PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements

Andy Piazza (Just a killer grizz with a keyboard)

SAINTCON 2025 · Day 2 · Main Track 3

Overview

In his SAINTCON talk, "PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements," Andy Piazza, Senior Director for Threat Research at Unit42, delivers a candid and provocative critique of how the cybersecurity industry, particularly the threat intelligence community, approaches intelligence requirements. Piazza argues that traditional methodologies, often inherited from military or government intelligence, are fundamentally misaligned with the needs and understanding of business leaders, leading to stagnation, inefficiency, and a failure to deliver impactful security outcomes. His central thesis is that the industry's reliance on complex, jargon-laden frameworks like Priority Intelligence Requirements (PIRs) often confuses stakeholders rather than informing them, hindering effective defensive strategies.

Watch on YouTube

Visual summary for PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements by Andy Piazza
Visual summary for PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements by Andy Piazza

Key moments

  1. 0:00 Introduction and the problem with traditional PIRs
  2. 2:00 DoD speak: Why it fails business leaders
  3. 3:10 Introducing TIRs (Threat Intelligence Requirements) for long-term strategy
  4. 4:00 Cheat sheet: What stakeholders actually care about
  5. 4:35 Beyond IT: Critical users and temporal security needs
  6. 5:45 Why email is the ultimate crown jewel system

PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements

Speakers: Andy Piazza, Senior Director for Threat Research, Unit42

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=i5BvfkAy8Gk

Overview

In his SAINTCON talk, "PIRs & Battle Scars - Lessons Learned from Implementing Intelligence Requirements," Andy Piazza, Senior Director for Threat Research at Unit42, delivers a candid and provocative critique of how the cybersecurity industry, particularly the threat intelligence community, approaches intelligence requirements. Piazza argues that traditional methodologies, often inherited from military or government intelligence, are fundamentally misaligned with the needs and understanding of business leaders, leading to stagnation, inefficiency, and a failure to deliver impactful security outcomes. His central thesis is that the industry's reliance on complex, jargon-laden frameworks like Priority Intelligence Requirements (PIRs) often confuses stakeholders rather than informing them, hindering effective defensive strategies.

Piazza's talk is a passionate call to simplify and reframe threat intelligence, making it more accessible, actionable, and directly relevant to an organization's specific business context. He challenges the established norms, advocating for a pragmatic, two-tiered system that distinguishes between long-term strategic intelligence needs and immediate, tactical priorities. By stripping away unnecessary complexity and focusing on what truly matters to business operations, Piazza aims to empower threat intelligence teams to become more effective contributors to their organization's overall security posture. This presentation is essential for any cybersecurity professional grappling with how to translate complex threat landscapes into meaningful guidance for leadership and operational teams.

The talk matters because it addresses a pervasive problem in cybersecurity: the communication gap between technical security teams and business decision-makers. In an era where cyber threats directly impact business continuity and financial performance, the ability to articulate intelligence requirements clearly and derive actionable insights is paramount. Piazza's proposed framework offers a practical pathway to bridge this gap, ensuring that threat intelligence efforts are not just technically sound but also strategically aligned and demonstrably valuable to the organization. His insights are particularly relevant for organizations struggling to define their intelligence program's direction or demonstrate its return on investment.

Background

▶ Watch: Introduction and the problem with traditional PIRs (0:00)

The genesis of Andy Piazza's frustration, and thus the core problem addressed in his talk, lies in the common practice of applying military-style intelligence frameworks, particularly Priority Intelligence Requirements (PIRs), directly to corporate cybersecurity environments. Many cybersecurity professionals, especially those with backgrounds in the Department of Defense (DoD) or intelligence agencies, bring with them a lexicon and methodology that, while effective in a military context, proves counterproductive in a business setting. Piazza highlights the use of terms like Essential Elements of Friendly Information (EEFI) and Specific Intelligence Requirements (SIRs), often presented in convoluted charts, as prime examples of this "DoD speak" that alienates Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs).

