Back to blog
Security Practices

Threat intelligence: turning feeds into decisions

Most threat intelligence programmes buy feeds, ingest indicators and change nothing. What intelligence is actually for, the three levels worth distinguishing, and how to tell whether yours is working.
GRC Copilot Team
Threat intelligence: turning feeds into decisions

The test of a threat intelligence programme is simple and most fail it: name a decision that was made differently because of it. Buying feeds and ingesting indicators is collection, not intelligence. Intelligence is what changes what you do.

Three levels, often conflated

  • Strategic - who is likely to target your sector and why, how that is shifting, what it means for investment. Consumed by executives, measured in months.
  • Operational - the tactics, techniques and procedures a relevant adversary uses. Consumed by detection engineers and threat hunters. This is where most of the practical value sits.
  • Tactical - indicators: hashes, IPs, domains. Consumed by tooling, and the shortest-lived.
Most programmes over-invest in tactical indicators, which age fastest and are trivially changed by an attacker, and under-invest in operational intelligence about behaviour, which is far harder for an adversary to alter and drives durable detections.

Start from requirements, not from feeds

Write down the questions you actually need answered - what threats matter to our sector and geography, which of our technologies are being actively exploited, is anyone targeting our brand or supply chain, what changed this quarter. Then acquire only what answers them.

Buying feeds first produces a firehose that gets ingested and ignored, and its volume is mistaken for coverage.

What to do with indicators

Not blanket blocking. Indicators need context, an expiry and a confidence level. Blocking a shared hosting IP because it appeared on a list is how you break a legitimate integration and lose trust in the programme.

  • Feed high-confidence indicators to detection, not directly to blocking, unless confidence is very high.
  • Expire them - an indicator from eight months ago is usually noise.
  • Retro-hunt: search historical telemetry for newly received indicators, which is where indicator feeds genuinely earn their cost.

Turn intelligence into tracked control decisions

GRC Copilot connects risks and controls to the evidence behind them, so intelligence-driven changes are recorded rather than informal.

Free sources are underrated

National CERT advisories, sector information-sharing bodies, known-exploited vulnerability catalogues, vendor advisories for your own stack, and peer sharing groups deliver much of the practical value at no cost. Commercial feeds are worth buying once you know what question they answer that these do not.

Attribution is mostly a distraction

Which named group is responsible rarely changes your response. What changes it is the behaviour observed and whether your controls cover it. Attribution matters for law enforcement, insurers and occasionally sanctions exposure - not for whether you should isolate the host.

Measuring it

  • Detections created or tuned as a direct result.
  • Vulnerabilities reprioritised because of exploitation evidence.
  • Retro-hunts run, and what they found.
  • Decisions changed - documented, not claimed.

Volume of indicators ingested is not a metric. Neither is number of feeds.

Frequently asked questions

Do we need a dedicated analyst?

Not initially. A defined set of questions and a few hours a week against free sources beats an unread commercial feed.

Should indicators auto-block?

Only very high confidence ones. Most belong in detection and retro-hunting, where a false positive costs an investigation rather than an outage.

Is attribution worth pursuing?

Rarely for defensive decisions. It matters for legal, insurance and sanctions questions.

What is the fastest useful start?

Subscribe to known-exploited vulnerability catalogues and your own vendors, and use them to reprioritise patching. That alone changes decisions.

Key takeaways

  • If no decision changed, it was collection rather than intelligence.
  • Operational behaviour intelligence outlasts tactical indicators.
  • Define requirements before buying feeds.
  • Attribution rarely changes what you should do.
#threat-intelligence #ioc #feeds #attribution #prioritisation #cti