How to Generate Strategic Intelligence by Answering 20 Questions

In the fast-paced world of cyber threat intelligence, it’s easy to get lost in the weeds of tactical data, chasing indicators with a shelf life measured in hours. While essential for immediate defense, you miss the big picture – patterns, trends, and an adversary’s ultimate objectives. How do you move from simply reacting to threats to anticipating them? The answer lies in mastering strategic intelligence. 

Generating strategic intelligence is what separates a good analyst from a great one, but creating it can feel like a daunting, unstructured art. 

This guide provides the framework you’ve been missing. We will break down the process into 20 fundamental questions that will guide you from initial planning to final delivery, helping you create impactful strategic intelligence that senior leaders will actually use. Let’s get started!

Want to listen on the go? Check out this article in podcast form!


What is Strategic Intelligence?

Before we dive into the questions, let’s clarify what we mean by strategic intelligence. 

Unlike its tactical and operational counterparts, strategic intelligence offers a high-level, forward-looking perspective on the threat landscape. It’s less about a specific indicator of compromise (IOC)  and more about understanding the “who,” “why,” and “what’s next.”

It shifts the focus from the server room to the boardroom, answering questions that impact the entire organization’s future.

For example, strategic intelligence connects cyber threats to broader geopolitical events, showing how international sanctions might drive a nation-state to sponsor corporate espionage. It links them to economic trends, explaining how a recession could fuel a rise in specific types of financially motivated cybercrime. And it ties them directly to an organization’s specific risks, assessing the threat landscape in a new market the company plans to enter.

Think of it as the difference between knowing a single soldier’s location (tactical), understanding their platoon’s immediate mission (operational), and grasping the entire army’s campaign strategy (strategic). 

The goal of strategic intelligence isn’t just to block an IP address; it’s to inform long-term, high-stakes business decisions. It guides cyber security investments by answering whether it’s more critical to fund insider threat programs or operational technology defenses based on a multi-year threat forecast. 

Ultimately, it helps executive leadership anticipate future challenges and opportunities, turning cyber threat intelligence (CTI) into a business enabler. 

Strategic Intelligence as Business Enabler

Strategic intelligence is often the most challenging type of intelligence to produce; it deals with ambiguity and requires a rare blend of deep technical expertise, business acumen, and geopolitical awareness, all underpinned by a rigorous analytic process that cannot be automated.

To help you get started, let’s focus on the 20 most important questions a CTI analyst must answer when generating strategic intelligence. Use these as guidelines when creating strategic intelligence.


20 Questions for Creating Strategic Intelligence

Creating robust strategic intelligence is not a simple task of reporting facts; it’s a dynamic journey of inquiry. This process requires you to constantly question, probe, and refine your understanding as you move from ambiguity to clarity. 

These 20 questions, adapted from the foundational work Critical Thinking for Strategic Intelligence by Randolph Pherson, provide a much-needed roadmap for that journey. 

Without a structured path, it’s easy to get lost in the vast sea of information or fall prey to cognitive biases that lead to flawed conclusions. This framework breaks the complex process into four logical and sequential phases, ensuring a rigorous and methodical approach: Getting Started, Gathering Information, Creating an Argument, and Sharing Your Message. 

Strategic Intelligence Four Categories of Questions

Each phase builds upon the last, guiding you from the initial spark of a question to a polished, impactful final product that can inform critical decisions.

Getting Started

This initial phase is about laying a solid foundation for your entire analytic endeavor. It is the deliberate, upfront work of defining the “who, what, and why” of your analysis before you write a single sentence or review a single piece of data. 

Strategic Intelligence Getting Started

Rushing this stage is a common and seductive mistake, often driven by the pressure of tight deadlines. The consequence is almost always unfocused and irrelevant analysis.

The time spent here—clarifying requirements, understanding the audience, and framing the key question—pays enormous dividends later, preventing costly rewrites and wasted hours down research rabbit holes. 