Piazza recounts numerous experiences where organizations spent two years or more simply trying to explain what an intelligence requirement was to their leadership, let alone agree on a list of priorities. This pedantic approach, he argues, "slows the business down" and prevents security teams from being impactful. The very word "priority" in PIRs becomes problematic when these requirements are treated as five-year strategic documents, undermining the sense of urgency the term implies. The traditional approach often boils down to asking "what keeps you up at night?" – a question Piazza dismisses as unhelpful and simplistic, failing to elicit the granular, actionable information needed to drive an intelligence program.

The fundamental disconnect arises because business leaders are primarily concerned with protecting the network and ensuring the business makes money. They are not interested in learning a new, complex intelligence doctrine. Prior work in threat intelligence often focused on generic threat feeds, indicator sharing, and high-level reports that lacked specific relevance to an organization's unique assets, operations, or risk profile. This led to intelligence teams producing vast amounts of data without clear guidance on what was most critical, resulting in a reactive rather than proactive security posture. Piazza's solution stems from this observed pattern of inefficiency and the need for a simplified, business-centric approach to defining and actioning intelligence requirements.

Key Findings

▶ Watch: Introducing TIRs (Threat Intelligence Requirements) for long-term strategy (3:10)

Andy Piazza's core contribution is a revised, pragmatic framework for defining intelligence requirements, designed to cut through jargon and directly serve business needs. He introduces a two-tiered system: Threat Intelligence Requirements (TIRs) for long-term strategic guidance and a re-imagined concept of Priority Intelligence Requirements (PIRs) for short-term, actionable priorities.

Piazza proposes that Threat Intelligence Requirements (TIRs) should be the foundational, enduring questions that guide an organization's threat intelligence program. These are broad enough to remain relevant for years (5, 10, even 20 years) but specific enough to drive collection management, data acquisition, and analytical focus. He offers a "cheat sheet" of universal TIRs that he has successfully implemented across multiple organizations, covering about 90% of typical intelligence needs.

In contrast, the re-conceptualized Priority Intelligence Requirements (PIRs) are treated as "RFIs on steroids." These are specific, time-bound requests (typically 90-180 days) that require continuous engagement or multiple intelligence products to address. They are tactical in nature, responding to ongoing campaigns, specific stakeholder needs (e.g., incident response support, marketing campaigns), and are actively tracked with due dates to ensure accountability and resource reallocation. This distinction allows the intelligence team to maintain strategic direction while flexibly addressing immediate, high-impact concerns.

The key findings revolve around these actionable categories and principles:

  1. Simplified Language: Eliminate DoD jargon in favor of clear, business-centric questions.
  2. Universal TIR Categories: Focus on a core set of fundamental questions about threat actors, critical assets, and relevant vulnerabilities.
  3. Actionable PIRs: Treat PIRs as short-term, high-impact requests with clear timelines and stakeholder engagement.
  4. Environmental Context: Emphasize the critical importance of applying threat intelligence to the organization's specific environment, rather than just reporting generic threats.
  5. Focus on Exploited Vulnerabilities: Prioritize tracking vulnerabilities actively exploited by threat actors, filtering out the vast majority of CVEs that pose no immediate threat.
  6. "Email is the Crown Jewel": Highlight email as arguably the most critical system in any organization due to its pervasive role in accessing other systems and containing sensitive information.
  7. Data-Driven Collection Management: Use intelligence requirements to drive the acquisition and analysis of necessary logs and data sets.
  8. Proactive Engagement: Encourage threat intel teams to proactively engage with various stakeholders beyond the CISO, including SOC, incident responders, detection engineers, and red teams.

By adopting this framework, organizations can foster a more efficient, relevant, and impactful threat intelligence function that directly supports defensive operations and strategic decision-making.

Technical Deep Dive

▶ Watch: Cheat sheet: What stakeholders actually care about (4:00)

Andy Piazza’s proposed framework for intelligence requirements is built on a clear conceptual split between long-term strategic needs and short-term tactical priorities, using the terms Threat Intelligence Requirements (TIRs) and Priority Intelligence Requirements (PIRs), respectively. This distinction is crucial for structuring an intelligence program that is both enduring and agile.

