The Number That Should Make Every Vendor Uncomfortable

A recent industry survey found that 91% of CISOs say threat intelligence is valuable. That sounds like a win for the threat intel market. Then you read the second stat: only 26% say that intelligence actually influences their decisions.

Think about that for a moment. Nine out of ten security leaders believe in the concept of threat intelligence. But fewer than three in ten find what they are getting actionable enough to change what they do. That’s not a ringing endorsement, and it seems like a polite way of saying most threat intel feeds are noise.

So, what would actionable threat intelligence look like if 91% of CISOs value it and 100% of that same population let it drive real decisions? It would have to make the required action glaringly obvious, tie that action directly to their specific environment, and arrive before the threat materialized rather than after. That bar is almost never met by a subscription feed.

The Threat Intelligence You Buy vs. The Threat Intelligence You Need

The threat intelligence market has built a very efficient machine for aggregating and redistributing publicly available information: IOC feeds, dark web monitoring, vendor advisories, and geopolitical threat reports. Some of it’s useful. Most of it describes threats you already knew existed, in a format that requires significant effort to operationalize.

The intelligence you actually need is specific to your environment, your industry, your adversary profile, and the tools you run. It should tell your SOC analyst not only that threat actor X is targeting the financial sector, but that a behavioral pattern matching that actor’s tooling was observed in your environment at 2:47 AM on Tuesday.

That kind of useful intelligence requires something the market rarely provides with context. Without context, you are reading weather forecasts for a continent instead of a zip code.

You Are Fighting on Multiple Fronts and Most Are Quiet Until They Are Not

We track the big campaigns. The named ransomware groups, the nation-state actors, the splashy breaches that make the front page of a security conference keynote. Those threats are well documented, heavily researched, and honestly, somewhat predictable.

Here’s the harder truth: what gets organizations is the guerrilla attack. The opportunistic threat actor who’s not running a sophisticated supply chain campaign. They’re scanning for an exposed RDP port, a misconfigured S3 bucket, or a credential-stuffed VPN account. No attribution. No MITRE ATT&CK profile. No prior art in the feeds you are subscribed to.

We write about these constantly. We see them in client environments week after week. They aren’t glamorous. They don’t generate headlines. And they work extraordinarily well because everyone is focused on the sophisticated threat while the quiet, low-effort attack walks through the front door.

Doing true intelligence gathering on every potential adversary, across every attack surface, at the scale of the threat landscape today is genuinely hard. You are conducting an electronic battlefield analysis on actors operating across dozens of countries, with different motivations, different tooling, and different targets. No single organization can cover all of that ground alone.

Doing It Yourself Is Possible. It Is Also Expensive and Incomplete.

Some organizations try to build internal threat intelligence programs. They hire analysts, buy premium feeds, stand up threat platforms, and run their own collection infrastructure. For a large enterprise with the budget and the staff, this approach can work.

For most organizations, especially in state and local government, education, and mid-market commercial, it isn’t realistic. The analysts are expensive. The tooling requires constant tuning. The data still needs to be correlated against your own environment to be actionable. And you’re starting from zero every time a new campaign emerges.

So, organizations do what is reasonable: they buy threat intelligence subscriptions. Not because they expect it to be transformative, but because not having it feels reckless. It’s a reasonable hedge and a cheap double-check. And if something happens and you didn’t have any intel program at all, that’s a hard conversation to have with your board.

The problem is that this calculus keeps a large portion of the industry paying for intelligence that influences exactly zero decisions, which brings us back to the 26%.

Why an Industry-Focused MSSP Closes the Gap

The model that actually works looks different. It isn’t a feed you subscribe to. It’s an organization that has instrumented detection across a broad client base in your vertical, correlates what they’re seeing in real time, and surfaces that signal to you with the context of your specific environment already applied.

At nuHarbor, we run security operations across state and local government, education, utilities, and mid-market commercial clients. What that means in practice is that when a new attack pattern shows up in one client environment, we see it. When the same pattern shows up in a second client two days later, we recognize it. By the time it reaches a third, we have detections tuned and SOAR playbooks drafted, and we can tell you exactly what it looks like in your environment specifically.

That’s threat intelligence that influences decisions because it isn’t abstract. It’s drawn from observed behavior in organizations that look like yours, running infrastructure similar to yours, facing adversaries targeting your sector.

Intelligence sharing across clients is the multiplier. No single organization can see the full picture. A cohort of organizations, watched by an attentive team with the right tooling, can. The breadth of visibility is what turns a raw indicator into a genuine early warning.

The Takeaway for Security Leaders

If your threat intelligence program is not influencing decisions, the problem is almost certainly not the concept. The concept is sound. The problem is the source, the context, and the ability to operationalize what you are receiving.

Ask your current provider how many of their detections came from observed telemetry in your industry versus aggregated open-source feeds. Ask how their intelligence is correlated against your specific environment before it reaches you. Ask whether they’re sharing signal across clients in a way that gives you earlier warning than any single organization could generate alone.

If the answers are vague, you have your answer.

The organizations getting real value from threat intelligence aren’t the ones with the biggest feeds. They’re the ones with the most relevant context. And context, at this scale, comes from shared visibility across an environment that actually looks like yours.

About the author

Justin is the founder and CEO of nuHarbor, where he continues to advance modern integrated cybersecurity services. He has over 20 years of cybersecurity experience, much of it earned while leading security efforts for multinational corporations, most recently serving as global CISO at Keurig Green Mountain Coffee. Justin serves multiple local organizations in the public interest, including his board membership at Champlain College.