It’s about aiming before you fire; a hunter who fires into the woods without a target wastes ammunition, and an analyst who begins without a clear objective will produce a report that makes a lot of noise but hits no target. Answer these questions before anything else.

Q1: Who is the Intelligence Consumer?

This is the most critical question, the one that anchors your entire effort. Your analysis, no matter how brilliant, is useless if it doesn’t serve the needs of its intended audience. 

You must go beyond a job title and understand the world your consumer lives in. Are you writing for a CISO, a CEO, or a board of directors? Each has different responsibilities, pressures, and levels of technical expertise.

  • A CISO focuses on operational resilience and risk management, assessing threats to prioritize defenses with questions like, “How does this threat affect our security posture and what do we need to do about it?” 
  • A CEO concentrates on strategic growth and competitiveness, asking, “How does this threat affect our business strategy?” 
  • The Board oversees governance, financial risk, and shareholder value, seeking assurance on cyber risk management with the question, “Are we prepared for the most significant cyber threats to our company’s value?”

Understanding your intelligence consumer means empathizing with their challenges. This is the first and most crucial step to creating relevant strategic intelligence that drives action, not just fills an inbox.

Q2: What Questions Are You Answering?

A well-crafted analysis answers a single, primary question. Vague requests like “tell me everything about threat actor X” are a recipe for failure, leading to sprawling, unfocused reports. 

Your job is to collaborate with your stakeholders to refine broad queries into precise, actionable intelligence questions. A good question is relevant, timely, and answerable in more than one way.

For example, a stakeholder might ask, “What’s the deal with this new ransomware group?” A good analyst will translate that into a series of focused questions:

  • “Which industries is this group primarily targeting, and do we fit their profile?”
  • “What is their typical time from initial access to ransomware deployment, and what does that mean for our incident response timeline?”
  • “Based on their TTPs, which of our security controls are most likely to be effective, and where are our biggest gaps?”

Instead of “What are Russian hackers doing?” a better question is, “How are Russian-sponsored threat actors likely to adapt their tactics to target the financial sector in the next 12 months, and what are the key indicators we should monitor for this shift?” 

This process of refining the question ensures your final product is a sharp, focused answer, not a vague data dump. It is here that your intelligence requirements will be created and refined.

Q3: What is the Broader Context?

No threat exists in a vacuum. You must understand the operational environment surrounding your issue, which means looking beyond the cyber domain. What are the political, economic, social, and technological (PEST) factors at play?

  • Political: A new international conflict could signal a shift in nation-state targeting priorities. New regulations on data privacy could change how cybercriminals operate.
  • Economic: A global recession might lead to an increase in insider threats as employees face financial pressure. A boom in a particular sector could make it a more attractive target.
  • Social: A major social movement could spawn a wave of hacktivism targeting corporations perceived to be on the “wrong” side of the issue.
  • Technological: The rapid adoption of AI could arm both attackers and defenders with new capabilities, fundamentally changing the nature of cyber conflict.

Understanding this context prevents you from “cherry-picking” data and reaching flawed conclusions. It allows you to see the “why” behind the “what,” which is the essence of strategic analysis. For more on this, check out our guide to IPCE and PESTLE analysis.

Q4: How Should I Deliver My Product?

The format and cadence of your deliverable matter immensely. A brilliant 30-page report is worthless if your consumer only has time to read a one-page summary. 

Does your CISO prefer a concise one-page memo, a detailed report, or a 15-minute weekly briefing?

The President’s Daily Brief, for example, is famously tailored to the specific information-processing preferences of each president, from the level of detail to the use of graphics.

Knowing whether your audience prefers paragraphs or bullets, graphics or text, is crucial. But it’s also about timing. A quarterly strategic outlook is valuable for budget planning, while an ad-hoc threat briefing is necessary during a crisis.

To understand these nuances, establishing a feedback loop is vital. Ask your consumers what works and what doesn’t, and be prepared to adapt. This iterative process ensures your intelligence remains relevant and impactful.

