Blog

Intelligence as the Connective Tissue for Information Operations

Written by David Hopkins | 20 July 2026 8:00:00 PM

David Hopkins, IIP Director and Head of Learning, is presenting the ideas behind this article at the Global Information Summit Australia 2026 in Adelaide. He'll be speaking on Tuesday in Stream B, "Applying Information Advantage: Lessons from Conflict and Competition," making the case that intelligence is the connective tissue binding information operations into a coherent, measurable capability. Drawing on case studies spanning counter-terrorism, counter-extremism messaging, and Australia's own Black Summer bushfires, his session shows what that looks like when it's built deliberately, and what's lost when it isn't. The full program is available on the summit's website

The Decision Gap

In 2009, Australian Special Forces in Afghanistan had access to something that felt like omniscience. A Heron unmanned aerial system was feeding real-time full-motion video directly into the command centre. Commanders could watch events unfold from altitude with a clarity that would have been unimaginable a decade earlier. But the improved picture still wasn't producing better decisions.

A live feed does not equal understanding. A single sensor feed, however detailed or continuous, doesn't generate intelligence value on its own. That value comes from correlating multiple sources and applying structured analytical tradecraft to produce an assessment a decision-maker can act on. The feed showed what was happening. Intelligence would have explained why, who was involved, and what was likely to happen next.

This gap between data and decision advantage, the capacity to observe without the analytical architecture to act on what's observed, isn't confined to the battlefield. It's the defining problem of the modern information environment. Governments, defence organisations, and industry are investing heavily in AI-enabled platforms, data-collection capabilities, and information-operations tools. Investment in sensing and collection continues to accelerate. The intelligence methodology needed to turn that data into decisions isn't keeping pace.

Before the information age, advantage came from controlling and constraining information. Today, it comes from making sense of an environment already flooded with data, where intelligence functions sit at the centre of both audiences' cultural understanding and the analytical work of verifying facts.

Many organisations invest heavily in capability that generates activity rather than effect. They collect data that never aids decision-making, and they run operations with no reliable way to gauge its effect. This gap is due to a lack of methodology and training, rather than a lack of technology.

Two propositions follow, and the rest of this paper develops each in turn.

    • Proposition One. Intelligence is the connective tissue of information operations. Without it, the other components produce activity that can't be measured, targeted, or controlled.
    • Proposition Two. Professionalisation, built around intelligence methodology, is the mechanism that builds this capability across sectors and at scale.

Intelligence and Information Operations as One Function

Defining the Information Environment

The information environment is the sum of individuals, organisations, and systems that collect, process, disseminate, or act on information. It has three dimensions.

    • Cognitive – the perceptions, beliefs, and decision-making of individuals and populations
    • Informational – the content, data, and systems that carry it
    • Physical – the infrastructure, platforms, and people that operate within it

These dimensions don't separate cleanly in practice. A cyberattack on communications infrastructure is also an act of cognitive disruption, designed to erode confidence and sow confusion. A narrative campaign is also an informational and technical operation that requires the collection, analysis, production, and dissemination of information. Operations that treat these as separate problems, handled by separate people in separate organisations, consistently fail to achieve integrated effects. This framework is drawn from the Information Power Institute Australia's information power model, and it grounds the argument that follows. The most consequential operations, and the case studies in this paper, sit where all three dimensions intersect.

Figure 1 - The information environment as three interrelated dimensions.

Intelligence is the Connective Tissue

In the information environment, the space between observing something and having what's needed to act on it is the decision gap. Intelligence closes this gap and runs through operations the way connective tissue runs through the body, binding them into one working system.

Information operations that run without intelligence methodologies produce content for undifferentiated audiences. There's no way to tell whether an operation achieved its intended effect, or to warn that an adversary has already achieved one. Intelligence produced without a connection to operations has the opposite problem, an assessment that never reaches a decision-maker in a form they can act on is analytically sound and operationally useless. Both failures were caused by intelligence and operations being treated as separate functions rather than as a single connected system.

