your intelligence requirements. A CTI team’s collection plan answers several key questions:

  • What are the intelligence requirements the team has been tasked with fulfilling?
  • What individual tasks must the team complete to support the fulfillment of an intelligence requirement?
  • What is each intelligence requirement’s cut-off date for when it’s no longer useful (ICOD)?
  • What data sources are available to the team?
  • What data sources can be used to fulfill each intelligence requirement?
  • What are the team’s key data sources (most heavily relied on)?
  • What potential intelligence gaps exist where a data source does not support an intelligence requirement?

An Intelligence Cut-Off Date (ICOD) is the point at which the intelligence produced is no longer helpful to the intelligence consumer. For instance, if a stakeholder needs to be aware of ransomware trends for their 2026 report, an ICOD could be January 2027, before the report is finalized and released.

A collection plan is a type of Collection Management Framework (CMF). A CMF is used to map informational needs to the available data sources. Typically, you list your informational need on the y-axis and the available data sources on the x-axis. Then, you fill in the information (or characteristics of that information) that each data source can use to query.

Internal Collection Management Framework (CMF)

This helps analysts know what questions they can ask of their data sources and the characteristics of this information (e.g., retention period). Using this knowledge, analysts can utilize CMFs as a reference when answering investigative questions, responding to incidents, or conducting threat hunting.

There are various kinds of CMFs, from those that focus on internal data to those that focus on external data sources. A cyber security team may use multiple CMFs during an investigation. The CTI team’s CMF is a collection plan.

PIRRFIDeliverableICODSIEMEDRDark Web MonitoringThreat Feed
PIR 1PIR 1.1Weekly report <date> Yes Yes No Yes
 PIR 1.2Threat feed N/A No No Yes No
PIR 2PIR 2.1Custom dashboard <date> No No Yes Yes
 PIR 2.2One-off report <date> Yes Yes No No
PIR 3PIR 3.1Daily Slack message N/A Yes No No Yes
 PIR 3.2One off report <date> Yes Yes Yes No

You can create your intelligence collection plan using various types of software. Here are some popular options:

  • Spreadsheets: A simple and easy-to-use solution. The biggest challenge is making it available to everyone in a readable format. Examples include Excel or Google Sheets.
  • Threat Intelligence Platforms: These are great for linking your intelligence requirements to specific threat events, activities, or investigations. However, there is often a learning curve. Examples are OpenCTI or MISP.
  • Project Management Software: This is ideal for larger teams that share their collection plan with multiple people. Again, it can allow you to link requirements to specific intelligence activities, but it requires additional learning. Examples include Jira, Notion, or ClickUp
  • Custom Databases: Perhaps overkill for creating a collection plan, but by far the most customizable solution. Custom databases provide the flexibility to edit, modify, and share requirements as needed. They are not recommended unless you have development experience or a lot of free time.

Regardless of what tool you use to create your intelligence collection plan, it must be available to everyone on your CTI team and the stakeholders whose intelligence requirements you fulfill. This availability provides your CTI team with a clear understanding of the big picture and ensures stakeholder expectations are aligned with intelligence tasking.

Now you know what an intelligence collection plan is, let’s explore how to create one!


How to Create an Intelligence Collection Plan

Creating an intelligence collection plan is not an intellectually rigorous task like some CTI processes. Instead, strong organizational skills are required to gather intelligence requirements and data sources and create RFIs that connect the two.

You can create a collection plan in 4 steps:

  1. Define Priority Intelligence Requirements (PIRs)
  2. Identify data sources
  3. Translate PIRs into RFIs
  4. Put it all together into an intelligence collection plan
Creating an Intelligence Collection Plan in 4 Steps

Let’s walk through these steps to see how to apply them practically.

Step 1: Defining Priority Intelligence Requirements

The first step to creating an intelligence collection plan is defining your Priority Intelligence Requirements (PIRs).

When you start the planning stage of the CTI lifecycle, you must establish the information needs of your organization and create a list of intelligence requirements that will satisfy these needs. These requirements are the foundation for all your CTI work, from threat intelligence collection to analysis to dissemination.