Threat Intelligence Requirements (TIRs): The Long-Term Compass

Piazza defines TIRs as the guiding, foundational intelligence questions that shape an organization's threat intelligence program over extended periods—potentially 5, 10, or even 20 years. These are not meant to change frequently but rather to establish the core areas of intelligence collection and analysis. He offers a "cheat sheet" of these requirements, designed to be universally applicable yet specific enough to drive action:

  1. Which threat actors have a demonstrated intent to impact our organization? This focuses on understanding who genuinely cares about targeting the business.
  2. Which threat actors have a demonstrated capability to impact our organization? This assesses the technical prowess and resources of those identified in the first requirement.
  • Example: Piazza cites historical DOJ indictments against China, noting that organizations involved in sensitive business negotiations with such countries should expect heightened targeting of their legal and business leaders.
  1. Which users or groups are critical to our operations? This extends beyond typical IT administrators or privileged accounts to include individuals whose compromise could severely disrupt business.
  • Example: Lawyers or business leaders traveling overseas for negotiations are high-value targets requiring elevated security.
  1. What are our crown jewel systems, critical network segments, and the protections in place? This moves beyond merely identifying sensitive data stores to understanding the interconnected systems and processes vital for business continuity.
  • Controversial but impactful take: Piazza emphatically argues that email is the number one crown jewel system in any organization, regardless of industry. He explains that email often holds the keys (password resets) to other critical systems, contains sensitive reports, and is a prime vector for social engineering (e.g., phishing links for bonuses). The Colonial Pipeline breach is cited as an example where, despite operational systems being intact, the inability to bill customers (a critical business process) forced a shutdown, highlighting the need to protect processes, not just data.
  • DoD parallel: For those from a DoD background, this aligns with Essential Elements of Friendly Information (EEFI), understanding the internal landscape, segmentation, and identity management.
  1. What vulnerabilities are actually present in our environment and being exploited by bad guys? This is a critical filter. Piazza stresses that threat intelligence teams should only focus on vulnerabilities actively exploited by real threat actors, not theoretical Proof of Concepts (PoCs) or those used by internal red teams.
  • Rationale: With 25,000-26,000 CVEs released annually (as per IBM's annual threat intelligence index), tracking all of them is futile. Less than 1% are ever actually exploited in the wild. A key defensive implication is the need for a robust asset inventory; sending a flash report about a zero-day that isn't even in the organization's environment is a waste of resources.
  • Threat vs. Risk: Piazza distinguishes between "threat" as a proper noun (e.g., a human operator, a "Storm" named actor by Microsoft) and "risk" (e.g., a tsunami). Threat intelligence, he argues, focuses on the former.

The core purpose of these TIRs is to enable a defender's threat intelligence team to apply intelligence to their specific environment. This means moving beyond simply regurgitating vendor reports (e.g., from Unit42 or Mandiant) to providing contextualized insights: "They're saying this, and here's how it applies to our environment. We have X systems with this vulnerability, and here's the patch plan."

Priority Intelligence Requirements (PIRs): RFIs on Steroids

Piazza redefines PIRs as distinct from TIRs. Instead of long-term strategies, PIRs are short-term, actionable requests that require sustained effort, multiple intelligence products, or continuous engagement. He likens them to "RFIs (Request for Information) on steroids."

  • Duration: PIRs typically have a due date, often 90 days, or up to 180 days for major campaigns (e.g., SolarWinds, F5, Avantes breaches).
  • Scope: They address specific, immediate needs such as incident response support, tracking a major threat campaign, or even supporting marketing initiatives.
  • Tracking: Piazza advocates for a simple tracker—even Excel is sufficient, though AirTable, SharePoint, or Confluence tables can also be used. This tracker should include due dates and align PIRs directly to stakeholder needs.
  • Stakeholder Alignment & Feedback: A critical aspect is explicitly linking PIRs back to the originating stakeholders and checking in on their needs. Piazza shares an anecdote from a SANS CTI course instructor about producing reports for two years for a stakeholder who had moved targets a year prior. Due dates prevent such waste. This direct stakeholder engagement also enables targeted surveys, significantly improving feedback quality and providing actionable metrics for the intelligence program.