The stakes are highest for democracies. Adversaries have evolved to run information operations that target populations directly, since votes determine who holds decision-making authority. The cognitive effects on a population today shape the political authority of decision-makers tomorrow. Warning a population of these operations before their narrative shapes debate is more effective than correcting it afterwards.

Building that connective tissue in practice means extending intelligence methodology into how operations are planned and run. The next section sets out what that looks like.

How Intelligence Enables Operations

Two methodologies do most of the work of making information operations coherent, targeted, and measurable. Target Systems Analysis (TSA) tells you what you're up against and where to apply pressure. Target Audience Analysis (TAA) tells you who you're trying to reach and how to reach them in ways that shift behaviour. Both are established, unclassified intelligence tradecraft.

Target Systems Analysis

TSA is a four-step process.

    • Characterise the environment and the problem
    • Characterise the target system
    • Develop options
    • Develop strategy

The second step is where most practitioners without intelligence training go wrong. It's easy to treat a target as a single node, a person, an account, a piece of infrastructure, and design an operation around removing or disrupting that node. TSA done properly asks a harder question: how does this system function, what makes it resilient, and where does pressure produce a lasting effect rather than a temporary one?

Target Audience Analysis

TAA is a five-step process, adapted from behavioural and diagnostic modelling approaches.

    • Define the behavioural problem
    • Identify and prioritise audiences
    • Diagnose behaviour
    • Develop intervention logic
    • Develop measurement logic

TSA and TAA are complementary disciplines. TSA tells you what the system looks like and where its pressure points are. TAA tells you which audiences within or around that system need to change their behaviour, and what would cause that change. An operation that characterises its target system correctly but skips audience diagnosis is likely to misfire; it'll apply pressure to the right structural point while speaking to the wrong people in the wrong way.

The reverse is just as true. An operation that diagnoses its audience correctly but skips characterising the target system will still misfire. It might reach and persuade exactly the audience it intended to, but have no way of knowing whether that audience actually holds any influence over the system it's trying to shift.

Tactical vs Systemic Understanding

TSA's second step, characterising the target system, is where tactical and systemic understanding diverge. Treating a target as a single node results in analysis that stops at the removal of the target. Treat it as a system, and the analysis uncovers what makes that system resilient in the first place and where to apply pressure for maximum effect. Leadership decapitation in counter-terrorism is the clearest test case. It’s a purely tactical approach, applied for decades and studied across more than a thousand instances, giving a rare chance to see whether removing a node without understanding the system around it works.

Jenna Jordan's research finds that decapitation's effectiveness depends heavily on organisational resilience, specifically an organisation's bureaucratisation and communal support.[1] Her analysis draws on leadership targeting against groups including al-Qaeda, Hamas, and ISIS. Older, larger organisations with clear succession processes tend to survive the loss of a leader. Bryan Price's analysis of the same phenomenon arrives at the same conclusion from a different angle. He finds decapitation does increase group mortality on average, but that the effect weakens as organisations age.[2] Even Price's more favourable findings only hold up against organisations that are still simple, young networks. Complex, resilient systems are exactly what TSA's second step is designed to characterise properly.

General Stanley McChrystal's restructuring of the Joint Special Operations Task Force in Iraq shows what fully applying TSA's second step looks like. When he took command in 2003, conventional tactics were failing against a decentralised adversary that could move fast, strike, and disappear into the population. McChrystal rebuilt the task force itself into a network, flattening decision-making, breaking down the silos between operators and analysts, and pushing information sharing down to the smallest teams.[3] He described the task force evolving from a network of people into a network of teams, then organisations, then nations, becoming what he called a ‘team of teams.’[4]

The system was understood as a network, rather than reduced to a list of nodes to remove, and the results were measurable. Raids increased from roughly four a month in 2003 to around 300 a month by 2006, a tempo shift that led directly to the operation that killed the leader of al-Qaeda in Iraq (AQI), Abu Musab al-Zarqawi, that June.[5]

Audience-Blind vs Audience-First

TAA's third step is to diagnose behaviour and research what an audience actually believes before designing a response. If that step is skipped, the response is built without evidence as to whether it will produce the intended behavioural change. This is what is referred to as "audience-blind." Complete the "audience-first" step, and the response is built around what will change minds. Think Again Turn Away, a US State Department counter-messaging campaign, is one of the clearest audience-blind examples.

