Security operations

What is Threat Intelligence?

A plain-language guide to threat intelligence, covering the four types, the feeds and how to turn it into action that stops real attacks.

Key takeaways
  • Threat intelligence is threat data that has been analysed and given context so your team can act on it.
  • It answers who is likely to attack you, how they operate and what to fix first.
  • The four types are strategic, operational, tactical and technical, each aimed at a different audience.
  • Feeds deliver intelligence to your tools, and the open standards STIX and TAXII let systems share it automatically (OASIS, 2021).
  • The Verizon 2025 DBIR found vulnerability exploitation was the way in for one in five breaches, up 34% year on year.
  • ENISA reports that newly disclosed flaws are now weaponised within days (ENISA Threat Landscape 2025).
  • US cybercrime losses reported to the FBI reached $16.6 billion in 2024, up 33% (FBI IC3, 2024).
  • In the Equifax, Log4Shell and Colonial Pipeline breaches the warning intelligence already existed, and acting on it was the gap.
  • Threat intelligence is now a legal expectation under NIS2, DORA and ISO 27001 Annex A 5.7, which was new in 2022.
  • More intelligence is not better security. Relevance to your systems and your people is what counts.

Threat Intelligence Defined in Plain Terms

Threat intelligence is information about cyber threats that has been collected, analysed and given context so a team can act on it. It answers who is likely to attack you, how they operate and what to defend first. Raw data becomes intelligence only once analysis turns it into a decision.

The distinction matters. A list of malicious IP addresses is data. The same list, checked against your own logs, ranked by relevance to your systems and turned into a blocking rule, is intelligence. The US National Institute of Standards and Technology describes it the same way as threat information that has been analysed and enriched to support a decision (NIST SP 800-150, 2016).

Here is why it matters now. Attackers move faster than most defences can react. The Verizon 2025 Data Breach Investigations Report found that exploiting a vulnerability was the initial way in for one in five breaches, up 34% on the previous year (Verizon, 2025).

ENISA reported the same pattern in Europe with criminals weaponising newly disclosed flaws within days of their becoming public (ENISA Threat Landscape 2025). You cannot block or patch a threat you have not seen. Threat intelligence is how a team sees it early enough to act and decides what to fix first.

How Threat Intelligence is Produced

Threat intelligence is a process, not a product you buy once. Most teams run a version of the intelligence cycle used by government agencies, adapted for security. It has six repeating stages.

How Threat Intelligence is Produced
  • Direction: Decide what you need to know, based on the business and its real risks.
  • Collection: Gather raw data from internal and external sources.
  • Processing: Sort, normalise and translate that data into a usable form.
  • Analysis: Turn the processed data into findings that answer the original questions.
  • Dissemination: Get the finished intelligence to the people who will act on it.
  • Feedback: Check whether it helped, then refine the next cycle.

The raw material comes from several places. Your own logs, alerts and past incidents are the most relevant source because they describe your environment. External sources add what you cannot see alone. These include open-source intelligence from public reporting, government and CERT advisories, sector sharing groups and monitoring of criminal forums and dark web marketplaces where stolen data and access are traded.

The output is only as good as the direction at the start. Intelligence built without a clear question tends to produce noise rather than answers.

The Four Types of Threat Intelligence

Threat intelligence is usually split into four types, each aimed at a different audience and a different decision. A mature programme uses all four.

  • Strategic: The big-picture view of risk and threat trends, written for leadership and boards to guide investment and policy.
  • Operational: Insight into specific campaigns and adversaries, who is likely to target your sector and why, used to prioritise defences.
  • Tactical: The techniques attackers use, often mapped to the MITRE ATT&CK framework, used by defenders to harden systems and hunt for intruders.
  • Technical: Specific indicators of compromise such as malicious IP addresses, file hashes and domains, fed straight into detection and blocking tools.

These four types work together. Technical indicators tell a firewall what to block today. Strategic intelligence tells a board where to spend next year. A board has no use for raw file hashes and detection tools cannot act on boardroom strategy.

Threat Intelligence Feeds and Sharing

Most organisations consume intelligence through feeds which are structured, machine-readable streams of threat data that plug into security tools. Feeds range from free to paid and knowing the difference is where a buyer should start.

  • Open-source and government feeds: Free public sources, national CERT advisories and community projects. A sensible starting point though they need filtering for relevance.
  • Sector sharing groups: Information Sharing and Analysis Centres, known as ISACs, where organisations in the same industry share what they are seeing.
  • Commercial feeds: Paid, curated intelligence with wider coverage and faster delivery, usually the step up once free sources are being used well.
  • Dark web monitoring: Watching criminal forums and marketplaces for your leaked credentials, data or mentions of your organisation.