Q5: What is My Analytic Approach?

How will you get from a question to an answer? Your approach depends on your goal. It’s helpful to think in terms of an analytic spectrum:

  • Descriptive analysis: What is happening? (e.g., “This new malware variant has these specific capabilities.”)
  • Explanatory analysis: Why is it happening? (e.g., “This malware was likely developed to steal intellectual property from aerospace firms.”)
  • Evaluative analysis: What is the significance? (e.g., “The capabilities of this malware pose a high risk to our R&D network.”)
  • Estimative analysis: What happens next? (e.g., “We assess this threat actor will likely use this malware to target our competitors in the next six months.”)

Strategic intelligence is almost always estimative. It requires you to move beyond reporting known facts to forecasting future trends and scenarios. 

Strategic Intelligence as a Crystal Ball

Your underlying objective is to help your organization prepare for what’s over the horizon.

Q6: Are There Opportunities for Collaboration?

You are not an island, and a single analyst rarely solves complex strategic problems alone. 

Collaboration enhances analysis by bringing in diverse perspectives and expertise, acting as a powerful safeguard against individual biases. Reach out to individuals within your CTI team and other teams across the business:

  • The geopolitical analyst can provide context on nation-state motives.
  • The fraud team can offer insights into the financial TTPs of cybercriminals.
  • The network defender working in the SOC can validate hypotheses about an actor’s on-network behavior.
  • The legal team can explain the regulatory implications of a data breach.

Even a quick, informal brainstorming session can uncover risks, assumptions, and opportunities you might have missed on your own. Effective collaboration turns a good analysis into a great one!

Gathering Information

Having established a solid plan, you are now ready to transition from the controlled environment of planning into the dynamic and often chaotic collection and evaluation phases.

This stage is far more than a simple data-gathering exercise; it is an active process of intellectual foraging and critical vetting. 

  • Intellectual foraging requires you to hunt creatively, looking beyond your usual feeds to find nuggets of insight in adversary forums or obscure technical blogs. 
  • Critical vetting is the essential counterpart, where the consequences of failure can be severe—wasted resources on false leads or flawed intelligence that misinforms leadership. 
Strategic Intelligence Gathering Information

The primary goal is therefore twofold: to systematically hunt for the information needed to answer your core question and, just as importantly, to rigorously assess the quality, relevance, and potential biases of every piece of data you find. Having an intelligence collection plan to do this is vital!

Here are some questions to consider during this phase.

Q7: What Analytic Technique Should I Use?

Structured Analytic Techniques (SATs) are essential for mitigating cognitive bias and adding rigor to your analysis. They are the mental frameworks that prevent you from jumping to conclusions. 

The technique you choose depends on your challenge:

  • Are you trying to generate new ideas? Use a brainstorming technique like Starbursting, which focuses on generating questions rather than answers. 
  • Do you need to evaluate competing explanations for an event? Use Analysis of Competing Hypotheses (ACH) to weigh the evidence for and against each possibility systematically. 

These techniques are the bedrock of sound analysis, transforming your intuition into a defensible assessment. For a guide on what technique to use and when, read this Quick Wins for Busy Analysts.

Q8: What Information is Available?

This question forces you to map out your knowledge and your ignorance. 

  • What do you know for a fact? 
  • What do you know that you don’t know (your “known unknowns”)? 
  • And most importantly, what don’t you know you don’t know (your “unknown unknowns”)? 

Start by surveying your existing knowledge and internal data—incident reports, network logs, previous assessments. Then, hunt for external information to fill the gaps. 

This could involve open-source research, vendor reports, or information from sharing communities (ISACs). Understanding the different data collection methods is crucial to building a comprehensive picture.

Q9: Can I Trust the Data Source?

Not all sources are created equal. You must critically evaluate the credibility of every piece of information before it enters your analysis. Who created it? Why? Do they have a vested interest or bias?