The US State Department's Think Again Turn Away campaign, launched in December 2013 through the Centre for Strategic Counterterrorism Communications, is a useful illustration of what happens when audience diagnosis is absent. The campaign's Twitter account engaged directly with jihadist accounts, arguing with them and countering their claims in public. Contemporary analysis at the time, including that of terrorism researcher Rita Katz, argued that the approach gave extremist accounts a public stage rather than countering them, and that understanding the audience's actual mindset should have come before designing the response.[6] Counter-messaging without audience diagnosis tends to talk past, or even amplify, the narrative it's trying to counter.

Google Jigsaw's Redirect Method took the opposite approach. In 2012, Jigsaw's Yasmin Green built the Against Violent Extremism network, the first global network of former violent extremists and survivors of terrorism. Drawing on her own interviews with ISIS defectors and jailed recruits, Green developed a method that used targeted advertising to intercept people actively searching for extremist content and redirect them toward curated counter-narrative material.[7] An independent RAND evaluation found that people searching for extremist content clicked on the counter-narrative ads at a rate comparable to standard industry benchmarks, though the evaluation explicitly stopped short of measuring whether the content changed anyone's attitude or behaviour.[8] That grounding in direct audience research is what got the right content in front of the right people. Whether it changed minds remains an open question, a reminder that exposure and effect are not the same thing.

A later academic review found Jigsaw's own execution to be inconsistent, with some high-risk search terms producing very little counter-narrative content at all.[9] The underlying audience diagnosis proved sound despite those execution gaps, revealing that TAA is not a one-time exercise. An audience diagnosis that isn't maintained and re-tested degrades over time.

Delayed Diagnosis: Australia's #ArsonEmergency

Australia has its own case study in the cost of skipping audience diagnosis. During the 2019 to 2020 bushfire season, false narratives blaming arson and inadequate backburning for the fires spread rapidly on Twitter under the hashtag #ArsonEmergency. Peer-reviewed research documented bot-like and troll-like behaviour driving much of the hashtag's spread, alongside genuine engagement from people who believed the narrative.[10] The narrative wasn't corrected through a planned, audience-diagnosed intervention. It shifted only after a ZDNet article by journalist Stilgherrian exposed the coordinated activity in January 2020, at which point mainstream media picked up the story and authorities, including the Rural Fire Service and Victorian Police, moved to counter it directly.[11]

The correction happened only because a journalist exposed the activity. No one had diagnosed the audience driving the narrative or designed a response in advance. In the weeks before that exposure, the arson narrative spread largely unchecked, obscuring climate change's role in the fires' severity and leading many to deny that link altogether, a denial the Rural Fire Service and other authorities then had to address directly. Researchers studying the episode noted a familiar pattern behind the denial, a documented tactic of climate disinformation campaigns more broadly, that of discrediting the scientific and expert consensus rather than engaging with it.[12]

Intelligence’s Connective Tissue in Practice

The previous section showed the mechanics of how intelligence enables operations, TSA and TAA done well, done late, or skipped entirely. Intelligence is the connective tissue, binding operations together. Sometimes that binding tightens until the two are indistinguishable. The examples below sit at the two extremes, one where publishing intelligence was the operation itself, and one where the TSA component of the work existed but the TAA component was missing, and a narrative ran unchecked for years as a result.

Where Intelligence is the Operation: Ukraine, 2022 to present

Russia's objectives in the opening phase of its invasion of Ukraine were to control the narrative, fracture Western unity, and suppress Ukrainian resistance by creating an impression of inevitable defeat. It launched the Viasat satellite attack in the opening hours to degrade Ukrainian command and communications.[13] This was timed alongside a series of pre-planned false flag narratives intended to attribute the start of the conflict to Ukraine and its Western backers.[14] Had those narratives taken hold, governments uncertain about who started the conflict would have moved far more slowly to coordinate support for Ukraine.