This two-tiered approach ensures that an intelligence program has a stable, long-term strategic direction (TIRs) while remaining responsive and impactful in addressing immediate, high-priority threats (PIRs).

Demo / Proof of Concept

▶ Watch: Beyond IT: Critical users and temporal security needs (4:35)

Andy Piazza's talk does not feature a traditional software or code demonstration. Instead, he illustrates his concepts through practical examples, anecdotes, and real-world scenarios drawn from his extensive experience. These serve as "proofs of concept" for the effectiveness of his proposed framework and the types of insights it can yield.

One key illustrative example involves collection management framework. Piazza describes a method he used in a large Splunk shop (though applicable to any SIEM). He would dump all indexes and source types, then add columns for various observable types (IP addresses, domains, usernames). By running simple searches (e.g., head 10) on each index and checking for the presence of these observables, he gained a deep understanding of what data was available before a breach. This not only aided future investigations by mapping observable types to specific log sources but also uncovered unknown data types, prompting conversations with IT administrators about custom software and its operational codes. This process, he explains, is essentially an "Essential Elements of Friendly Information" exercise, helping to understand internal systems.

Another powerful anecdote involved a "hunt" to identify all web servers in a very large organization, necessitated by internal politics preventing direct queries to IT. The team scoured Splunk for web server index types and then identified which were internet-facing. While seemingly inefficient (simply asking IT would have been easier), this exercise forced the team to intimately understand the diverse systems present. This hunt led to a critical discovery during the 2020 elections, while supporting the United States Postal Service (USPS). They found a publicly facing USPS website for political mailers that allowed unauthenticated file uploads of "pretty much any file type." This discovery, unknown to the internal red team, highlighted a significant potential vulnerability and prompted crucial conversations with IT about file handling, execution environments, and server security.

Piazza also emphasizes the importance of understanding critical IT systems in peacetime. He candidly admits that, like many, he had no idea what SolarWinds was until the infamous breach, despite his organization having five such servers. This illustrates the need for threat hunters to get "intimate" with critical infrastructure before an incident occurs, making response significantly faster.

These examples, while not live demos, effectively demonstrate how an intelligence team, operating under Piazza's principles, can proactively discover critical information, identify overlooked vulnerabilities, and build a deeper understanding of their environment, thereby proving the practical utility of his framework.

Defensive Implications

▶ Watch: Why email is the ultimate crown jewel system (5:45)

Andy Piazza's talk offers several crucial defensive implications for organizations looking to mature their threat intelligence programs and improve their overall security posture.