A technical report from a trusted security vendor with a long history of accurate reporting is fundamentally different from an anonymous post on a hacking forum. 

Assessing source reliability and information credibility is a fundamental skill that involves checking the source’s track record, their access to the information, and their potential motives.

Q10: How Can I Assess Information Reliability?

Beyond the source, you must assess the information itself. 

  • Is it tangible evidence (like a malware sample you can reverse engineer) or testimonial evidence (like a human source report, which is subject to interpretation and memory)? 
  • Crucially, is it corroborated by other independent sources?

Be especially wary of single-source reporting for critical judgments. A common trap in open-source intelligence is “circular reporting,” where multiple news outlets all cite the same single, unverified source, creating a false illusion of corroboration. 

Always ask: could this be deception or disinformation designed to mislead me?

Creating an Argument

After gathering and vetting your information, you enter the synthesis phase. Analysis isn’t just a collection of interesting facts; it’s the art and science of weaving those facts into a coherent and logical argument that leads to an insightful conclusion.

This is what provides the crucial “so what” that decision-makers need to act. A list of indicators is just data; an argument explaining that those indicators point to a coming shift in an adversary’s targeting priorities is intelligence. 

Strategic Intelligence Creating an Argument

This phase involves methodically constructing the argument piece by piece and then rigorously stress-testing it from every angle to expose and remedy hidden flaws before your audience does. 

A strong argument not only has to be built, but it must also survive a deliberate attempt to tear it down. Here are questions you must answer to create a strong argument.

Q11: What Are My Key Assumptions?

Every analysis rests on assumptions—things we take for granted as true to fill in gaps in our knowledge. These are the hidden pillars of your argument; if one collapses, your whole assessment can fall.

A Key Assumptions Check is a vital technique where you explicitly list and question these foundational beliefs. For example, you might assume a threat actor’s primary motivation is financial. But what if it’s actually destructive, and the financial demands are just a cover? 

Challenging that single assumption completely changes your assessment of the risk. 

Assumptions in Strategic Intelligence

Experience has shown that about one in four key assumptions collapses under scrutiny, so this is not a step to be skipped.

Q12: How Can I Make My Argument?

An argument consists of a claim (your main point), backed by evidence, and linked by reasons. 

Your primary claim is your bottom-line message, the single most important thing you want your consumer to know. This should be supported by several sub-claims, each with its own evidence, that build a logical case. For instance:

  • Claim: Ransomware actors will increasingly target mid-sized manufacturing companies over the next 18 months.
  • Reason 1: These companies represent a “sweet spot” of having sufficient revenue to pay a significant ransom but often lack the robust security budgets of larger enterprises.
  • Evidence: Analysis of recent victimology data reveals a shift away from large enterprises, with threat actors on underground forums mentioning manufacturing as an “easy target.”
  • Reason 2: The “just-in-time” nature of modern manufacturing makes these companies highly susceptible to downtime, increasing their willingness to pay.
  • Evidence: Economic analysis of the manufacturing sector; case studies of previous ransomware attacks that caused major production halts.

Follow this structure in your CTI report to craft a compelling argument.

Q13: Are There Alternative Hypotheses?

This is a cornerstone of rigorous analysis and a powerful antidote to confirmation bias. Instead of trying to prove your primary hypothesis, you should actively try to disprove alternative ones. 

If you believe China is behind a specific intrusion, you must also seriously consider and evaluate other plausible actors (e.g., Russia, a sophisticated cybercrime group, or an insider) and see if the evidence fits them better. 

The most credible hypothesis is the one with the least amount of disconfirming evidence. Also, don’t forget the null hypothesis: the possibility that the event wasn’t malicious at all (e.g., a network outage caused by human error).

Q14: How Can I Deal With Politics?

Politicization—the pressure, whether explicit or implicit, to tailor analysis to fit a desired policy or business outcome—is a real danger. It can be top-down (a senior leader pushing for a certain conclusion) or bottom-up (an analyst’s own unconscious biases). 