The allied response countered this directly. From January 2022, the US and UK released declassified intelligence assessments warning of Russian troop movements and false flag preparations, well before the invasion began.[15] By making that intelligence public, allied governments pre-empted the false flag narratives and ensured the international community had a verified picture of Russian intent before the first shot was fired. Publishing the intelligence was the operation. Russia's narrative framing failed in the opening hours because the conditions for misattribution had already been denied.

Where Intelligence is Incomplete: Operation Ghostwriter, 2017 to present

Operation Ghostwriter has targeted Poland, Lithuania, and Latvia since 2017. Germany and the European Union initially attributed the activity to Russian military intelligence,[16] though subsequent technical analysis by Mandiant linked the campaign more directly to Belarusian operators, with likely Russian collaboration.[17] The operation compromised government websites and email accounts to plant fabricated content, forged military communiqués, invented policy statements, and fake correspondence attributed to real officials, all designed to make it appear that NATO officials and member-state governments were themselves questioning the alliance's value.[18]

The operation ran largely unchallenged for several years before attribution was achieved. No intelligence collection or analysis was tracking a hybrid operation like this one, so the narrative effect accumulated while the defender didn't know who was producing it or why. Applied early, TSA would have characterised the network behind the operation, and TAA would have flagged the audiences it was targeting, years before Mandiant's attribution eventually caught up.

Ghostwriter hasn't stopped since Mandiant's attribution. It has expanded to target Belarusian opposition activists alongside its original NATO-focused targets, and during Russia's 2022 invasion of Ukraine, it defaced Ukrainian government websites and ran phishing campaigns against Ukrainian military personnel.[19] The response since has stayed almost entirely technical, tracking infrastructure and attributing new activity as the group evolves.[20] The audience side has had far less attention; little is publicly known about which specific audiences the fabricated content targets or why those audiences find it credible.[21] TAA would close that gap by identifying those audiences directly and diagnosing what makes the fabricated narratives land with them. That would give defenders something to build a counter-response around, rather than only tracking the infrastructure that produces it.

Professionalisation and a Shared Discipline Across Sectors

Intelligence is the connective tissue that provides information operations with the methodology needed to plan, execute, and quantify effectively. TSA and TAA are some of its practical applications. Intelligence methodology only becomes connective tissue across sectors if it's applied consistently, with the same standards and the same language, wherever it's used. This is achieved through professionalisation, which involves training, shared standards, and a common professional identity.

What Happens Without Intelligence Training

Many information operations today across different sectors are conducted without an intelligence methodology. Practitioners instead lean on marketing frameworks, such as demographic and psychographic audience segmentation, borrowed from commercial advertising. Engagement metrics, likes, shares, and reach might appear useful, but they do not accurately indicate whether any changes occurred or if operations were effective. Where no framework exists at all, institutional instinct fills the gap, a practitioner's accumulated feel for what has worked before, which holds up only until the environment shifts.

These substitutes produce predictable failure modes. Confirmation bias shapes targeting toward conclusions practitioners already hold. Poor source validation lets narratives through unchecked, sometimes reinforcing the very narrative the operation was meant to counter. Without intelligence training, practitioners also struggle to distinguish influence from manipulation, leaving them unable to tell whether their own operations fall within the ethical and legal boundaries their organisations expect.

These practitioners work across government, defence, and industry. Military information warfare planners, policy officers in national security agencies, public communicators during emergencies, and corporate communications and risk professionals in finance, mining, and critical infrastructure all do work that depends on this discipline, whether or not they've had the training for it.

IIP's Role

The Institute for Intelligence Professionalisation is developing an intelligence training framework towards nationally recognised qualifications, creating portable intelligence literacy across sectors. This builds on the intelligence training continuum developed for Australia's Defence intelligence workforce, which demonstrated that structured professional development in intelligence practice works at scale and translates across very different operational contexts.

For information operations specifically, training centres on TSA and TAA, generalisable tradecraft, alongside structured analytical techniques and the adjacent skills of producing and delivering intelligence products, reports, briefings, and presentations. That shared foundation is what allows a government analyst, an industry communications lead, and an academic researcher to discuss the same operation using the same language and the same standard of evidence. The Australian Institute of Professional Intelligence Officers (AIPIO) already demonstrates what that shared identity looks like at a national level. AIPIO is a membership organisation spanning national security, defence, law enforcement, regulation, business, industry, and academia, held to a common code of ethics since 1990. IIP works closely with AIPIO, so practitioners trained through IIP can become recognised members of the profession.

