Cyber security breaches are repeatedly placed among the top risks by governments and organizations in the private sector. States are revising and improving their national strategies to improve resilience of their critical infrastructure sectors, among them the financial sector. Financial institutions have several motivations to invest and build their own cyber security capabilities. Their services are being increasingly digitized. Cyber security is within the focus of financial regulatory authorities. Financial institutions are being constantly targeted by hacktivists, cyber crime groups, nation-states, or nation-state proxies. Because of these reasons and available resources, financial institutions are in the forefront of developing or adopting novel defensive cyber security capabilities to protect their assets. Two capabilities that stand out are Cyber Threat Intelligence and Red Teaming. The former having a longer history, while the latter is receiving more focus by different regions and regulatory authorities in the recent years. A number of frameworks within the sector were recently developed for conducting intelligence-driven red teaming exercises.In this talk, I will focus on two capabilities – Cyber Threat Intelligence and Red Teaming. I will begin by exploring frameworks for the purposes of intelligence analysis. Next, I will focus on the role of red teaming, and I will argue why traditional methods of security assessments and testing, are no longer sufficient to assure resilience against sophisticated cyber attacks. Then, I will discuss the interplay of the two capabilities captured by different frameworks for conducting intelligence-driven red teaming exercises. And finally, I will compare exercises in the financial sector with cyber defense exercises such as Locked Shields and Crossed Swords.