There are various methods you can use to create these intelligence requirements:

Unfortunately, not all intelligence requirements you generate will be feasible. Your CTI team will often lack the ability or resources to fulfill every intelligence requirement that could benefit your business. As such, you must prioritize these intelligence requirements to build a list of PIRs your team can realistically accomplish.

Common methods for turning your intelligence requirements into PIRs include:

  • MoSCoW: The easiest prioritization method to use. You split your requirements into Must-haves, Should-haves, Could-haves, and Won’t-haves based on business needs and return on investment (ROI). Implementing it can be challenging when multiple stakeholders are involved.
  • A RACI Matrix: A popular tool project managers and consultants use to clarify the roles and responsibilities of completing a project or making a decision. This is good for when multiple stakeholders are involved in the intelligence requirements generation process and all want a say in what becomes a PIR.
  • Aggregating, Scoring, and Ranking: Data analysis techniques to fairly “voice” every stakeholder’s opinion based on their level of involvement in the intelligence product. This is the most comprehensive method for creating PIRs, but it is also the most time-consuming.

Using one (or all) of these methods will produce a list of achievable PIRs you can add to your intelligence collection plan.

PIRRFIICOD<data source><data source><data source><data source>
PIR 1PIR 1.1     
 PIR 1.2     
PIR 2PIR 2.1     
 PIR 2.2     
PIR 3PIR 3.1     
 PIR 3.2     

Next, identify the available data sources that will help you fulfill these requirements.

Step 2: Identifying Data Sources

Step two focuses on identifying your data sources. This could range from Endpoint Detection and Response (EDR) tools to threat intelligence gathered from the dark web.

To provide some structure for this identification process, you can break down your data sources into several categories:

  • Technical: Data collected from a technical control (e.g., log). This includes the technical aspects of cyber threats, such as malware, exploits, hacking tools, attacker infrastructure (domains and IP addresses), and TTPs.
  • Human: Information collected from a human source. This could include a cybercriminal on the dark web or someone within your organization (e.g., the IT team providing you with a list of user roles).
  • Open: Data that is freely available. This includes intelligence from open-source CTI feeds or news sites, as well as data that can be collected from the organization (e.g., logs).
  • Closed: Sources behind a paywall or ones with restrictions on who can access them. These could be proprietary threat feeds or restricted cybercrime forums. Access to these data tends to be harder to achieve or more volatile.

These four categories should help you determine what data sources are available to you as a CTI analyst. Here is an example of some data sources that might be available.

 TechnicalHuman
OpenOS logs
Authentication logs
Mail transactions
Cloud activity logs
Antivirus logs
Zeek logs
VPN access logs
Web proxy logs
EDR logs
Open-source threat feed
User Roles
Assets Roles
Installed Applications
ClosedProprietary threat feed (malware)
Proprietary threat feed (network indicators)
Private message group access (Signal)
Private cybercrime forum

With a list of available data sources, you can begin to categorize them to make your intelligence collection plan more manageable. For instance, if your organization has centralized logging, you can group many “logs” identified under SIEM. You can group threat intelligence into categories based on the type of information it provides (e.g., endpoint indicator threat feed, network indicator threat feed, friendly intelligence, dark web intelligence, etc.).

Once grouped, you can add your data sources to your intelligence collection plan

PIRRFIICODSIEMEDRDark Web MonitoringThreat Feed
PIR 1PIR 1.1     
 PIR 1.2     
PIR 2PIR 2.1     
 PIR 2.2     
PIR 3PIR 3.1     
 PIR 3.2     

The next step is to make your PIRs actionable by breaking them down into RFIs.

Step 3: Translate PIRs into RFIs

Now that you have your PIRs and data sources in your intelligence collection plan, you need to move into the operational world of CTI and define the day-to-day tasks to ensure the PIRs are fulfilled.

You do this by breaking down your PIRs into actionable tasks that your CTI can complete. These tasks are called Request for Information (RFIs) and are what you will undertake daily as a CTI analyst. Each PIR comprises one or more RFIs, depending on the scope of the requirement and the number of questions necessary to fully encapsulate it.

