Threat Intelligence Defined in Plain Terms
Threat intelligence is information about cyber threats that has been collected, analysed and given context so a team can act on it. It answers who is likely to attack you, how they operate and what to defend first. Raw data becomes intelligence only once analysis turns it into a decision.
The distinction matters. A list of malicious IP addresses is data. The same list, checked against your own logs, ranked by relevance to your systems and turned into a blocking rule, is intelligence. The US National Institute of Standards and Technology describes it the same way as threat information that has been analysed and enriched to support a decision (NIST SP 800-150, 2016).
Here is why it matters now. Attackers move faster than most defences can react. The Verizon 2025 Data Breach Investigations Report found that exploiting a vulnerability was the initial way in for one in five breaches, up 34% on the previous year (Verizon, 2025).
ENISA reported the same pattern in Europe with criminals weaponising newly disclosed flaws within days of their becoming public (ENISA Threat Landscape 2025). You cannot block or patch a threat you have not seen. Threat intelligence is how a team sees it early enough to act and decides what to fix first.
How Threat Intelligence is Produced
Threat intelligence is a process, not a product you buy once. Most teams run a version of the intelligence cycle used by government agencies, adapted for security. It has six repeating stages.

- Direction: Decide what you need to know, based on the business and its real risks.
- Collection: Gather raw data from internal and external sources.
- Processing: Sort, normalise and translate that data into a usable form.
- Analysis: Turn the processed data into findings that answer the original questions.
- Dissemination: Get the finished intelligence to the people who will act on it.
- Feedback: Check whether it helped, then refine the next cycle.
The raw material comes from several places. Your own logs, alerts and past incidents are the most relevant source because they describe your environment. External sources add what you cannot see alone. These include open-source intelligence from public reporting, government and CERT advisories, sector sharing groups and monitoring of criminal forums and dark web marketplaces where stolen data and access are traded.
The output is only as good as the direction at the start. Intelligence built without a clear question tends to produce noise rather than answers.
The Four Types of Threat Intelligence
Threat intelligence is usually split into four types, each aimed at a different audience and a different decision. A mature programme uses all four.
- Strategic: The big-picture view of risk and threat trends, written for leadership and boards to guide investment and policy.
- Operational: Insight into specific campaigns and adversaries, who is likely to target your sector and why, used to prioritise defences.
- Tactical: The techniques attackers use, often mapped to the MITRE ATT&CK framework, used by defenders to harden systems and hunt for intruders.
- Technical: Specific indicators of compromise such as malicious IP addresses, file hashes and domains, fed straight into detection and blocking tools.
These four types work together. Technical indicators tell a firewall what to block today. Strategic intelligence tells a board where to spend next year. A board has no use for raw file hashes and detection tools cannot act on boardroom strategy.
Threat Intelligence Feeds and Sharing
Most organisations consume intelligence through feeds which are structured, machine-readable streams of threat data that plug into security tools. Feeds range from free to paid and knowing the difference is where a buyer should start.
- Open-source and government feeds: Free public sources, national CERT advisories and community projects. A sensible starting point though they need filtering for relevance.
- Sector sharing groups: Information Sharing and Analysis Centres, known as ISACs, where organisations in the same industry share what they are seeing.
- Commercial feeds: Paid, curated intelligence with wider coverage and faster delivery, usually the step up once free sources are being used well.
- Dark web monitoring: Watching criminal forums and marketplaces for your leaked credentials, data or mentions of your organisation.
Open-source intelligence or OSINT, is anything gathered from public sources such as breach disclosures, vulnerability databases, researcher blogs and social media. It is free and often timely but the work is in filtering signal from noise. Dark web threat intelligence goes a step further, watching closed criminal spaces for the early signs that your organisation is a target such as stolen credentials appearing for sale.
Feeds only work at scale if the data speaks a common language. Two open standards do that job. STIX structures the intelligence into a consistent format and TAXII moves it automatically between systems. Both became OASIS standards in 2021, having started as US government projects (OASIS, 2021). Government schemes such as CISA’s Automated Indicator Sharing use the same two standards to exchange indicators machine to machine (CISA).
A threat intelligence platform, or TIP, sits on top of these feeds. It aggregates sources, removes duplicates, scores what matters and passes the result to the tools that act. The value is less noise and faster action on the data that actually applies to you.
Threat Intelligence in Real-World Cases
The cost of acting without good intelligence is not abstract. In the US alone, victims reported $16.6 billion in losses to the FBI’s Internet Crime Complaint Center in 2024, a 33% rise on the year before (FBI IC3, 2024). Ransomware featured in 44% of breaches worldwide (Verizon, 2025).