A Shared Responsibility

Shared responsibility means both sides have work to do; other sectors must work to adopt the intelligence discipline, and the intelligence community must open to meet them. Skipping either has a real operational cost. For example, a critical infrastructure operator and a government analyst can see the same hostile narrative and still fail to coordinate a response, one side lacking the methodology, the other withholding what it knows. The intelligence community has, at times, been part of the problem, siloed, classification-bound, and slow to share with partners outside government. Professionalisation must work outward, extending this discipline into sectors that have never had formal intelligence training, and inward, building a greater openness within the intelligence community itself to working alongside those sectors.

Intelligence tradecraft, TSA and TAA, among them, must be common currency across the practitioners who need it, wherever they operate. Two practitioners who can't exchange sensitive material can still coordinate if they're both trained to the same standard and trust each other's assessments. IIP is dedicated to producing a professional, highly trained, and connected intelligence community.

Conclusion

The 2009 Afghanistan story that opened this article is, at its core, a story about a gap between what an organisation could see and what it could do with what it saw. That gap hasn't closed in the seventeen years since. It's widened because the volume and speed of information now flowing through every sector has grown faster than the analytical discipline needed to make sense of it.

Intelligence becomes connective tissue through deliberate construction. That means treating intelligence methodology, TSA and TAA, foremost among them, as core professional practice rather than a specialist add-on. It also means training practitioners to apply intelligence methodology regardless of which sector they sit in.

Professionalisation across sectors is how that connective tissue gets built at scale. This involves training, shared standards, and a common professional identity. Practitioners doing this work, wherever they operate, can then apply the same methodology, use the same language, and meet the same standard.

Intelligence and defence organisations already use intelligence methodology in their information operations. Professionalisation, the work of turning intelligence into a shared discipline across sectors, is still underway, and other sectors now have a role to play. That means treating intelligence methodology as core professional infrastructure for information operations and building the training pathways that make that discipline portable across every sector that needs it.

References and Sources

Bey, J. (2018, May 17). YouTube's efforts to combat extremist videos falling short, researchers say. CBS News. https://www.cbsnews.com/news/youtube-extremist-videos-redirect-pilot-program-efforts-falling-short-researchers-2018-05-17/

Council of the European Union (2021, September 24), Declaration by the High Representative on behalf of the European Union on respect for the EU's democratic processes. https://www.consilium.europa.eu/en/press/press-releases/2021/09/24/declaration-by-the-high-representative-on-behalf-of-the-european-union-on-respect-for-the-eu-s-democratic-processes/

Council of the European Union (2022, May 10), Russian cyber operations against Ukraine: Declaration by the High Representative on behalf of the European Union. https://www.consilium.europa.eu/en/press/press-releases/2022/05/10/russian-cyber-operations-against-ukraine-declaration-by-the-high-representative-on-behalf-of-the-european-union/

Dover, R. & Goodman, M. S. (2024). Intelligence warning in the Ukraine war, Autumn 2021 to Summer 2022. Intelligence and National Security. https://doi.org/10.1080/02684527.2024.2322214

European Repository of Cyber Incidents. (2023). Advanced persistent threat profile: UNC1151. https://eurepoc.eu/wp-content/uploads/2023/05/EuRepoC-APT-profile-UNC1151.pdf

Green, Y. (2019, January 28). Google algorithms and human psychology: How Jigsaw rescues teens from ISIS recruiters. Fast Company. https://www.fastcompany.com/90294876/how-jigsaw-is-using-ai-human-connections-and-adwords-to-fight-isis

Helmus, T. C., & Klein, K. (2018). Assessing outcomes of online campaigns countering violent extremism: A case study of the Redirect Method. RAND Corporation. https://doi.org/10.7249/RR2813

Institute for Intelligence Professionalisation (n.d.). Available at: https://intelprofession.com/