For instance, a PIR may ask: “Which Russian nation-state sponsored APT groups will likely target the organisation?” You could further break this question into several PIRs, such as:

  • What Russian APTs are currently actively targeting our organization’s industry?
  • What Russian APTs are targeting our demographic?
  • What are the capabilities of these Russian APT groups?
  • What are the likely objectives of their attacks?
  • What socio-economic factors would change Russian APTs targeting our organization?
  • What political factors would change Russian APTs targeting our organization?
  • Are there relevant technological trends that may impact Russian APTs targeting our organization?
  • How do Russian APT groups establish targeting patterns?
  • Are there any regulatory changes in our jurisdiction that may impact the Russian state’s APTs targeting us?

You can use techniques like PESTLE analysis to help you break down PIRs into RFIs. This environmental scanning technique provides a framework for assessing the Political, Economic, Social, Technological, Legal, and Environmental factors affecting a PIR. Performing this technique enables you to engage in divergent thinking and more effectively assess how to address the PIR thoroughly.

For example, using the previously stated PIR “Which Russian nation-state sponsored APT groups will likely target the organisation?”, you can use the six PESTLE categories to break down this question further.

PoliticalEconomicSocialTechnologicalEnvironmentalLegal
What political factors would change Russian APTs targeting our organization?What socio-economic factors change Russian APTs targeting our organization? What are the capabilities of these Russian APTs groups?What Russian APTs are targeting our demographic?Are there any regulatory changes in our jurisdiction that may impact the Russian state’s APTs targeting us?
How do Russian APT groups establish targeting patterns?    What are the likely objectives of their attacks?What Russian APTs currently actively target our organization’s industry? 
   Are there relevant technological trends that may impact Russian APTs targeting our organization?  

Here I have mapped our questions into the six PESTLE categories. These individual questions can then be transformed into RFIs that help you fulfill the original PIR.

PIRRFIs
Which Russian nation-state sponsored APT groups will likely target the organisation?What changes to the political objectives of the Putin regime would change Russian APTs targeting our organization?
 How do Russian APT groups establish targeting patterns under the current administration?
 What are the capabilities of these Russian APTs groups?
 What are the likely objectives of their attacks?
 How will the rise of AI over the next five years impact Russian APTs targeting our organization?
 What Russian APTs are targeting the UK healthcare sector?
 How will recent changes to GDPR impact Russian APTs targeting our organization?

Notice how some questions have been combined while others have been made more specific as they are turned into RFIs. Your RFIs should follow the same success criteria as your intelligence requirements: singular, atomic, decision-centric, and timely.

This structured approach enables you to develop detailed questions that remain relevant to the overall PIR, allowing you to conduct in-depth research. It also gives you a good idea of the overall intelligence effort to fulfill a certain PIR.

In addition, each RFI will have an ICOD that the RFI must be completed before, so the intelligence produced remains relevant. This leads to the two types of RFIs you might see:

  • Standing RFIs: These are tied to an organization’s standing areas of concern that don’t often change. They are ongoing and only stop if a significant change happens. As they are performed daily, these RFIs may not have an applicable ICOD.
  • Non-standing RFIs: These RFIs have a defined beginning and end, including an ICOD by which they must be completed to remain relevant.
PIRRFIICODSIEMEDRDark Web MonitoringThreat Feed
1.1) Which Russian nation-state sponsored APT groups will likely target the organisation?”1.2) What changes to the political objectives of the Putin regime would change Russian APTs targeting our organization?<date>    
 1.3) How do Russian APT groups establish targeting patterns under the current administration?N/A    
 1.3) What are the capabilities of these Russian APTs groups?N/A    
 1.4) What are the likely objectives of their attacks?<date>    
 1.5) How will the rise of AI over the next five years impact Russian APTs targeting our organization?<date>    
 1.6) What Russian APTs are targeting the UK healthcare sector?N/A    
 1.7) How will recent changes to GDPR impact Russian APTs targeting our organization?<date>    
 1.8) What changes to the political objectives of the Putin regime would change Russian APTs targeting our organization?N/A    
PIR 2PIR 2.1     
 PIR 2.2     
PIR 3PIR 3.1     
 PIR 3.2     

You now have all the pieces to create your intelligence collection plan. Let’s see how you can assemble them by mapping RFIs to data sources.

