Companies want more from their threat intelligence platforms

With each passing year, cyber threat actors become more sophisticated, more innovative in their attack techniques, and more determined to obtain their ill-gotten gains regardless of law enforcement. This has led to many enterprises leaning increasingly heavily on third-party intelligence platforms (such as Blackwired) to secure their data. However, many of these companies have faced a range of problems with their threat intelligence platforms. One such platform, Recorded Future, has published their 2025 State of Threat Intelligence report, outlining many of the growing pains the threat intelligence community has experienced this past year.

On the whole, threat intelligence platforms have gone from a convenience to a necessity. Of the 615 security leaders surveyed in the report, 83 percent now have dedicated threat intelligence teams, a slight uptick from last year. Further, many have found advantage in having a diversity of intelligence, with 48 percent of companies paying for more than one threat intelligence service, while 41 percent pay for only one. Generally, the maturity of these programs is also increasing. 49 percent of companies rated the maturity of their threat intelligence programs as advanced, compared with 45 percent last year, and 44 percent rated their programs’ maturity as intermediate, compared with 40 percent last year. Only 5 percent of companies said they were operating at a basic maturity level, a drop from 10 percent. “This progression in maturity year over year suggests that organizations are increasing investments in comprehensive threat intelligence products, dedicated teams, and automated workflows,” Recorded Future said.

As always, there are also complaints. The biggest complaint, cited by 50 percent of surveyed companies, was the difficulty of determining the accuracy and credibility of the reports that their threat intelligence platforms generated. Other common complaints include poor integration with existing tools, information overload, and a lack of context tailored to specific network environments. Interestingly, when asked what they would improve, the most common request, from 33 percent of respondents, wasn’t more reliable intelligence, but faster delivery of intelligence. Given the issues with information overload, this seems like a contradiction, but perhaps security experts believe it’s better to have all the intelligence possible and sort it out for themselves rather than have some be held back.

All in all, things in the threat intelligence community seem to be improving, with marked increases in operational maturity. We can hope that this trend will continue into 2026 and will not be hampered by new offensive innovations from threat actors.

Share

Related Posts

shubham-dhage-2nnRCNuHdVs-unsplash
8machine-_-pzcfw9AV5HY-unsplash
bw-blog_un-1682146029185-198922bd8350

Copyright © All Right Reserved

Privacy Policy