Security Intelligence

The Intelligence Cycle: A Primer for Security Leaders

How the classical intelligence cycle applies inside corporate security teams, and where it typically breaks down.

By Mowlid Ali 20 Jan 2026 6 min Security Intelligence
Source

Originally reported by US ODNI — ICD 203. INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 4 citations
Author
Mowlid Ali
Source
US ODNI — ICD 203
Publication date
20 Jan 2026
Location
Missing
Country
Missing
Category
Security Intelligence
Threat level
SUBSTANTIAL — An attack is likely.
Analytic confidence
High
Verification status
Verified
Listen · 2 minReady to play · about 2 min

The classical intelligence cycle, direction, collection, processing, analysis, dissemination, is one of the most useful and one of the most abused frameworks in corporate security. Used well, it disciplines a team into producing decision-relevant work. Used badly, it produces reports no one reads.

Where corporate teams get stuck

  • Direction: unclear intelligence requirements, driven by 'nice to know' rather than 'need to decide'.
  • Collection: over-reliance on media and vendor feeds, under-investment in human and internal sources.
  • Processing: unstructured storage that makes retrieval and cross-tasking painful.
  • Analysis: descriptive reporting instead of assessment, what happened, but not what it means.
  • Dissemination: right product, wrong audience, wrong time, and no feedback loop.

What to fix first

In our experience, the single highest-use fix is to write real intelligence requirements, three to five, agreed with the decision-makers, revisited quarterly. Everything else in the cycle either serves those requirements or gets deprioritised. Teams that get this right stop producing reports and start producing decisions.

Intelligence is not what the analyst knows. It is what the decision-maker does differently because of it.

A pragmatic starting point

Run a one-week diagnostic against the cycle: what do we currently produce, who consumes it, what decisions did it inform in the last quarter, and where did it fail to reach the decision in time? The output of that exercise is usually a much shorter list of things the team should be doing, and a longer list of things it can stop.

Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on security intelligence and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.