Open-source intelligence or OSINT, is anything gathered from public sources such as breach disclosures, vulnerability databases, researcher blogs and social media. It is free and often timely but the work is in filtering signal from noise. Dark web threat intelligence goes a step further, watching closed criminal spaces for the early signs that your organisation is a target such as stolen credentials appearing for sale.

Feeds only work at scale if the data speaks a common language. Two open standards do that job. STIX structures the intelligence into a consistent format and TAXII moves it automatically between systems. Both became OASIS standards in 2021, having started as US government projects (OASIS, 2021). Government schemes such as CISA’s Automated Indicator Sharing use the same two standards to exchange indicators machine to machine (CISA).

A threat intelligence platform, or TIP, sits on top of these feeds. It aggregates sources, removes duplicates, scores what matters and passes the result to the tools that act. The value is less noise and faster action on the data that actually applies to you.

Threat Intelligence in Real-World Cases

The cost of acting without good intelligence is not abstract. In the US alone, victims reported $16.6 billion in losses to the FBI’s Internet Crime Complaint Center in 2024, a 33% rise on the year before (FBI IC3, 2024). Ransomware featured in 44% of breaches worldwide (Verizon, 2025).

The three cases below share a pattern. In each, the information that would have changed the outcome already existed. What decided the result was whether it reached the right team and prompted action.

The Equifax Breach (2017)

In March 2017 a maximum-severity flaw was found in Apache Struts, a common web framework (CVE-2017-5638). A patch was released the same day, and public exploit code followed within hours. This was well-publicised vulnerability intelligence, available to everyone.

Equifax had it too. An internal alert told staff to patch within 48 hours but it went to a distribution list that did not include the team running the affected consumer dispute portal so the fix was never applied. Automated scans then failed to catch the still-vulnerable system (US House Oversight Committee, 2018).

Attackers exploited the gap from May to July 2017 and reached the data of about 147 million people before anyone noticed. Nothing here turned on missing intelligence. It turned on routing. A process that sends an advisory to the team that owns the asset and confirms the patch is applied would have closed the gap.

The Log4Shell Vulnerability (2021)

In December 2021 a critical flaw surfaced in Log4j, a logging library built into countless Java applications (CVE-2021-44228). It allowed remote code execution from a single crafted string and attackers began exploiting it within hours of public disclosure. CISA, the UK NCSC and others issued urgent advisories almost immediately (US Cyber Safety Review Board, 2022).

So the intelligence was fast and widely shared. The hard part was different. Log4j is often a hidden dependency pulled in by other software so many organisations did not know whether they ran it at all, let alone where.

Teams with a software asset inventory found their exposure and patched in hours. Teams without one spent weeks searching. What separated the two groups was visibility. Match an advisory to the systems it affects and shared intelligence becomes a same-day fix.

The Colonial Pipeline Attack (2021)

In May 2021 the DarkSide ransomware group shut down Colonial Pipeline which carries close to half of the fuel on the US East Coast. The disruption caused fuel shortages and an emergency declaration. Colonial paid about $4.4 million in ransom of which the US Department of Justice later recovered about $2.3 million (US DOJ, 2021).

The way in was mundane. Attackers used the username and password of a dormant VPN account that was still enabled and had no multi-factor authentication, as the company’s chief executive told a US Senate committee (Senate testimony, 2021). The password was later found in a batch of leaked credentials on the dark web, consistent with reuse from an earlier breach, though investigators could not confirm exactly how it was obtained.

Two ordinary controls would have closed the door. Multi-factor authentication makes a stolen password useless on its own and dark web monitoring for your own leaked credentials flags the exposure before an attacker uses it. This is threat intelligence pointed inward, at your own footprint.

Threat Intelligence and Compliance

In the EU, threat intelligence has moved from good practice to legal expectation. Several frameworks now assume you are collecting and acting on it.

NIS2, the EU’s cybersecurity directive, requires continuous monitoring and incident handling under Article 21, both of which depend on threat intelligence. Article 29 goes further and sets up voluntary arrangements for organisations to share cyber threat information including indicators of compromise and attacker tactics (Directive (EU) 2022/2555).

In Sweden this is law as Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026 with boards personally accountable under Article 20. See our NIS2 compliance guide for the full picture.

For financial entities, DORA is stricter. Article 45 encourages the sharing of cyber threat information and intelligence across the sector and the rules on threat-led penetration testing (Articles 26 to 27) require identified firms to test their defences against real threat intelligence at least every three years (Regulation (EU) 2022/2554). Our DORA compliance guide covers the detail and our penetration testing service supports this kind of testing.

