5 min read · Updated September 2026
Intelligence reporting is the output an intelligence function is judged on: for most stakeholders it is the only tangible evidence the function exists. It works on a fixed cadence with a consistent structure, devotes most of its length to assessment rather than to recounting facts, and is published where readers can find it rather than pushed at them.
Read first: The intelligence cycle (dissemination is a phase of it)
Reporting is the primary vehicle through which an intelligence function has any influence at all. It is the product most stakeholders will ever engage with, and for many of them it is the only proof the function exists and is worth funding. That makes report quality a strategic matter rather than a matter of style, and it deserves to be treated as the thing the team is actually judged on.
Good intelligence writing combines journalistic instinct with analytical precision, and it cannot be produced by a template alone or taught entirely in a course. The analysts who do it well share an inquisitive nature, a clear writing style, and a grasp of what a cyber threat means for a business. The skill that matters most is distillation: turning complex technical detail into insight somebody outside the technical function can use.
Different stakeholders genuinely have different needs. That does not mean producing a bespoke report for each of them, which is how a small team ends up spending its week on formatting.
The defence is a clear intake process for stakeholder needs, so requests are captured and clarified early rather than arriving as one-off demands, and a set of standardised formats broad enough to satisfy most groups. A mature function has a handful of report types it does well, not a catalogue of variants nobody can maintain.
Regular reporting should run on a defined rhythm, typically weekly, monthly, quarterly and annual. Each should exist as a full written version, published where people can reach it, and a shortened visual version for audiences who will only ever see a deck.
The important mechanic is that the periods feed one another. Weekly reporting is the foundation; weekly feeds monthly, monthly feeds quarterly, quarterly feeds annual. Built this way the longer reports are an act of synthesis rather than a scramble, and they can afford to become progressively more strategic and more visual as the window widens, leaning on charts and trend views rather than restating individual events.
Functions that skip the weekly layer discover the cost at quarter end, when there is nothing to aggregate and somebody has to reconstruct three months from memory.
Publish intelligence to an accessible platform and make sure stakeholders know where it lives and when it appears. Relying on email distribution means relying on a moment of attention that may never come, and it produces missed insight that nobody notices.
The aim is to train the audience to come and get it, to contribute feedback through comments or follow-up requests, and to carry some responsibility as readers. That is a cultural change rather than a tooling one, and it takes consistency to establish: people only develop the habit of checking if there is reliably something there.
Every article inside a report should follow the same three-part shape:
Alongside it, one rule does more for report quality than any other: one-third situation, two-thirds assessment. A third of the length summarises the facts; two-thirds is analysis and insight.
Most weak intelligence reporting inverts that ratio. It is mostly recounting of events with a short closing paragraph of interpretation, which leaves the reader to do the analytical work the function exists to do for them. If a report is mostly situation, it is a news summary regardless of what it is called.
Consistency of naming and headings matters for the same reason. Readers who know where the assessment sits will read the assessment.
Reporting responsibility should sit with the analyst who owns that threat vector. This produces depth, keeps accuracy attached to expertise, and creates genuine ownership of the product rather than diffuse collective authorship.
A workable weekly rhythm looks like this: drafting starts on the same day the previous edition goes out, the bulk is complete by end of week, and the report is finalised and disseminated at the start of the following week with any significant weekend developments folded in. The specifics matter less than that the rhythm exists and everybody knows it.
Major events cannot wait for the cadence, and ad hoc reporting exists for them. It needs three constraints, or it will erode the routine it sits alongside.
It should be fast, drafted and out within about half an hour, because the value of an urgent report decays quickly. It should follow an agreed selection threshold rather than an analyst's judgement in the moment. And it should be sent only when business impact or threat relevance is actually confirmed.
Without a threshold, ad hoc reporting expands until it is the normal mode, at which point the audience stops treating urgency as meaningful.
Delivering a report is not the same as being useful to somebody. The objective is for intelligence to become part of how a stakeholder thinks and works, which is built through structured outreach, periodic review and real feedback mechanisms rather than through distribution alone.
One trap is worth naming: relationships that depend on individuals are fragile. When the intelligence function's influence rests on one analyst knowing one sympathetic manager, it leaves with either of them. Repeatable, documented processes survive personnel turnover. Build partnerships rather than dependencies.
Conundrum generates reporting in exactly the situation, assessment, recommendations structure described above, and runs the four nesting cadences so weekly material rolls up into monthly, quarterly and annual without anybody reconstructing the period by hand.
Reporting is published to a place stakeholders come to rather than pushed into inboxes by default, which is the pull model; routed delivery exists, but it follows rules your team sets rather than being the primary mechanism. Every published report is versioned at publication, so what was said and when stays fixed, and dissemination is logged, so the question of who was told what has an answer.
What the platform does not do is write the assessment for you. The two-thirds of a report that carries the analysis is the part that needs an analyst who understands the vector and the business, and generated material is a draft for that person to work from rather than a replacement for them.