Jordan, J. (2014). Attacking the Leader, Missing the Mark: Why Terrorist Groups Survive Decapitation Strikes. International Security, 38(4), 7-38. https://doi.org/10.1162/ISEC_a_00157

Jordan, J. (2019). Leadership Decapitation: Strategic Targeting of Terrorist Organizations. Stanford University Press. https://www.sup.org/books/politics/leadership-decapitation

Katz, R. (2014, September 16). The State Department’s Twitter War with ISIS is Embarrassing. Time. https://time.com/3387065/isis-twitter-war-state-department/

Mandiant. (2021, November 16). UNC1151 assessed with high confidence to have links to Belarus, Ghostwriter campaign aligned with Belarusian government interests. https://cloud.google.com/blog/topics/threat-intelligence/unc1151-linked-to-belarus-government/

McChrystal, S. (2013). Lesson from Iraq: It Takes a Network to Defeat a Network. LinkedIn, 21 June 2013. https://www.linkedin.com/pulse/20130621110027-86145090-lesson-from-iraq-it-takes-a-network-to-defeat-a-network

McChrystal, S., Collins, T., Silverman, D. & Fussell, C. (2015). Team of Teams: New Rules of Engagement for a Complex World. Portfolio/Penguin. https://www.penguinrandomhouse.com/books/317066/team-of-teams-by-general-stanley-mcchrystal-tantum-collins-david-silverman-and-chris-fussell/

Mocatta, G., & Hawley, E. (2020). Uncovering a climate catastrophe? Media coverage of Australia's Black Summer bushfires and the revelatory extent of the climate blame frame. M/C Journal, 23(4). https://doi.org/10.5204/mcj.1666

Page, C. (2022, February 25). Ukraine says Belarusian hackers are targeting its defense forces. TechCrunch. https://techcrunch.com/2022/02/25/belarus-hackers-ukraine/

Price, B. (2012). Targeting Top Terrorists: How Leadership Decapitation Contributes to Counterterrorism. International Security, 36 (4): 9–46.. https://doi.org/10.1162/ISEC_a_00075

Stilgherrian. (2020, January). Twitter bots and trolls promote conspiracy theories about Australian bushfires. ZDNet. https://www.zdnet.com/article/twitter-bots-and-trolls-promote-conspiracy-theories-about-australian-bushfires/

UK National Cyber Security Centre (2022, May 10). Russia behind cyber attack with Europe-wide impact an hour before Ukraine invasion. https://www.ncsc.gov.uk/news/russia-behind-cyber-attack-with-europe-wide-impact-hour-before-ukraine-invasion

Weber, D., Nasim, M., Falzon, L. & Mitchell, L. (2020). #ArsonEmergency and Australia's "Black Summer": Polarisation and Misinformation on Social Media. In M. van Duijn, M. Preuss, V. Spaiser, F. Takes, & S. Verberne (Eds.), Disinformation in open online media: MISDOOM 2020 (Lecture Notes in Computer Science, Vol. 12259). Springer. https://doi.org/10.1007/978-3-030-61841-4_11

AI Use Disclosure

This paper was developed with AI assistance for research, structuring, and editing for clarity. All ideas, arguments, and conclusions are those of the author. Final responsibility rests with the Institute for Intelligence Professionalisation in accordance with IIP's AI Use Policy.

[1] Jordan (2014, 2019).

[2] Price (2012).

[3] McChrystal et al. (2015).

[4] McChrystal (2013).

[5] McChrystal et al. (2015).

[6] Katz (2014).

[7] Green (2019).

[8] Helmus & Klein (2018).

[9] Bey (2018).

[10] Weber et al. (2020).

[11] Stilgherrian (2020).

[12] Mocatta & Hawley (2020).

[13] UK National Cyber Security Centre (2022); Council of the European Union (2022).

[14] Dover & Goodman (2024).

[15] Dover & Goodman (2024).

[16] Council of the European Union (2021).

[17] Mandiant (2021).

[18] Mandiant (2021).

[19] Page (2022).

[20] European Repository of Cyber Incidents (2023).

[21] European Repository of Cyber Incidents (2023).