  1. Refactor Intelligence Requirements for Business Relevance: The most immediate implication is to abandon complex, jargon-laden intelligence frameworks in favor of Piazza's simplified Threat Intelligence Requirements (TIRs) and Priority Intelligence Requirements (PIRs). This means engaging stakeholders—not just CISOs, but also SOC analysts, incident responders, detection engineers, and red teams—with clear, concise questions about what truly matters to the business. By focusing on critical users, crown jewel systems, and specific threat actors, defenders can ensure their intelligence efforts are aligned with organizational risk and operational continuity.
  1. Prioritize Crown Jewels Beyond Data: Defenders must broaden their definition of "crown jewels" beyond just sensitive data stores. Piazza's emphasis on email as the paramount crown jewel system, due to its role in authentication, communication, and social engineering, necessitates a re-evaluation of its security posture. Furthermore, understanding and protecting critical business processes (like billing, as seen in the Colonial Pipeline example) is as important as protecting individual systems. This requires a holistic view of how systems interconnect and support business functions.
  1. Focus Vulnerability Management on Active Exploitation: Threat intelligence teams should filter the overwhelming volume of CVEs and focus solely on those that are actively being exploited by demonstrated threat actors in the wild. This requires robust asset inventory management to determine if a vulnerable system even exists within the environment. By doing so, defenders can significantly reduce alert fatigue and concentrate scarce patching resources on the most pressing threats.
  1. Proactive Environmental Awareness is Key: Don't wait for a breach to understand your network. Defenders should conduct internal "hunts" or data analysis exercises (like Piazza's Splunk index analysis or the web server hunt) to map their own systems, data flows, and log availability. Understanding what logs are collected, what systems are present, and how they function in "peacetime" makes incident response and threat hunting exponentially faster and more effective during an actual engagement.
  1. Implement Foundational, High-Impact Security Controls: Piazza advocates for simple yet highly effective measures. For example, implementing physical MFA (e.g., UB Keys) for critical access, especially for email on new devices, offers a significant security uplift for a relatively low cost and minimal user friction. Telling concise, impactful stories (e.g., a help desk credential leading to domain admin and ransomware in 36 hours) can effectively communicate the "why" behind such recommendations to CIOs and drive adoption.
  1. Improve Threat Intelligence Integration and Actionability: The way threat intelligence is consumed needs a fundamental shift. Instead of merely integrating threat feeds to look for future traffic, defenders should use intelligence to look backwards in their logs for past activity related to reported incidents. If a fishing email with IoCs is shared, the immediate action should be to search historical logs for those IoCs, not just to update future detections. Furthermore, intelligence reporting should move beyond just techniques (e.g., MITRE ATT&CK) to include procedural-level details and the sequence of actions (kill chains) observed in specific campaigns, enabling more precise detection engineering and adversary emulation.
  1. Measure Impact, Not Just Activity: Tie PIRs to specific stakeholder needs and track their completion with due dates. Use targeted surveys based on fulfilled PIRs to gather actionable feedback. This allows intelligence teams to demonstrate their value, measure impact, and reallocate resources effectively, moving beyond vague KPIs and metrics that don't reflect actual contribution to security outcomes.

By embracing these implications, security teams can transform their threat intelligence function from a pedantic, often ignored, reporting mechanism into a dynamic, business-aligned engine that directly enhances an organization's defensive capabilities.

Key Takeaways

  • Simplify Intelligence Language: Ditch complex DoD jargon (PIRs, EEFI, SIRs) when communicating with business leaders. Use clear, concise, business-relevant language to define intelligence needs.
  • Adopt a Two-Tiered Framework: Implement Threat Intelligence Requirements (TIRs) for long-term strategic guidance (5-20 years) and a revised concept of Priority Intelligence Requirements (PIRs) for short-term, actionable, time-bound requests (90-180 days).
  • Email is the Ultimate Crown Jewel: Prioritize the security of email systems, as they often serve as the gateway to other critical assets and contain highly sensitive business information. Extend "crown jewel" thinking to critical business processes, not just data stores.
  • Focus on Actively Exploited Vulnerabilities: Concentrate vulnerability management efforts and threat intelligence analysis on CVEs that are demonstrably being exploited by real threat actors in your environment, not theoretical risks or a deluge of unexploited vulnerabilities.
  • Proactively Understand Your Environment: Conduct internal exercises (e.g., analyzing SIEM logs, hunting for unknown systems) to build an intimate understanding of your organization's assets and data before a breach occurs, enabling faster and more effective incident response.
  • Integrate Intelligence for Retrospective Hunting: Shift threat intelligence integration to look backwards in logs for historical activity related to new indicators of compromise, rather than solely focusing on future detections.

About the Speaker(s)

Andy Piazza is the Senior Director for Threat Research at Unit42, the global threat intelligence team at Palo Alto Networks. He describes himself as "just a killer grizz with a keyboard" and has been deeply involved in the threat intelligence community for a long time. Throughout his career, he has observed and been frustrated by common pitfalls in how organizations approach threat intelligence, particularly the misapplication of military intelligence frameworks to business contexts. His work focuses on making threat intelligence more practical, impactful, and aligned with organizational objectives.

All talks from SAINTCON 2025