ISO 27001, the international standard for information security management, made threat intelligence an explicit control in its 2022 revision. Annex A 5.7 requires organisations to collect and analyse information about threats to produce threat intelligence, a control with no equivalent in the previous 2013 version (ISO/IEC 27001:2022). If you are working towards certification, see our ISO 27001 guide.

GDPR sits underneath all of this. Article 32 expects security appropriate to the risk and Article 33 gives you 72 hours to report a personal-data breach. Good intelligence helps you detect a breach and meet that clock. Our GDPR compliance guide explains the obligations.

How to Put Threat Intelligence to Work

Intelligence only pays off when it changes what your team does. Start with people, process and technology, in that order, then build the habits that turn feeds into action.

How to Put Threat Intelligence to Work

People come first because someone has to own the questions the intelligence should answer. Process comes next so findings reach the right team and get acted on rather than filed. Technology comes last and only once you know what you want it to do.

  • Define what you need to know, tied to your real business risks before subscribing to any feed.
  • Start with free OSINT and government advisories and add commercial feeds once you use those well.
  • Feed technical indicators straight into your detection and blocking tools so they act automatically.
  • Map attacker techniques to MITRE ATT&CK so you can see and close your defensive gaps.
  • Monitor the dark web for your own leaked credentials and data and enforce multi-factor authentication everywhere.
  • Keep an up-to-date asset inventory so an advisory can be matched to the systems it affects.
  • Route every relevant advisory to the team that owns the asset and confirm the fix is done.

One caveat, honestly stated. More intelligence is not better security. A feed you cannot act on adds cost without adding protection. The goal is relevance. A small amount of intelligence that maps to your systems and reaches the right people beats a firehose no one reads.

Building this in-house takes people and time that many organisations do not have. A managed provider can run the intelligence cycle for you, turning feeds into alerts already filtered for your environment. eBuilder Security is a Sweden-based provider of managed detection and response, threat intelligence and advisory services and can help you put the steps above into practice.

Myths & Facts

Myth

Threat intelligence is just a list of bad IP addresses.

Threat intelligence is only for large enterprises.

Buying a threat intelligence feed makes us secure.

Threat intelligence and threat hunting are the same thing.

Open-source intelligence is too low quality to bother with.

Compliance does not require threat intelligence.

Fact

That is threat data. It becomes intelligence only once it is analysed, given context and turned into a decision your team can act on. A raw list with no analysis is noise.

Attackers automate and target by opportunity rather than size. Small and mid-sized firms can start with free open-source feeds and government advisories, then add paid sources as they mature.

Owning a feed is not the same as using one. Intelligence only helps once it is filtered for your environment and reaches the people who act on it.

They are related but different. Intelligence tells you what to look for, and threat hunting is the act of searching your environment for it. One informs the other.

OSINT is free and often timely, covering breach disclosures, vulnerability databases and researcher reporting. The real work is filtering it for relevance rather than doubting its value.

It increasingly does. ISO 27001 added it as control Annex A 5.7 in 2022, and NIS2 and DORA both build in threat information sharing for the organisations they cover.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. A critical flaw in a common software library is disclosed publicly, and attackers are already exploiting it. Your security feed flagged it within the hour.

    What is your first move?

    • Wait for your software vendors to tell you if you are affected.
    • Check your asset inventory to find where the library runs, then patch.
    • Assume you are not affected because you have never heard of the library.
  2. A dark web monitoring alert shows an employee's reused password for sale, tied to an old but still-active remote access account.

    What do you do?

    • Ignore it, since the password is old.
    • Disable the dormant account, reset the credential and confirm MFA is enforced.
    • Email the whole company to change passwords next month.
  3. Your team receives a vendor advisory about a maximum-severity flaw in a framework your public website uses. The alert lands in a shared inbox.

    What is the right process?

    • Leave it in the inbox until someone has time to read it.
    • Route it to the team that owns the website and confirm the patch is applied.
    • Forward it to the whole company for awareness.
  4. Leadership asks you to improve threat intelligence, but the budget is small and your tools already generate more alerts than the team can handle.

    Where do you start?

    • Buy the most expensive commercial feed you can afford.
    • Define what you need to know, then use free OSINT and government feeds filtered for relevance.
    • Turn on every free feed at once to maximise coverage.

Knowledge Test

  1. What turns threat data into threat intelligence?

    • Storing it in a database
    • Analysis and context that support a decision
    • Sharing it publicly
    • Encrypting it

    Intelligence is data that has been analysed and given context so a team can act on it.

