CTI-CRAFT is an advanced practitioner-led programme for analysts, consultants and security teams who need to produce defensible intelligence assessments, threat scenarios and regulatory-grade outputs — not memorise the intelligence lifecycle.
Why it exists
Regulated intelligence engagements require judgement, structure, defensible reasoning and the ability to support operational testing. CTI-CRAFT is built around that reality.
Knowing the intelligence cycle is useful. Producing a threat assessment that survives client, regulator and red team challenge is a different skill entirely.
Feeds and IOCs are one layer. The value sits in requirements, analysis, scenario design, judgement and decision-ready reporting.
DORA, CBEST and TIBER-EU demand people who understand business services, threat-led testing, mature reporting and operational handover.
Outcomes
The outcome is not more knowledge. It is the ability to plan, analyse, produce and defend intelligence work in high-stakes environments.
From scoping and requirements through collection planning, analysis, reporting and stakeholder review.
Plausible, evidence-backed CBEST and TIBER-style scenarios with actor selection, attack paths and procedure-level ATT&CK mapping.
Assess governance, programme planning, operations and functional management using structured evidence and scoring.
ACH, key assumptions check, premortems, indicators and warnings, alternative futures, and estimative language with confidence ratings.
Brief red teams, supply adversary context, support technique replay, and convert intelligence into detection improvement.
Curriculum
Core intelligence foundations combined with advanced modules focused on CBEST, TIBER-EU, DORA TLPT and financial sector threat intelligence.
Intelligence principles, lifecycle management, collection, requirements, legal and ethical boundaries, reporting and technical foundations.
Important business services, critical important functions, payment systems, systemic risk, SWIFT, open banking and financial sector threat actors.
Actor profiling, procedure-level ATT&CK mapping, attack path design, plausibility statements and red team handover.
Governance, programme planning, operations, functional management, evidence-based scoring and improvement roadmaps.
Bias control, probability language, confidence ratings, assumptions testing, alternative futures and intelligence failure analysis.
Geopolitical analysis, OT and ICS threats, insider threat, purple teaming, AI-enabled intelligence and AI-specific attack vectors.
Failure modes
Senior analysts are not separated by how many frameworks they know. They are separated by how they handle ambiguity, weak evidence, uncertainty, challenge and pressure.
What you take away
Built around demonstrated outputs, templates, live walkthroughs and practical exercises — the artefacts expected in real intelligence-led engagements.
Walkthroughs use real working methods to show how requirements, collection, analysis, fusion, scenario development and reporting connect — requirements to reporting, analysis to scenario, evidence to judgement.
Who built it
CTI-CRAFT is written by a practising threat intelligence lead delivering targeted threat intelligence phases under TIBER-EU, CBEST and DORA TLPT requirements — current engagement work rather than past experience.
The tradecraft underneath it comes from over twenty years of operational intelligence work spanning law enforcement intelligence and cyber, including structured intelligence production, source handling and formal grading schemes applied directly to threat intelligence delivery.
Start free
CTI-CRAFT is an advanced programme. If you need the groundwork first — core intelligence concepts, the lifecycle, and analytical foundations — the free foundation course covers it and prepares you for the advanced modules.
The free course covers:
Questions
Security analysts, intelligence consultants, red team leads and financial sector security professionals who need to produce and defend regulatory-grade intelligence outputs for CBEST, TIBER-EU and DORA TLPT engagements. If you already understand the CTI lifecycle and need to operate above it, this is built for you.
Most CTI training teaches framework knowledge and lifecycle theory. CTI-CRAFT is built around what happens when your work is challenged — by a client, a regulator or a red team. The focus is defensible tradecraft, delivery under scrutiny, and the specific artefacts required for regulated threat-led testing. Not credential accumulation.
Yes. The curriculum is built around the intelligence requirements for regulated threat-led testing — targeted threat intelligence production, CBEST and TIBER-style scenario development, threat intelligence maturity assessment, and regulatory-grade reporting.
CTI-CRAFT is advanced. Anyone without a foundation in intelligence concepts should complete the free foundation course first, then progress into the CTI-CRAFT modules.
CTI-CRAFT is in development. Register your interest for launch updates, early access pricing, sample modules and access to the free foundation course.
Register interest
Launch updates, early access pricing, sample modules, and the free CTI foundation course. No drip sequence.