Cyber Threat Intelligence Podcast

Inside the Red Team and CTI Relationship: Intel Quality, Feedback Loops, and Blind Spots (William Wright & Pedro Kertzman)

• Pedro Kertzman • Season 2 • Episode 13

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 24:49

A single sentence from the right threat intel analyst can blow up weeks of planning and that’s exactly why we love it. Pedro Kertzman sits down with William Wright, CEO of Closed Door Security, to dig into cyber threat intelligence from the attacker’s end of the table: red teaming, threat-led penetration testing, and the real-world frictions between CTI, SOC teams, and offensive security.

We get specific about what “actionable intelligence” actually means when you’re the person who has to run the TTPs. William breaks down how DORA and TIBER-EU style engagements push CTI reports toward clearer structure, and why some deliverables still miss the mark. If a report is just a dump of IOCs, file hashes, or a heat map that paints nearly everything red, it doesn’t guide testing or improve detection and response. The value shows up when intelligence connects threat actor behavior to runnable scenarios and helps defenders tune telemetry and playbooks.

The best part: the human layer. We talk about why a short report plus a walkthrough call can beat a “perfect” document, and how those conversations uncover fresh leads, nuance, and the kind of context that never fits on a page. William shares a memorable example from a trading platform where internal CTI advice changed a phishing plan instantly by steering the team toward contractors instead of traders.

If you want stronger CTI programs, better red team outcomes, and tighter feedback loops between CTI and security operations, hit subscribe, share this with your team, and leave a review. What’s the most useful thing you’ve ever gotten from threat intelligence?

Send us Fan Mail

Support the show

Thanks for tuning in! If you found this episode valuable, don’t forget to subscribe, share, and leave a review. Got thoughts or questions? Connect with us on our LinkedIn Group: Cyber Threat Intelligence Podcast—we’d love to hear from you. If you know anyone with CTI expertise that would like to be interviewed in the show, just let us know. Until next time, stay sharp and stay secure!

People on this episode