Threat-informed defense, Decision Packages, Not Intelligence Briefings
Fewer PDFs. More decisions. A threat brief built for CISOs who don't have time to read one.
Why this exists
The 2026 SANS CTI Survey put it bluntly: CTI is no longer fighting for legitimacy. It is fighting for influence.
91% of CISOs say threat intelligence is valuable. Only 26% say it significantly influences their decisions. That’s a 65-point gap between “I care” and “I can act on this.”
The barrier isn’t data. It’s time (44% cite it) and funding (44% cite it). CISOs are drowning in feeds, reports, and vendor briefings that read like intelligence products written for analysts — not decision packages written for the people who sign the checks.
This newsletter is my attempt at the second thing.
What this is
A short brief — 15 minutes, no more — built around one question:
What does a security leader need to decide this week that they wouldn’t have known to decide otherwise?
Every issue follows the same structure:
30-second summary — the whole issue in one paragraph
🔴 Act Now — decisions that can’t wait
🟠 Watch — developments to monitor
🟡 Awareness — context that shapes strategy
The CISO’s Take — my read, not a summary
Worth Your Time — one link, curated hard
Question for You — because I’d rather have a conversation than an audience
No sponsored content. No fear-mongering. No vendor-speak. If I don’t have signal, I don’t publish.
How this is made
Honesty first: this newsletter is produced with AI in the loop. So is roughly 45% of the CTI work happening in mature security programs today (SANS 2026). Pretending otherwise would be dishonest and behind the times.
Here’s the split:
AI does: retrieval across public sources (CISA, Mandiant, CrowdStrike, Microsoft, Google TAG, NCSC, ENISA, The DFIR Report, and … dark web eventually), first-pass summarization, draft synthesis
I do: source selection, prioritization, tier assignment, the CISO’s Take, and final validation
That’s the model the industry is moving toward. I’d rather do it out in the open than pretend I’m hand-crafting every word at 2 AM.
Who I am
I've spent 20 years across IT and security roles, most of them with cybersecurity somewhere in the job description. I'm CISSP-certified.
I’m not a vendor. I’m not selling a platform. I’m writing this because I want it to exist, and I couldn’t find it anywhere else.
What’s coming
Issue #1 lands when I have signal worth your time. That could be next week. That could be sooner. Signal over schedule.
If you want to be there when it does, subscribe below.
If this isn’t for you, no hard feelings. Forward it to someone it might be for.
A question for you
Reply to this email or comment below:
What’s the last threat intel report you actually acted on — and what made it different from the ones you didn’t?
I’m reading every response. The answers shape Issue #1.
Readin InfoSec. Threat-informed defense, decision packages, and the occasional strong opinion.

