
Cyber Threat Intelligence 101
Start learning about cyber threat intelligence with this short intro course taken from our PTIA.
100% Online • Self-Paced • Start Immediately
What's Included
- 4+ hours of training content
- 100% online and on-demand self-study course
- arcX final micro exam
- Includes 2.5+ hours of video training
- Engaging exercises
- 100+ practice questions

Free
Trusted by leading organisations worldwide












Where a cyber threat intelligence career begins
An intruder can sit inside a network for months while every dashboard stays green. Threat intelligence is how you see them first.
In the mid-2010s the typical attacker spent roughly five months inside a target's network before anyone noticed: five months to read email, map systems, and choose exactly what to steal, all while the alerts stayed silent. Calm dashboards are not proof of safety. They are often the problem.
This course teaches you to turn that silence into signal. You will learn to define what cyber threat intelligence actually is, tell a bored teenager apart from a paid criminal and a nation-state operative, map an organisation's attack surface, walk the intelligence cycle from requirement to dissemination, and weigh the legal and ethical lines a UK analyst has to respect.
It gets you there through scenario-driven decisions and real cases: the Stuxnet worm, Mandiant's APT1 report, the SolarWinds Orion compromise, and the Shein and Romwe breach. This is a deliberately basic, theory-first introduction built for someone deciding whether a CTI career is for them, drawn from arcX's practitioner-level course.
Product Overview
This short course serves as a sneak peek into our incredible Cyber Threat Intelligence Practitioner course.
During the course you will learn some basic CTI concepts to help get you started:
- What is cyber threat intelligence and why is it useful
- What are threat actors and their motivations
- What are the common threat vectors and vulnerability types
- What is the intelligence lifecycle and why is it so important
The course will begin with a baseline assessment designed to understand your starting knowledge, and will end with a final examination to see how you have performed. Those who successfully pass the final exam will be awarded with the arcX Foundation Level Threat Intelligence Analyst (FTIA) certification.
Your Journey
You define cyber threat intelligence in your own words and, more importantly, work out what it actually does: turning gathered threat information into actionable advice that guides security decisions. Through a new analyst's first morning you decide what qualifies as intelligence, whether to focus on yesterday's attack or tomorrow's, and how to describe the purpose of a programme to a manager. You explore how organisations use CTI, the levels of intelligence for different audiences, and the day-to-day role and responsibilities of a CTI analyst.
- You will explain the difference between reacting to current threats and preparing for potential ones
- You will describe how organisations use CTI to prioritise resources and improve incident response
- You will outline the roles and responsibilities of a CTI analyst, from setting intelligence requirements to presenting findings
- You will see why credible, actionable advice is the core measure of an analyst's work
Inside this module
- What is Cyber Threat Intelligence (CTI)?
- What is in a name?
- How do organisations use CTI?
- The Role of a CTI Analyst
- End of Module Assessment
You take the loaded word 'hacker' apart, tracing it back to the MIT Tech Model Railroad Club, and separate white, grey and black hat activity by intent rather than ability. From there you break black hat actors into nation-state operatives, cyber criminals and hacktivists such as Anonymous, and learn why the lines between them are blurring. You meet the CIA triad and study Mandiant's influential APT1 report to understand how advanced persistent threats operate, exfiltrate and reveal themselves.
- You will classify hackers by intent across white, grey and black hat categories
- You will distinguish nation-state actors, cyber criminals and hacktivists and their motives
- You will explain Confidentiality, Integrity and Availability and how organisations weight them
- You will draw practical lessons from the Mandiant APT1 report on how persistent threat groups behave
- You will see why researching threat actors is central to a CTI analyst's curiosity
Inside this module
- Grey, White and Black Hat Hackers
- Breaking Down Black Hat Hackers
- End of Module Assessment
You learn what threat vectors and vulnerabilities look like from an organisation's perspective and how to think about the corporate attack surface as the sum of every possible entry point. Using the analogy of a house with its doors, windows and vents, you see how identifying weaknesses lets you prioritise the most pressing threats. The SolarWinds Orion compromise anchors the module, showing how a single supply-chain vulnerability rippled out to thousands of organisations and even government.
- You will define the corporate attack surface and why mapping it matters
- You will use the house analogy to identify and prioritise potential entry points
- You will examine supply-chain vulnerabilities through the SolarWinds Orion attack
- You will connect attack-surface understanding to mitigation strategy
You walk the intelligence cycle, the framework at the core of CTI, from defining what information is needed through collection, processing, analysis and dissemination. You see how raw data from sources like OSINT, proprietary databases and sensor networks is verified, fused and turned into a coherent picture. You learn how results feed back to inform the next round of collection, keeping an organisation's view of the threat landscape current.
