
Episode #4
Bringing CTI to the Executive Table - Interview with Jan Henrik Schou Straumsheim S3E4
Jan Henrik Schou Straumsheim, a partner in PwC's cyber advisory practice, sits down with host Freddy Murre to talk about the real work behind cyber threat intelligence. His interest in the field traces back to getting his hands on his father's old 386 computer and a book his mother gave him on the history of codes, and later took shape during years as a reserve infantry officer in Norway's armed forces, where he trained at the Defense Intelligence School and eventually became his unit's intelligence officer (S-2). From there, his career moved through a summer internship at Accenture, a part-time job in the security operations center at mnemonic, a pivot into consulting, and almost a decade now at PwC. The conversation explores what actually separates CTI from cybersecurity, and why so much of what gets sold as intelligence is really just unfiltered data dumps. Jan Henrik and Freddy debate how analysts should weigh sources, including the tricky question of trusting personas on dark web forums, then turn to how private-sector teams train and retain analytical skill, and why Nordic organizations still lag in treating CTI as more than a detection add-on. Jan Henrik shares a real client case, where a board commissioned a foresight report on AI risk, showing what it looks like when CTI actually reaches the boardroom. The conversation then shifts to AI's role in intelligence work: how Jan Henrik uses large language models every day, why he still insists on a human checking every output before his name goes on it, and where the line sits between AI as a sparring partner and AI replacing analytical judgment altogether. They close on a reminder that opportunity often comes from someone else opening a door, and why passing that on matters. This episode with Jan Henrik is a grounded, occasionally blunt conversation about what good intelligence work actually requires, well worth a listen for anyone trying to make CTI matter to the business it's meant to serve. RESOURCES simon singh the code book - https://www.amazon.com/dp/0385495323 Mnemonic Internships - https://www.mnemonic.io/no/careers/internships/ Hatlebrekke The Problem of Secret Intelligence - https://www.amazon.com/dp/0748691839 Freddy's SANS CTI Summit presentationFrom Gut to Gold Standard: The Admiralty System in CTI - https://youtu.be/y-CSDxMMXb0?t=5 Freddy's SANS posts on Admiralty Scale - https://www.sans.org/profiles/freddy-murstad#resources SANS Cybercrime Investigations - https://www.sans.org/cyber-security-courses/cybercrime-investigations Washington D.C. police gaming crime statistics - https://www.washingtonpost.com/dc-md-va/2026/05/08/dc-police-crime-statistics-internal-investigation-findings/ Research article Non-Determinism of “Deterministic” LLM System Settings in Hosted Environments - https://aclanthology.org/2025.eval4nlp-1.12/ Research article Cognitive offloading, critical thinking and attitudes towards artificial intelligence https://pubmed.ncbi.nlm.nih.gov/42377671/ Freddy's LinkedIn Profile -https://www.linkedin.com/in/fmurre/ CHAPTERS 0:00 Early path into cybersecurity 2:12 From mnemonic's SOC to PwC 8:27 Building PwC's global CTI arm 10:38 CTI versus cybersecurity defined 11:45 Military intelligence background 18:40 What actually counts as intelligence 20:05 Separating good intel from bad 26:19 Training and upskilling analysts 32:57 CTI maturity across the Nordics 41:20 Linking CTI to enterprise risk 50:28 Building a successful CTI function 56:30 Measuring CTI's real value 1:03:12 AI's rapid rise in CTI 1:14:51 AI risks and human oversight 1:26:01 Career-defining opportunities and mentorship