Step 4: Putting it all Together

The final step in creating an intelligence collection plan is mapping the RFIs you have identified to the data sources that can be used to answer them.

In theory, this is a simple step. You select a ‘yes’ or ‘no’ answer next to the data source under which the RFI falls. However, to do this accurately, you must be able to interpret the listed data source and understand the questions you can ask of it.

These are key cognitive skills analysts must master to use a data source effectively. They can be broken into two components:

  • Interpretation: The ability to interpret the data and understand what relationships it represents.
  • Capability Comprehension: Knowing what questions can be asked of a data source (e.g., what searchable items does this data source provide?)

These are not the only skills an analyst must master to utilize a data source. They must also be able to collect the data and manipulate it to produce the answer to their question. These are both technical skills that analysts perform.

In addition to mapping your RFI to a data source, you must map your RFI to an intelligence deliverable that will satisfy its completion.

This could be as simple as a daily update in a Slack channel, a weekly report emailed to the SOC, or a monthly presentation delivered to executives. However, it could also be part of a more tactical approach, such as building a threat profile, investigating executives’ digital footprints, maintaining a threat feed, or creating a custom dashboard.

How you decide on your intelligence deliverables will depend on the target audience, agreed-upon cadence, and underlying goal of the RFI.

Once you fully understand the data sources available to you, the relationships they represent, and what questions you can ask of them, you map each of your RFIs to each data source and add the deliverable(s) that will be produced. Here is what that might look like.

PIRRFIDeliverableICODSIEMEDRDark Web MonitoringThreat Feed
1.1) Which Russian nation-state sponsored APT groups will likely target the organisation?”1.2) What changes to the political objectives of the Putin regime would change Russian APTs targeting our organization?One-off report<date>NoNoYesYes
 1.3) How do Russian APTs groups establish targeting patterns under the current administration?One-off reportN/ANoNoYesYes
 1.3) What are the capabilities of these Russian APTs groups?Monthly reportN/AYesYesYesYes
 1.4) What are the likely objectives of their attacks?Quarterly report<date>YesYesYesYes
 1.5) How will the rise of AI over the next five years impact Russian APTs targeting our organization?One-off report<date>NoNoYesYes
 1.6) What Russian APTs are targeting the UK healthcare sector?Threat feed and dashboard in threat intelligence platformN/ANoNoYesYes
 1.7) How will recent changes to GDPR impact Russian APTs targeting our organization?Annual report<date>NoNoYesNo
 1.8) What changes to the political objectives of the Putin regime would change Russian APTs targeting our organization?One-off reportN/ANoNoYesYes
PIR 2PIR 2.1<date>    
 PIR 2.2<date>    
 PIR 2.3<date>    
PIR 3PIR 3.1<date>    
 PIR 3.2<date>    

There you have it! A complete intelligence collection plan template that your CTI team can use to begin fulfilling the intelligence requirements you’ve been tasked with completing. Obviously, yours will be much larger in real life.

To take things one step further, let’s examine how you can create an intelligence collection Wiki to complement your collection plan, ensuring that your CTI analysts don’t need to recall how to use every data source you have.


Building a Threat Intelligence Collection Wiki for Your Collection Plan

A threat intelligence collection Wiki is a knowledge base that explains how analysts can effectively use each data source listed in your collection plan. It provides detailed guidance on the data sources analysts can use to answer their RFIs by addressing key investigative questions they may have.

You can break your threat intelligence collection Wiki into three sections:

  1. Data Source Reference: A section that references your data sources. This includes questions you can ask, such as how to access it, how it is created, how long it is retained, what coverage exists, what fields are available, and any miscellaneous notes about its implementation within your organization.
  2. Most Searched Fields: This focuses on where else you can learn more about a certain piece of evidence. For instance, what data sources contain the “username” field? This provides analysts with pivot points to expand their research or investigation.
  3. Data Acquisition Appendix: This section provides information on what analysts can access and where it is stored, enabling them to understand the data they have to work with. This can save a significant amount of time when conducting research or during an investigation.