The best defense is a commitment to objectivity and a transparent analytic process.

Using structured analytic techniques provides an audit trail for your reasoning. It shifts the debate from “I don’t like your conclusion” to “Show me where your evidence or logic is flawed.” This depersonalizes disagreement and keeps the focus on the analysis itself.

Q15: What Could Go Wrong?

Before finalizing your assessment, conduct a “premortem.” 

This is a powerful reframing technique where you imagine it’s six months in the future and your analysis has been proven spectacularly wrong. Then, work backward as a team to figure out how that could have happened. 

  • Did you misinterpret a key piece of evidence?
  • Was a linchpin assumption wrong? 
  • Did a low-probability, high-impact event occur that you had dismissed? 

This exercise is one of the best ways to spot hidden flaws, biases, and vulnerabilities in your argument before it’s too late. It provides a psychologically safe way to challenge the consensus.

Sharing Your Message

You have now reached the final phase of the threat intelligence lifecycle. All the meticulous planning, deep research, and rigorous analysis you’ve conducted can be rendered meaningless if the final message fails to connect. 

The most brilliant analysis is worthless if it isn’t communicated effectively. An intelligence report sitting unread in an executive’s inbox is like a state-of-the-art weapon left in the armory during a battle—powerful, but ultimately useless. 

Strategic Intelligence Sharing Your Message

This final phase is about ensuring your message is not only sent, but that it is truly received, understood, and remembered so that it can be acted upon. This is where your analysis becomes action.

Q16: Is My Argument Persuasive?

Persuasion in intelligence isn’t about emotional appeals or slick marketing; it’s about credibility and logic. Your argument is persuasive if it is clear, well-supported, and directly addresses the needs of your client. 

Use simple, direct language and avoid jargon that can obscure your meaning. A compelling, descriptive title and a “Bottom Line Up Front” (BLUF) approach are essential. 

Busy executives are conditioned to look for the key takeaway immediately. Respect their time by giving it to them first, then use the rest of the document to explain how you got there. This structure ensures that even if they only read the first paragraph, they will still grasp your core message.

Q17: How Can I Clarify My Certainty?

Never state an estimative judgment as a fact. The future is uncertain, and your language must reflect that. 

Use probabilistic language to convey your level of certainty. Words like “likely,” “unlikely,” or “even chance” are standard, but they are more powerful when you explain why you have that level of confidence. 

For example, “We assess with high confidence that Threat Actor Y will target the energy sector” is a good start. It’s even better when you add, “…because of their observed targeting patterns, their recent recruitment of engineers with ICS experience, and their anti-Western rhetoric in private forums.” 

This transparency allows the decision-maker to understand the basis of your judgment. Using estimative language correctly is a hallmark of a professional analyst.

Q18: Can I Improve My Presentation?

Good writing is good thinking, made visible. If you’re struggling to write a clear sentence, it’s often a sign that your underlying argument is not yet clear in your own mind. Self-edit ruthlessly.

A great technique is to read your draft aloud; your ear will catch awkward phrasing and run-on sentences that your eyes might miss. Better yet, get a peer review from a trusted colleague. Don’t just ask them to “look it over.” Give them specific questions:

  • Is my main argument clear? 
  • Is there any part that is confusing or unconvincing?
  • Do you see any gaps in my logic?

Remember, a sloppy draft with typos and grammatical errors suggests sloppy thinking and undermines your credibility before the reader even gets to your main point.

Q19: How Can I Convincingly Deliver My Message?

Whether in writing or a briefing, you must tailor your delivery to your audience and the medium. 

Use graphics and visuals not as decoration, but to summarize complex data and tell a story. A well-designed chart showing a trend over time can be infinitely more powerful than a dense paragraph of text describing it. 

A map visualizing the global distribution of an adversary’s C2 infrastructure tells a story that a simple list of IP addresses cannot.