  2. Which type of threat intelligence is aimed at boards and leadership?

    • Technical
    • Tactical
    • Strategic
    • Operational

    Strategic intelligence gives leadership the big-picture view of risk and trends.

  3. What do the STIX and TAXII standards do?

    • Encrypt hard drives
    • Structure and automatically share threat intelligence
    • Scan for malware
    • Rank employees by risk

    STIX structures the intelligence and TAXII moves it automatically between systems, both OASIS standards.

  4. According to the Verizon 2025 DBIR, vulnerability exploitation was the initial access vector in roughly how many breaches?

    • One in fifty
    • One in twenty
    • One in five
    • Nine in ten

    The Verizon 2025 DBIR put it at one in five breaches, up 34% year on year.

  5. In the Log4Shell case, what most separated organisations that patched fast from those that did not?

    • Access to the advisory
    • An up-to-date asset inventory
    • A bigger security budget
    • Luck

    The advisory was public to all, so knowing where the vulnerable library ran is what enabled a fast fix.

  6. Which ISO 27001 control introduced threat intelligence as a formal requirement in 2022?

    • Annex A 5.7
    • Annex A 8.8
    • Article 33
    • Annex A 9.1

    Annex A 5.7 Threat intelligence is a new control in the 2022 revision, absent from the 2013 version.

Why Training Matters

Threat intelligence works best when the whole organisation can use it. The tactics it describes, from phishing lures to fake supplier requests, target ordinary staff in finance, HR and operations. Intelligence that never reaches those people cannot protect them.

Regular security awareness training turns that intelligence into instinct. When people know the current tricks and how to report them, they become an early-warning source in their own right. Under NIS2 and Cybersäkerhetslagen, security awareness training is now a legal duty as well.

Frequently Asked Questions

What is threat intelligence in simple terms?

Threat intelligence is information about cyber threats that has been collected, analysed and given context so your team can act on it. It answers who is likely to attack you, how they operate and what to defend first. Raw data becomes intelligence only once analysis turns it into a decision.

What is the difference between threat data and threat intelligence?

Threat data is raw and unprocessed, such as a list of malicious IP addresses. Threat intelligence is that data after it has been analysed, checked against your environment and turned into something you can act on. Data tells you what exists, while intelligence tells you what to do.

What are the four types of threat intelligence?

The four types are strategic, operational, tactical and technical. Strategic serves leadership with a big-picture view of risk. Operational covers specific campaigns and adversaries. Tactical describes attacker techniques, often mapped to MITRE ATT&CK. Technical delivers specific indicators such as malicious IPs and file hashes for your tools.

What are threat intelligence feeds?

Threat intelligence feeds are structured, machine-readable streams of threat data that plug into security tools such as firewalls and detection systems. They range from free open-source and government feeds to paid commercial services. Open standards called STIX and TAXII let different systems exchange this data automatically.

What is open source threat intelligence?

Open source threat intelligence, or OSINT, is threat information gathered from public sources such as breach disclosures, vulnerability databases, researcher blogs and social media. It is free and often timely, which makes it a good starting point. The main effort is filtering it for relevance to your organisation.

What is dark web threat intelligence?

Dark web threat intelligence is the monitoring of criminal forums and marketplaces for early signs that your organisation is a target. This includes stolen credentials, leaked data or discussion of your company being offered for sale. It lets you respond to an exposure before an attacker acts on it.

Does NIS2 require threat intelligence?

NIS2 does not use the exact phrase, but it requires continuous monitoring and incident handling under Article 21, both of which depend on threat intelligence. Article 29 also sets up arrangements for organisations to share cyber threat information. In Sweden these duties are law under Cybersäkerhetslagen.

Is threat intelligence part of ISO 27001?

Yes. The 2022 revision of ISO 27001 added threat intelligence as a formal control, Annex A 5.7, which requires organisations to collect and analyse information about threats. It is a completely new control with no equivalent in the previous 2013 version, reflecting how central intelligence has become.

Do small and mid-sized companies need threat intelligence?

Yes, because attackers automate and target by opportunity rather than company size. Smaller firms do not need an expensive programme to start. Free open-source feeds, national CERT advisories and basic dark web monitoring for leaked credentials give a strong return before any paid service is considered.

How do we start with threat intelligence?

Start by deciding what you need to know, based on your real business risks, before buying anything. Then use free open-source and government feeds, feed technical indicators into your existing tools and keep an asset inventory so advisories can be matched to your systems. Add paid feeds as you mature.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.