Writing · Threat Intelligence
What most organisations get wrong about threat intelligence
By Mahmoud Lotfy · Mar 2026 · 7 min read
Let me tell you what actually happens when most organisations buy a threat intelligence product.
They get a dashboard. The dashboard has feeds: IOCs, threat actor profiles, TTPs mapped to MITRE ATT&CK. It looks impressive in a slide deck. The CISO presents it to the board as evidence that the security team is being proactive. Everyone feels good about it.
Then nothing changes.
"Intelligence is something more specific: it tells you something about your environment that changes what you do next."
The alerts come in. The analysts look at them, maybe action a few, mostly scroll past. The threat actor profiles sit in a tab nobody opens. The IOC feeds get ingested into the SIEM and forgotten. Six months later, someone asks what value they're getting from the platform. Nobody has a good answer. The renewal comes up and they pay it anyway because cutting it would look bad.
I've seen this play out more times than I can count. And the frustrating thing is it's not a technology problem. It's a thinking problem.
Data is not intelligence
This is the distinction that most programs never actually make.
Data is raw. A list of malicious IP addresses is data. A feed of known malware hashes is data. Information is data that's been processed, you've looked at it and understood what it means. Intelligence is something more specific: it's information that's actionable, that tells you something about your environment, that changes what you do next.
Most threat intelligence programs are buying data and calling it intelligence. The leap from one to the other requires human judgment, context, and an understanding of your own organisation's attack surface. That's the part that can't be automated and the part that most programs skip entirely.
Three reasons it fails
The first is that it's disconnected from the business. I've seen organisations with detailed threat actor profiles for groups that have zero interest in their industry, their geography, or their technology stack. Somebody built the profile because it was technically impressive, not because it was relevant. Threat intelligence that doesn't map to your actual attack surface isn't intelligence, it's trivia.
The second is that it reaches the wrong people. Analysts get the feeds. They're busy, they're dealing with alerts, they don't have time to synthesise raw data into something meaningful. The people who actually make security decisions, the CISO, the risk committee, the board, get a summary slide once a quarter that tells them nothing useful. The gap between raw intelligence and the people who need to act on it is where most programs die.
The third is that there's no feedback loop. Intelligence that doesn't inform a decision or change a control is just noise. If your threat intel team produces a report and nothing in your environment changes as a result, no patch gets prioritised differently, no detection rule gets updated, no playbook gets revised, then you haven't produced intelligence. You've produced a document.
What good actually looks like
A threat intelligence program that works starts with a question, not a feed. What are we actually trying to understand? Who would want to attack us, and why? What does our environment look like from the outside? Those questions drive what intelligence you collect, how you process it, and who needs to see it.
It feeds into real decisions. Your threat intel should be informing patch prioritisation, which CVEs are actually being exploited against organisations like yours, right now. It should be feeding your incident response playbooks. If you know which threat actors are relevant to your sector, you can pre-build detection logic for their TTPs before you need it. It should be reaching leadership in a language they understand, not IOC counts, but business risk.
And it should close the loop. When a piece of intelligence leads to a control change, document it. When it doesn't, ask why.
The honest version
You don't need more data. The problem has never been a shortage of threat data, there's more of it than anyone could ever process. What most organisations actually need is less data, processed by people who understand the business, reaching the people who can act on it.
One piece of intelligence that changes a decision is worth more than ten thousand IOCs that nobody looks at.
The hardest part of building a good threat intelligence program isn't technical. It's getting people to agree on what questions they're actually trying to answer, and being disciplined enough to only collect what helps you answer them.
Everything else is noise.