Since the publication of Mandiant’s APT1 report in 2013, cyber threat intelligence discipline has been widely adopted by organisations globally. We have observed success stories as well as fails of organisations trying to develop CTI capabilities or, in other words, adding value to business. As a community, it is critical to capture the relevant lessons learned and conduct a status check for these 5 years of applied CTI discipline. The utmost goal of this presentation is to identify the areas that organisations should put more focus on. Based on our assessment, we identify and deep dive into the three major areas where most current CTI teams struggle: 1) intelligence direction (such as stakeholder identification and collection of intelligence requirements), 2) intelligence reporting and dissemination and 3) CTI analyst's skill set. Key takeaways of this presentation include: the realization of the significance of intelligence requirements for the intelligence cyclehow proper stakeholder identification increase situational awarenesshow classic intelligence approaches can be applied to CTI productionsuccess stories on disseminating intelligence products and capturing feedbackunderstanding the variety of competencies of CTI teams and ways of baselining analysis process within CTI teams.