Most security teams I speak with have threat intelligence. Far fewer have threat intelligence that changes what they actually do on Monday morning.
The pattern is familiar enough that I can usually predict it. A feed gets purchased and a platform gets deployed. Indicators start arriving by the hundred thousand. Someone on the team writes a weekly summary of what the major vendors published, sends it out to a distribution list, and a handful of people skim it on their phones during a meeting. Then the week starts and the SOC works the same alerts it worked the week before, using the same detections, and missing the same things it was already missing.
That is not an intelligence program. That is a newsletter with a security budget attached to it.
I raise this not to be cynical but because the gap between saying “we have CTI” and being able to say “our CTI measurably improves our defenses” is where most of the money quietly disappears. It is also a gap that can be closed without buying anything new.
The Handoff That Nobody Owns
Here is a question worth asking your own team. When a major threat actor report lands, who is responsible for deciding whether you would have caught that activity in your own environment?
In my experience there is usually a long pause before anyone answers. The intelligence analyst says they circulated the report. The detection engineer says nobody raised a specific request. The incident response lead says they read it and found it interesting. Everyone did their job as they understood it, and yet nothing about the organization’s defensive posture changed.
The underlying problem is that the handoff between reading about an adversary and doing something about that adversary is rarely assigned to anyone in particular. Because it is unowned, it happens inconsistently. It tends to occur in bursts, driven by whichever individual cares enough to push it forward, and it stops entirely when that person becomes busy or moves on to another company.
Closing this gap does not require reorganizing your security function. It requires a small, repeatable loop that somebody explicitly owns. A report arrives and someone extracts the behaviours and techniques from it rather than the IP addresses. That person then asks whether the existing telemetry would even record that behaviour, and if the answer is no, the missing visibility gets logged as a formal gap. If the telemetry does exist, the next question is whether a detection covers it, and any shortfall becomes a tracked backlog item. Finally, whatever gets built is validated against something real, whether that is an atomic test, a purple team exercise, or a lab replay of the technique.
Most teams never progress past the first step, because the output of their intelligence process is a document rather than a decision.
Your Own Incidents Are the Best Feed You Own
The second point I would press is that the richest source of intelligence available to most organizations is one they already possess and consistently underuse, which is their own incident history.
When a forensic investigation concludes, you know precisely how the attacker gained access, which systems they touched, what your tooling failed to surface, and how long it took anyone to notice. That is not a vendor’s aggregated estimate of global activity. It is ground truth about your environment, your users, your architecture, and your specific blind spots.
Despite that, in most organizations the incident report gets filed, a few remediation tickets get raised, and the analytical value dies there. The behavioural details that actually matter, such as the particular living-off-the-land binary that was abused, the unusual parent and child process relationship, or the service account that turned out to hold permissions nobody had reviewed in three years, never become a detection rule or a hunting hypothesis. They also rarely make their way back to the analysts who will encounter a variation of the same activity six months later.
If an organization did nothing else this year except systematically convert its own incidents into detections and hunts, it would likely see more defensive improvement than from any feed subscription it could purchase.
Artificial Intelligence Accelerates the Process Without Fixing It
There is genuine value in what language models bring to this work. Summarizing a fifty page adversary report, extracting technique mappings, drafting an initial detection query, or translating a rule between query languages are all real time savers, and I use them regularly.
I would offer one caution that I think gets lost in the current enthusiasm. These tools amplify whatever process already exists. If your intelligence pipeline currently terminates in a document that nobody acts upon, then introducing automation simply produces more documents, faster, that nobody acts upon. The bottleneck was never how quickly your analysts could read. It was the absence of a defined point at which intelligence converts into a change to your detection surface.
There is a quieter risk as well. Machine generated summaries read fluently and sound confident, which makes them easy to accept without proper scrutiny. Threat intelligence is a field where nuance matters a great deal, where attribution is frequently contested, and where a subtle misreading of an adversary’s tradecraft can send a team hunting for entirely the wrong thing. Speed without verification produces well formatted wrong answers at scale.
Measure Something that Matters
Most intelligence programs report on volume, counting feeds ingested, indicators processed, and reports published. None of those figures tell a board whether the organization is harder to compromise than it was six months ago.
More useful questions include how many detections were created or modified as a direct result of intelligence this quarter, how long it takes to reach a documented coverage decision after a relevant report is published, what percentage of your prioritized techniques have tested detection coverage, and how many of your own incidents produced a durable detection improvement.
Those metrics are considerably harder to make look impressive, which is precisely why they are worth tracking.
None of this requires a dedicated intelligence team. A two person security function can run this loop against a single adversary group relevant to its sector and be meaningfully better off within a quarter. The shift is not technological. It is a decision that intelligence is something you act on rather than something you subscribe to.