If you’re briefing in person, practice your delivery. Make eye contact, speak clearly, and be prepared for questions. Anticipate the three toughest questions you might be asked and have your answers ready.

Your goal is to ensure your hard-earned strategic intelligence is not just delivered, but that it truly lands and has the impact it deserves.

Q20: How Do I Know When I Am Finished?

The simple answer is that an intelligence product is never truly “finished”; it is a snapshot in time. 

However, knowing when to stop refining and start disseminating is a crucial skill. A good analyst knows they are ready to publish not when the first draft is complete, but when the product has been rigorously reviewed and stress-tested. 

This involves a multi-layered approach:

  1. Conduct a substantive review using techniques like a final Key Assumptions Check or a Premortem Analysis to challenge your own conclusions one last time.
  2. Engage in a peer review, asking a trusted colleague to act as a fresh set of eyes to catch gaps in logic or unstated biases. 
  3. Perform a meticulous self-edit, ideally after stepping away from the draft for a day. Submitting a polished, error-free product is not just about professionalism; it signals to your consumer that you are a careful, rigorous thinker. 

You are finished when you are confident that your product is clear, compelling, well-supported, and free of avoidable errors.


Conclusion

Creating high-impact strategic intelligence is a craft, a skillful blend of art and science that requires more than just technical knowledge. 

It demands discipline to adhere to a rigorous process amidst chaos, the intellectual curiosity to look beyond the immediate event, and a structured approach to navigate ambiguity. By consistently asking these 20 questions, you can transform your analytic process from a reactive scramble—constantly fighting fires—into a proactive, rigorous discipline focused on preventing them. 

Strategic intelligence moves your CTI work from a technical support role to a trusted advisor, making it an indispensable part of the strategic conversation where the future of the business is decided.

Frequently Asked Questions

What is the Meaning of Strategic Intelligence?

Strategic intelligence is a high-level form of analysis that provides a deep, forward-looking understanding of the threat landscape and its implications for an organization. It’s not just about what is happening now, but what is likely to occur in the future and why. 

It connects specific threats to broader business risks, geopolitical trends, and long-term organizational goals to inform executive decision-making. For example, it might assess how a new technology like generative AI will alter the landscape of social engineering attacks over the next five years.

Why is Strategic Intelligence Important?

Strategic intelligence is important because it allows organizations to move from a reactive to a proactive security posture, which is critical for long-term survival and success. Instead of just responding to attacks as they occur, it helps senior leaders anticipate future threats, enabling them to make smarter, more informed investments in security controls, personnel, and training. 

It helps answer questions like, “Should we invest more in cloud security or OT security next year?” By understanding risks to the overall business strategy, the organization ensures that its cyber security efforts are aligned with and support its primary goals, ultimately building a more resilient and adaptable defense.

What is a Strategic Intelligence Analysis?

A strategic intelligence analysis is the formal process of creating a strategic intelligence product, whether it’s a written report, a briefing, or a scenario workshop. 

This comprehensive process involves identifying key stakeholder requirements and intelligence gaps, collecting and evaluating information from a wide range of sources (both technical and non-technical), and applying rigorous structured analytic techniques to assess threats, trends, and future possibilities. 

The final, crucial step is communicating the findings and their implications in a clear, concise, and actionable way to senior decision-makers who are not cyber security experts.

What is the Difference Between Tactical and Strategic Intelligence?

The primary difference lies in their time horizon, audience, and purpose. 

  • Tactical intelligence is technical, immediate, and machine-readable. Frontline security teams and automated systems use it to block current threats (e.g., malicious IPs, file hashes, YARA rules). Its lifespan is often short. 
  • Strategic intelligence, on the other hand, is high-level, forward-looking, and human-intensive. It is consumed by executive leadership to inform long-term strategy, planning, and risk management. Its insights are meant to be durable, shaping decisions for months or even years.