Ten Year Anniversary

Celebrating a Decade of Analyst-Driven Intelligence

10 years of building tools and tradecraft for defenders

Limited Series Podcast

TLDR: Key Takeaways

The Graphic That Sparked the Conversation

Show Notes

Nicole never expected her Hard Cyber Threat Intel Pills to Swallow graphic to resonate as widely as it did.

Inspired by an illustration about endometriosis, she adapted the format to capture frustrations she'd experienced throughout her own intelligence career. What surprised her wasn't simply the popularity of the graphic, it was how many analysts immediately recognized themselves in it.

Rather than generating debate over whether the observations were true, the response largely became one of shared recognition: these were conversations many practitioners had been having privately for years.

Why Enterprise CTI Changes Your Perspective

One of the strongest themes throughout the discussion is the difference between threat research and enterprise threat intelligence.

Threat researchers naturally gravitate toward understanding campaigns, actors, and the broader threat landscape. Enterprise intelligence teams, however, have a different responsibility: helping one organization make better security decisions. That shift changes what success looks like.

Interesting developments aren't automatically important. Attribution isn't always necessary. And many fascinating stories simply don't affect the business you're trying to protect.

Nicole argues that mature intelligence teams become better not by learning more about every threat, but by becoming more disciplined about which threats deserve attention.

Escaping the Panic Cycle

Modern CTI teams are constantly surrounded by breaking news, zero-day disclosures, and rapidly spreading social media discussions.

Nicole describes how analysts can easily become trapped in what she calls panic cycles, where every new headline feels urgent simply because everyone is talking about it.

Her recommendation is simple: instead of allowing the broader internet to dictate priorities, intelligence teams should continually return to their own organization's intelligence requirements.

One of the most valuable threat feeds isn't an external vendor at all - it's your own incident queue.

Understanding what is actually happening inside your environment often provides more useful intelligence than chasing every emerging headline.

Learning to Let Go of Attribution

Perhaps the most controversial takeaway centers around attribution. Nicole explains that while identifying threat actors can be deeply satisfying (and often essential for threat research) it isn't always what enterprise stakeholders actually need.

Leadership generally cares less about the evolution of a ransomware group's branding than they do about practical questions:

For enterprise CTI teams, actionable risk often matters more than naming the adversary.

Becoming a Better Intelligence Communicator

The conversation also explores one of the most overlooked analyst skills: communication.

Nicole argues that effective reporting isn't about demonstrating how much research was completed, it's about making decisions easier.

That means:

As she notes during the discussion, shortening a report often takes significantly more work than writing a long one.

Advice for New Analysts

When asked which "hard pills" every new analyst should accept early in their career, Nicole doesn't hesitate: you're going to be wrong sometimes (and that's okay). Threat intelligence is inherently probabilistic. Analysts routinely make judgments based on incomplete information, evolving evidence, and uncertain futures.

The goal isn't perfect prediction - the goal is producing thoughtful, transparent assessments that improve decision-making over time.

Resources Mentioned