Threat Intelligence

Threat intelligence tiers and indicator shelf life

Most threat intelligence sold to small companies is a list of addresses that stops being true within days, and which the tools you already own were consuming anyway.

  • Glossary
  • Detection

The short answer

Threat intelligence is information about attackers, their methods and their infrastructure, processed so it can inform a decision. It ranges from board-level assessments of who is likely to target your sector down to individual addresses seen hosting malware last week. The value depends almost entirely on which of those you are buying, and whether anything in your organisation acts on it.

Threat intelligence nobody acts on is a subscription, not a control.

The three threat intelligence tiers

TierWhat it containsWho acts on it
StrategicWhich groups target your sector, how they are funded, what they are after and how that is shiftingFounders and the board, when setting budget and risk appetite
OperationalThe methods behind a campaign. Which access route is being used, which software is being exploited, how the intrusion typically unfoldsWhoever decides what to patch, harden or monitor next
TacticalIndividual indicators. Addresses, domains, file hashes, sender addressesTools, automatically, with no human in the loop

Buyers think they are getting strategic and receive tactical

The pitch describes attacker groups and sector targeting. The delivery is a feed of indicators. Both are called threat intelligence, and the gap between them is where most disappointment sits. Before signing anything, ask which tier you are being sold, what format it arrives in, and which system will consume it. If the answer to the last question is that somebody will read a weekly report, you are buying a newsletter.

Why indicators expire

EASY FOR AN ATTACKER TO CHANGE File hash Recompile the file. New hash in seconds IP address Rent another one. Minutes Domain name Register a new one. Hours, and cheap Tooling Rebuild or switch tools. Weeks Behaviour Retrain. Painful HARD FOR AN ATTACKER TO CHANGE Feeds sell the top rows. Detection value sits in the bottom ones.

A feed of hashes and addresses blocks the attack that already happened somewhere else. That is worth having, and it is close to free, because everything in the top three rows can be replaced faster than most organisations can ingest the update.

Detection built on behaviour survives the swap. An unusual sign-in followed by a new mailbox rule is the same pattern whichever address it came from, and that pattern comes from your own logs rather than a subscription.

Threat intelligence you already have

Before buying a feed, it is worth knowing how much threat intelligence is already arriving inside products you have paid for.

ControlIntelligence already embedded
Web application firewallAttack signatures, malicious source reputation, bot fingerprints, updated continuously by the vendor
Email securitySender reputation, known phishing infrastructure, newly registered domain scoring
DNS filteringMalicious and command and control domain lists, refreshed constantly
Endpoint detectionBehavioural rules mapped to known attacker techniques, not just signatures
Vulnerability managementExploit availability and active exploitation status, which is what should drive patch order

Paying separately for indicators your existing tools are already consuming is common, and it usually shows up as a feed connected to a SIEM that generates alerts nobody has the capacity to work.

When a threat intelligence feed is worth buying

SituationVerdict
Under 50 people, no dedicated security staffNo. The intelligence embedded in your existing controls is the right level. Spend on coverage gaps instead
Someone is paid to investigate alertsYes, for enrichment. Intelligence that answers what an address is while an analyst looks at it saves real time
Sector-specific sharing group existsYes. Financial and healthcare sharing communities carry attacks aimed at organisations that look exactly like yours
Regulator or framework requires itYes, and scope it to what is required. Several regimes name intelligence as an expected capability
Your brand is being impersonatedYes, but the product is takedown and lookalike domain monitoring rather than a general feed
Bought to reduce alert volumeNo. It adds sources. Volume is a tuning and automation problem

The capacity question comes first

Threat intelligence only becomes a control when something consumes it. Either a system blocks on it automatically, or a person uses it to make a decision they were already going to make. If neither is true on the day the contract starts, the feed will accumulate quietly and be discovered at renewal. Decide who acts on it before deciding what to buy.

Where Osto fits

Osto is not a threat intelligence vendor and does not sell a feed. Intelligence arrives embedded in the modules that enforce something with it, which for a company without a security team is the only form that reliably gets used. Attack signatures and reputation in the web application firewall, malicious domain lists in DNS filtering and inbound email security, behavioural rules in endpoint detection, and exploitation status in vulnerability management so remediation is ordered by what is actually being used against people.

The more useful signal for a team of your size is local. Because endpoint, identity, network and application events land in one SIEM rather than five consoles, behaviour that no external feed would ever describe becomes visible: a sign-in from an unfamiliar location, followed by access to a system that user has never touched, followed by an unusual outbound transfer. No indicator list contains that. Correlation across your own stack produces it.

Where a framework expects a threat intelligence capability, that expectation is generally satisfied by showing that external sources inform your controls and that you monitor for relevant threats. SOC 2, ISO 27001 Annex A and NIST CSF all address it at that level rather than requiring a named subscription.

Platform walkthrough

Signal from your stack, not a subscription

Endpoint, identity, network and application events correlated in one SIEM, with vendor intelligence already enforcing inside every module.

Book a demo

Evidence from live controls · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is threat intelligence?

Information about attackers, their methods and their infrastructure, processed so it can support a decision. It spans strategic assessments of who targets your sector, operational detail on how campaigns run, and tactical indicators such as addresses and file hashes.

What is the difference between threat intelligence and a threat feed?

A feed is raw data, usually tactical indicators. Intelligence is that data assessed for relevance to you and turned into something actionable. Most products described as intelligence are feeds.

Do small companies need it?

Rarely as a separate purchase. Your firewall, email security, DNS filtering and endpoint tools already consume vendor intelligence continuously. A standalone feed adds most value once somebody is paid to investigate alerts.

How long do indicators stay useful?

Not long. A file hash changes on recompilation, an address can be swapped in minutes and a domain registered in hours. Detection built on behaviour rather than indicators survives those changes.

Is threat intelligence required for compliance?

NIST CSF and ISO 27001 Annex A both expect the capability, and several sector regulators name it. None require a specific subscription. Showing that external sources inform your controls and that you monitor relevant threats usually satisfies the expectation.