Category /

Threat Intelligence Reports Are Not the Same as Threat Intelligence

Threat Intelligence Reports Are Not the Same as Threat Intelligence

Most organisations subscribing to threat intelligence feeds are not doing threat intelligence. They are doing threat notification. A feed tells you what happened somewhere else, to someone else, on infrastructure that may or may not resemble yours. That is not the same as knowing what threatens you.

The distinction sounds pedantic until you sit in a security committee meeting and ask a simple question: which of the fifteen threat actors named in this month’s briefing pack actually target our sector, our region, and our technology stack? In most organisations, nobody can answer that question with confidence. The briefing pack gets read, the acronyms get repeated, and the meeting moves on.

What most programmes actually have

Strip away the branding and most “threat intelligence programmes” are a subscription, a mailing list, and a person whose job is to forward PDFs. The feed itself is often high quality. The problem sits downstream of it. Nobody has built the layer that takes a generic indicator of compromise and asks whether it maps to anything in the organisation’s actual attack surface.

This produces two failure modes, and organisations tend to alternate between them depending on who is in the room. The first is noise blindness, so many alerts arrive that the security team stops reading them closely, because reading closely has never once changed a decision. The second is theatre, a slide is built for the board showing threat actor logos and MITRE ATT&CK tactics, giving the impression of sophistication that the underlying process does not support.

Neither failure mode is really about the feed. Both are about the absence of a triage function that connects external threat data to internal risk context; what assets exist, what they are worth, and what would actually happen if a given technique were used against them.

Why this gap persists

Threat intelligence tooling is easy to buy and hard to operationalise. A platform subscription is a procurement decision with a clear owner and a defined budget line. Building the analyst function that turns raw intelligence into prioritised, contextualised action is a staffing and process decision, and it is far less visible on a vendor’s sales deck. So organisations buy the tooling, tick the box, and quietly defer the harder work of building the function around it.

There is also an incentive problem specific to security vendors. A feed provider is paid whether or not the intelligence changes any decision inside the client organisation. Nobody’s renewal depends on whether the client actually used the data to reprioritise a patch cycle or adjust detection logic. The measurement gap is structural, not accidental.

What functioning threat intelligence requires

A threat intelligence capability that does something has three components most feed subscriptions lack.

The first is asset and exposure mapping; a current, accurate picture of what the organisation runs, where it runs, and what depends on it. Without this, no amount of external intelligence can be prioritised, because prioritisation requires knowing what is actually at stake.

The second is a confidence and relevance scoring discipline. Not every report warrants the same weight. Distinguishing a confirmed, sector-specific campaign from a speculative, unconfirmed one is analytical work, not a filter setting. Organisations that skip this step end up treating every alert with equal urgency, which in practice means treating none of them with real urgency.

The third is a documented feedback loop from intelligence to action: detection rule changes, patch reprioritisation, control adjustments; with a record of what changed and why. Regulators examining incident response maturity under frameworks like NIS2 and DORA are increasingly asking for exactly this evidence trail. A feed subscription with no downstream action log does not satisfy that expectation, however comprehensive the feed itself is.

In practice

In practice, the organisations that get this right tend to be smaller and less resourced than the ones that get it wrong. Scale does not produce discipline; it produces more dashboards. What separates a functioning programme from a decorative one is usually a single analyst function (sometimes one person, part-time) whose explicit job is to ask “does this matter to us, and if so, what changes because of it?” before anything reaches a report or a board slide.

This does not require replacing the feed. It requires building the fifteen percent of the process that the feed provider was never going to build, because it is specific to one organisation’s risk profile and cannot be productised. The threat landscape briefing that lists actor names and campaign summaries is the easy part. The harder, more valuable work is the quiet judgment call about which of those names should change what the organisation does on Monday morning.

That judgment call is the actual intelligence. Everything upstream of it is just information.

Share the Post:

More Posts

Identity Is the Perimeter. Governance Hasn’t Caught Up.

The perimeter security model is functionally obsolete for most organisations. The network boundary that once defined the security boundary has dissolved replaced by a distributed architecture in which users, services, and data operate across environments that no firewall can meaningfully contain. Identity has become the effective perimeter. Credentials determine what

Read More

The Board Asked About Cyber Risk. Nobody Had a Good Answer.

Board members are asking better questions about cyber risk than they were five years ago. The answers they are receiving have not kept pace. That gap is not primarily a knowledge problem. It is a structural one, and it produces consequences that extend well beyond uncomfortable boardroom conversations. The mismatch

Read More