Skip to content

Impactful is the new Actionable

Published:

5 min read

Impactful is the new Actionable

In a previous post, I argued that dedicated Threat Intelligence teams will not exist in a few years. When discussing this claim with other peers the reaction was mixed. Some agreed. Some pushed back hard. The pushback usually came from people whose job title includes something with “Threat Intelligence Analyst”.

That is a fair reaction. But it misses the underlying point. The point is not that threat intelligence is dead. The way many companies practice this topic is however.

The Intelligence Problem Is Not What You Think

The traditional threat intelligence pyramid has two levels, well it actually has four but in my world as nobody understands the difference between technical/tactical/operational anyways there are two. Leaving with strategic and technical. For years, the industry chased technical intelligence. Indicators of compromise. Hashes. IP addresses. Domains. The assumption was that if you had enough IOCs, you could block enough threats and keep your organization safe. How many companies build their CTI KPIs around how many indicators are produced or consumed by your SIEM.

IOCs are dead. Not because TTPs are the next hottest thing, as few people claim since a couple of years (looking at you Mitre, or what ever is left of it nowadays). TTPs are dead as well. Both are dead because the security tooling you already pay for has its own intelligence layers built in. Your EDR has behavioral analytics, your firewall has threat feeds, your email gateway has ML-based classification, your SIEM has correlation rules that update automatically. The marginal value of a custom IOC feed, on top of what your vendors already provide, is approaching zero for most organizations.

You can argue that vendor intelligence is generic and your team needs threat intelligence tailored to your industry, your technology stack, your geography. This argument has merit in theory. In practice, the effort required to collect, validate, normalize, and distribute a custom feed that meaningfully outperforms what CrowdStrike, SentinelOne, or Palo Alto already push to your endpoints is enormous. The question every security leader should ask is whether that effort produces enough additional detections to justify the headcount. For most companies, the answer is no.

From Actionable to Impactful

This is where the paradigm shifts. The traditional goal of threat intelligence was actionable intelligence. Information that could be transformed into a detection rule, a firewall block, or a threat hunting query. That model made sense when producing those artifacts was itself a scarce capability.

Today, AI and modern security platforms increasingly automate that operational layer. The differentiator is no longer how quickly you can generate detections, but how well you can understand what actually matters. The new objective is impactful intelligence: intelligence that changes how the organization perceives risk, prioritizes investments, and adapts its security strategy.

If we’re honest, the most valuable intelligence has always lived at the strategic level. It isn’t another weekly IOC feed or another list of ATT&CK techniques. It’s the intelligence that helps leadership answer difficult questions: Does adopting this new AI platform expose our intellectual property? Are we affected by the supply-chain compromise that dominated the headlines last week? How is the threat landscape changing, and what does that mean for our security investments over the next 12 months? This is the intelligence that changes decisions, not just detections.

But here is another uncomfortable truth. Most companies that need strategic intelligence already have a team that produces it. They call it business intelligence. Or strategy. These teams already monitor news feeds. They already track industry developments. They already produce reports that inform executive decision-making. The gap is not the absence of intelligence collection. The gap is the absence of technical context.

A business intelligence team can tell you that a new ransomware group is targeting healthcare organizations in Europe. What they cannot tell you is whether your email filtering would catch their initial access vector, whether your backup strategy would survive their encryptions, or whether your detection rules would alert on their lateral movement technique. This is the gap that a CTI team can fill. Not by running a parallel intelligence operation. By providing technical insights that make the business intelligence team’s output actionable from a security perspective.

What This Means for Your Organization

If you run a dedicated threat intelligence team, ask yourself what happens when the output of that team stops being the primary consumer of threat intelligence. If the answer is unclear, the model is already breaking.

If you have a business intelligence team, ask yourself whether they have access to technical security context. If the answer is no, you are leaving intelligence on the table.

The organizations that adopt it will not be the ones with the largest security budgets. They will be the ones with the clearest understanding of what their security teams actually need to do. Everything else is overhead.

So, what now?

I don’t know. I’m still thinking what will be the future of CTI and how to protect what I loved all these recent years from eradicating and losing the battle against a vibe coded dashboard.

Maybe the question isn’t how we protect Threat Intelligence from AI. Maybe it’s how we ensure Threat Intelligence remains indispensable because of AI. Perhaps the future of CTI isn’t about protecting the function. It’s about ensuring its expertise becomes inseparable from security operations itself.