Uploaded June 2026 | Updated September 2026, 33 minutes ago
Joe Slowik (Paralus, US)
Cyber threat intelligence (CTI) is, at its core, a discipline of decision support. CTI that cannot enable, improve, or otherwise facilitate a security action is of questionable operational value. In evaluating CTI efficacy, we typically focus on applicability, accuracy, and contextuality, but the relationship of CTI to security actions (particularly for tactical flavors of CTI) also demands examination of another metric: timeliness. Put simply, CTI that arrives too late for the decisions supported is irrelevant.
In this discussion we will explore the implications of a time-oriented view to CTI production, dissemination, and integration into operational decision making. From this we will identify a tension at the core of CTI production: between the speed at which CTI is disseminated and the depth or quality of the CTI produced. Put simply, organizations cannot have immediate decision support while simultaneously having deep contextuality in the current environment, leading to discussions of tradeoffs and continuums of possible CTI outcomes. Evaluating CTI thus becomes a question of determining audience and customer needs, purpose, and response timelines to appropriately structure finished CTI for the given entity in question.
---
Joe Slowik has over 15 years of experience across multiple information security domains, with specializations in cyber threat intelligence, detection engineering, and threat hunting. Joe currently is Director of Cybersecurity Alerting Strategy for Dataminr, and has previously held roles at the MITRE corporation, Huntress, DomainTools, Dragos, Los Alamos National Laboratory, and the US Navy. In addition to the above, Joe also provides threat intelligence training and advising through his company, Paralus LLC.
Joe Slowik (Paralus, US)
Cyber threat intelligence (CTI) is, at its core, a discipline of decision support. CTI that cannot enable, improve, or otherwise facilitate a security action is of questionable operational value. In evaluating CTI efficacy, we typically focus on applicability, accuracy, and contextuality, but the relationship of CTI to security actions (particularly for tactical flavors of CTI) also demands examination of another metric: timeliness. Put simply, CTI that arrives too late for the decisions supported is irrelevant.
In this discussion we will explore the implications of a time-oriented view to CTI production, dissemination, and integration into operational decision making. From this we will identify a tension at the core of CTI production: between the speed at which CTI is disseminated and the depth or quality of the CTI produced. Put simply, organizations cannot have immediate decision support while simultaneously having deep contextuality in the current environment, leading to discussions of tradeoffs and continuums of possible CTI outcomes. Evaluating CTI thus becomes a question of determining audience and customer needs, purpose, and response timelines to appropriately structure finished CTI for the given entity in question.
---
Joe Slowik has over 15 years of experience across multiple information security domains, with specializations in cyber threat intelligence, detection engineering, and threat hunting. Joe currently is Director of Cybersecurity Alerting Strategy for Dataminr, and has previously held roles at the MITRE corporation, Huntress, DomainTools, Dragos, Los Alamos National Laboratory, and the US Navy. In addition to the above, Joe also provides threat intelligence training and advising through his company, Paralus LLC.