The three cases below share a pattern. In each, the information that would have changed the outcome already existed. What decided the result was whether it reached the right team and prompted action.
The Equifax Breach (2017)
In March 2017 a maximum-severity flaw was found in Apache Struts, a common web framework (CVE-2017-5638). A patch was released the same day, and public exploit code followed within hours. This was well-publicised vulnerability intelligence, available to everyone.
Equifax had it too. An internal alert told staff to patch within 48 hours but it went to a distribution list that did not include the team running the affected consumer dispute portal so the fix was never applied. Automated scans then failed to catch the still-vulnerable system (US House Oversight Committee, 2018).
Attackers exploited the gap from May to July 2017 and reached the data of about 147 million people before anyone noticed. Nothing here turned on missing intelligence. It turned on routing. A process that sends an advisory to the team that owns the asset and confirms the patch is applied would have closed the gap.
The Log4Shell Vulnerability (2021)
In December 2021 a critical flaw surfaced in Log4j, a logging library built into countless Java applications (CVE-2021-44228). It allowed remote code execution from a single crafted string and attackers began exploiting it within hours of public disclosure. CISA, the UK NCSC and others issued urgent advisories almost immediately (US Cyber Safety Review Board, 2022).
So the intelligence was fast and widely shared. The hard part was different. Log4j is often a hidden dependency pulled in by other software so many organisations did not know whether they ran it at all, let alone where.
Teams with a software asset inventory found their exposure and patched in hours. Teams without one spent weeks searching. What separated the two groups was visibility. Match an advisory to the systems it affects and shared intelligence becomes a same-day fix.
The Colonial Pipeline Attack (2021)
In May 2021 the DarkSide ransomware group shut down Colonial Pipeline which carries close to half of the fuel on the US East Coast. The disruption caused fuel shortages and an emergency declaration. Colonial paid about $4.4 million in ransom of which the US Department of Justice later recovered about $2.3 million (US DOJ, 2021).
The way in was mundane. Attackers used the username and password of a dormant VPN account that was still enabled and had no multi-factor authentication, as the company’s chief executive told a US Senate committee (Senate testimony, 2021). The password was later found in a batch of leaked credentials on the dark web, consistent with reuse from an earlier breach, though investigators could not confirm exactly how it was obtained.
Two ordinary controls would have closed the door. Multi-factor authentication makes a stolen password useless on its own and dark web monitoring for your own leaked credentials flags the exposure before an attacker uses it. This is threat intelligence pointed inward, at your own footprint.
Threat Intelligence and Compliance
In the EU, threat intelligence has moved from good practice to legal expectation. Several frameworks now assume you are collecting and acting on it.
NIS2, the EU’s cybersecurity directive, requires continuous monitoring and incident handling under Article 21, both of which depend on threat intelligence. Article 29 goes further and sets up voluntary arrangements for organisations to share cyber threat information including indicators of compromise and attacker tactics (Directive (EU) 2022/2555).
In Sweden this is law as Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026 with boards personally accountable under Article 20. See our NIS2 compliance guide for the full picture.
For financial entities, DORA is stricter. Article 45 encourages the sharing of cyber threat information and intelligence across the sector and the rules on threat-led penetration testing (Articles 26 to 27) require identified firms to test their defences against real threat intelligence at least every three years (Regulation (EU) 2022/2554). Our DORA compliance guide covers the detail and our penetration testing service supports this kind of testing.
ISO 27001, the international standard for information security management, made threat intelligence an explicit control in its 2022 revision. Annex A 5.7 requires organisations to collect and analyse information about threats to produce threat intelligence, a control with no equivalent in the previous 2013 version (ISO/IEC 27001:2022). If you are working towards certification, see our ISO 27001 guide.
GDPR sits underneath all of this. Article 32 expects security appropriate to the risk and Article 33 gives you 72 hours to report a personal-data breach. Good intelligence helps you detect a breach and meet that clock. Our GDPR compliance guide explains the obligations.
How to Put Threat Intelligence to Work
Intelligence only pays off when it changes what your team does. Start with people, process and technology, in that order, then build the habits that turn feeds into action.

People come first because someone has to own the questions the intelligence should answer. Process comes next so findings reach the right team and get acted on rather than filed. Technology comes last and only once you know what you want it to do.
- Define what you need to know, tied to your real business risks before subscribing to any feed.
- Start with free OSINT and government advisories and add commercial feeds once you use those well.
- Feed technical indicators straight into your detection and blocking tools so they act automatically.
- Map attacker techniques to MITRE ATT&CK so you can see and close your defensive gaps.
- Monitor the dark web for your own leaked credentials and data and enforce multi-factor authentication everywhere.
- Keep an up-to-date asset inventory so an advisory can be matched to the systems it affects.
- Route every relevant advisory to the team that owns the asset and confirm the fix is done.
One caveat, honestly stated. More intelligence is not better security. A feed you cannot act on adds cost without adding protection. The goal is relevance. A small amount of intelligence that maps to your systems and reaches the right people beats a firehose no one reads.
Building this in-house takes people and time that many organisations do not have. A managed provider can run the intelligence cycle for you, turning feeds into alerts already filtered for your environment. eBuilder Security is a Sweden-based provider of managed detection and response, threat intelligence and advisory services and can help you put the steps above into practice.