- You will describe each stage of the intelligence cycle in order
- You will identify data sources used in the collection phase, including OSINT
- You will explain the purpose of the dissemination phase for stakeholders
- You will understand why the cycle is continuous and feeds its own future collection
You draw the line between laws as society's rules and ethics as personal or organisational codes, and see why breaching internal guidelines can cost you your job even without legal consequence. You are introduced to the key UK legal articles a CTI analyst should know, from the Computer Misuse Act 1990 to the Data Protection Act, aligned with CREST exam requirements. The Zoetop breach behind Shein and Romwe shows how concealing an incident led to a fine and why honest, early disclosure limits the damage.
- You will distinguish laws from ethics and organisational guidelines
- You will recognise the key UK legal articles relevant to CTI work
- You will understand why blurred legal and ethical lines demand an analyst's caution
- You will draw lessons on breach disclosure from the Zoetop Shein and Romwe case
What You'll Learn
Skills You'll Gain
How This Course Is Delivered
This course is delivered through a combination of interactive content and practical exercises.
Video Content
Immerse yourself in the arcX Cyber Threat Intelligence 101 training course through its core delivery method: video. You'll have access to a comprehensive series of 11 videos, collectively spanning over 2.5 hours of content.
Quizzes
Our bespoke testing engine will ensure you experience a combination of free-form and adaptive tests. These are thoughtfully integrated to reinforce your learning and consistently evaluate your skills.
Practical Exercises
You'll engage in micro-exercises, requiring just a few minutes to complete, and more extensive research projects that extend over hours. Each exercise is structured to gauge your comprehension of various concepts.
Video Content
Included in the course are downloadable intelligence reports and research papers, strategically provided to enhance your understanding of the taught concepts and expand upon them.
Who This Course Is For
This is a deliberately basic, theory-first introduction for anyone weighing up a career in cyber threat intelligence before committing further, as well as those who want a clear grounding in the core concepts.
- Newcomers considering a first step into cyber threat intelligence
- Board executives and non-technical managers overseeing security operations
- Practising threat intelligence analysts wanting a concept refresher
- Penetration testing professionals broadening their perspective
- Cyber security professionals looking to enrich their day-to-day role
Course Details
Instructor
Stewart K Bertram
Stewart has worked within the field of Intelligence and Security for the past 20 years with experience across both the private and public sector. Starting his career in 2004 in the Intelligence Corps of the British Army, Stewart entered the private sector in 2009 and has held a number of roles in Cyber Threat Intelligence (CTI) since then. These have included product development, service delivery and consulting, with his most recent roles involving the management of specialist teams involved in research into the cyber criminal underground and nation state threat actors. Holding both a Masters in Computing and a Master of Letters in Terrorism Studies from St. Andrews University. Stewart was also among the first in the world to pass the CREST Certified Threat Intelligence Manager (CCTIM) examination. Stewart’s research interests and work have always sat at the intersection of technology, security and people focused issues. These unique areas of focus are bought to bare within his role at arcX, where he is responsible for the design and delivery of the core CREST related CTI courses and oversight of the wider Cyber Threat Intelligence stream.
Difficulty Level
Language
en
Available Subtitles
This course sits at the Foundation Level Threat Intelligence Analyst (FTIA) level, introducing the core concepts of cyber threat intelligence.
Trusted by Security Professionals
Join 70,000+ professionals who have advanced their careers with arcX training
"The courses provided by arcX are the best in terms of content and structure I have come across, that are aligned to CREST's CPTIA and CRTIA exams. An absolute must for anyone wanting to pursue these certifications but also anyone wanting to gain a solid baseline knowledge set for a career in CTI."
Chris
Cyber Threat and Risk Manager
"Great content and fantastic customer service. Put me in a great position to gain my qualification. 10/10 recommend."
Dan
Cyber Security Project Manager
"I have done courses in offensive security, networking, forensics and malware. All from prestigious training vendors. None compare to arcX. I secured a straight transition into a senior CTI role. The platform provided me with insights into my strengths and weaknesses and allowed me to track changes. Very grateful to the guys for this!"
Pat
Senior Threat Intelligence Analyst
Frequently Asked Questions
About This Course
General Course FAQs
Click your avatar in the top right corner and select Contact Support, or email us directly at [email protected]. We typically respond within 24-hours.
You will have 12 months access after activating your course in accordance with our Terms & Conditions. You can work through your course at a pace that suits you. Once you have completed your course you will retain access and be able to refresh your knowledge anytime within the access period.
Our courses are delivered on-demand. This means you can start and stop learning whenever you like. There is no time limit and no restriction on how many times you can access course content.
No. CREST exam vouchers need to be purchased separately through CREST or Pearson VUE. You can find further information on our CREST Accreditation page.
Absolutely! Demonstrating your dedication to professional development in cyber security is always valuable. Our certifications are recognised by partner organisations who value our training.
Yes! You can create individual accounts and purchase courses through our portal for instant access. For multiple employees, please contact us for volume pricing.
Yes! We're always happy to speak with industry experts interested in producing high-quality training courses. Become an instructor and help make a positive impact on someone's career.
Can't find what you're looking for? Get in touch
Cyber Threat Intelligence 101
Free