Aim to create a threat intelligence collection Wiki to support your collection plan and make both easily accessible to your CTI team. This documentation will save you countless hours when performing CTI work.


Conclusion

An intelligence collection plan is a systematic approach to tracking your intelligence requirements, the data sources that empower your team to meet them, and the daily tasks that contribute to their fulfillment.

It is a crucial piece of documentation that all cyber threat intelligence teams need to traverse the threat intelligence lifecycle and move from the planning stage to the collection stage.

This guide has taught you the importance of having a comprehensive collection plan, how to create one in four simple steps, and how to build an intelligence collection Wiki to support your collection plan. Using this knowledge, you can now create a collection plan for your organization and start making your intelligence requirements actionable!

Frequently Asked Questions

How Do You Write an Intelligence Collection Plan?

An intelligence collection plan is a key piece of documentation for your organization’s cyber threat intelligence team. You can create an intelligence collection plan using four simple steps:

  1. Define Priority Intelligence Requirements (PIRs): You must turn your intelligence requirements into PIRs by prioritizing the most mission-critical ones your team can fulfill.
  2. Identify data sources: Locate all available data sources to investigate cyber threats and add them to your collection plan.
  3. Translate PIRs into RFIs: Break down your PIRs into actionable Request for Information (RFI) tasks that your cyber threat intelligence team can complete daily.
  4. Put it all together: Map your RFI’s to the data sources that will aid your team in completing them. This lets your team quickly research or investigate their RFI tasks and fulfill PIRs.
How is Cyber Threat Intelligence Collected?

Cyber threat intelligence (CTI) can be collected in various ways, depending on available data sources. You can break data sources into internal and external sources (e.g., internal to your organization or external and held by someone else) and technical and human sources (e.g., data gathered from technical sources or collected from humans).

Cyber security and CTI teams often use Collection Management Frameworks (CMFs) to help organize their data sources and map out the investigative questions they can answer. One form of CMF is an intelligence collection plan.

What is a Threat Intelligence Wiki?

A threat intelligence wiki (or collection wiki) is a knowledge base that contains all the data sources available within your organization, along with instructions on how to utilize them. It includes information on how to access the data source, its creation process, retention period, available coverage, queryable fields, and any additional notes specific to your organization’s implementation.

The wiki serves as a shortcut for analysts to quickly look up their data sources and understand how to utilize them effectively. It is a time-saver during investigations or research.

What is a Collection Management Plan?

An intelligence collection management plan, or collection plan, is a document that includes your cyber threat intelligence team’s Priority Intelligence Requirements (PIRs) and your organization’s data sources that aid in fulfilling these requirements. PIRs are mapped to data sources through Request for Information (RFI) tasks, which convert PIRs into actionable activities at the operational level.

This document formalizes the processes for PIRs, RFIs, and the data sources available to the cyber threat intelligence team. It also acts as a guide for producing intelligence products that can be shared with key stakeholders.

What is an OSINT Collection Plan?

An OSINT Collection Plan is a systematic strategy that guides the gathering of information from publicly available sources to address specific intelligence requirements. It outlines what information is needed (e.g., threat actor TTPs, potential vulnerabilities), identifies the relevant sources to monitor (like dark web forums, social media, or code repositories), and specifies the tools and methods that will be used for collection. This structured approach ensures that the collection efforts are focused, efficient, and directly support the threat intelligence requirements.

What are Cyber Threat Intelligence Requirements?

Cyber Threat Intelligence (CTI) Requirements are specific questions posed by an organization’s stakeholders to guide the intelligence team’s research and analysis efforts. These requirements focus the team on investigating threats, vulnerabilities, and threat actors that are most relevant to the organization’s specific assets, industry, and strategic goals. By answering these priority questions, the team produces tailored, actionable intelligence that helps leaders make informed security decisions, rather than simply providing generic threat data.