Most threat intelligence sold to small companies is a list of addresses that stops being true within days, and which the tools you already own were consuming anyway.
The short answer
Threat intelligence is information about attackers, their methods and their infrastructure, processed so it can inform a decision. It ranges from board-level assessments of who is likely to target your sector down to individual addresses seen hosting malware last week. The value depends almost entirely on which of those you are buying, and whether anything in your organisation acts on it.
Threat intelligence nobody acts on is a subscription, not a control.
On this page
The three threat intelligence tiers
| Tier | What it contains | Who acts on it |
|---|---|---|
| Strategic | Which groups target your sector, how they are funded, what they are after and how that is shifting | Founders and the board, when setting budget and risk appetite |
| Operational | The methods behind a campaign. Which access route is being used, which software is being exploited, how the intrusion typically unfolds | Whoever decides what to patch, harden or monitor next |
| Tactical | Individual indicators. Addresses, domains, file hashes, sender addresses | Tools, automatically, with no human in the loop |
Buyers think they are getting strategic and receive tactical
The pitch describes attacker groups and sector targeting. The delivery is a feed of indicators. Both are called threat intelligence, and the gap between them is where most disappointment sits. Before signing anything, ask which tier you are being sold, what format it arrives in, and which system will consume it. If the answer to the last question is that somebody will read a weekly report, you are buying a newsletter.
Why indicators expire
A feed of hashes and addresses blocks the attack that already happened somewhere else. That is worth having, and it is close to free, because everything in the top three rows can be replaced faster than most organisations can ingest the update.
Detection built on behaviour survives the swap. An unusual sign-in followed by a new mailbox rule is the same pattern whichever address it came from, and that pattern comes from your own logs rather than a subscription.
Threat intelligence you already have
Before buying a feed, it is worth knowing how much threat intelligence is already arriving inside products you have paid for.
| Control | Intelligence already embedded |
|---|---|
| Web application firewall | Attack signatures, malicious source reputation, bot fingerprints, updated continuously by the vendor |
| Email security | Sender reputation, known phishing infrastructure, newly registered domain scoring |
| DNS filtering | Malicious and command and control domain lists, refreshed constantly |
| Endpoint detection | Behavioural rules mapped to known attacker techniques, not just signatures |
| Vulnerability management | Exploit availability and active exploitation status, which is what should drive patch order |
Paying separately for indicators your existing tools are already consuming is common, and it usually shows up as a feed connected to a SIEM that generates alerts nobody has the capacity to work.
When a threat intelligence feed is worth buying
| Situation | Verdict |
|---|---|
| Under 50 people, no dedicated security staff | No. The intelligence embedded in your existing controls is the right level. Spend on coverage gaps instead |
| Someone is paid to investigate alerts | Yes, for enrichment. Intelligence that answers what an address is while an analyst looks at it saves real time |
| Sector-specific sharing group exists | Yes. Financial and healthcare sharing communities carry attacks aimed at organisations that look exactly like yours |
| Regulator or framework requires it | Yes, and scope it to what is required. Several regimes name intelligence as an expected capability |
| Your brand is being impersonated | Yes, but the product is takedown and lookalike domain monitoring rather than a general feed |
| Bought to reduce alert volume | No. It adds sources. Volume is a tuning and automation problem |
The capacity question comes first
Threat intelligence only becomes a control when something consumes it. Either a system blocks on it automatically, or a person uses it to make a decision they were already going to make. If neither is true on the day the contract starts, the feed will accumulate quietly and be discovered at renewal. Decide who acts on it before deciding what to buy.
Where Osto fits
Osto is not a threat intelligence vendor and does not sell a feed. Intelligence arrives embedded in the modules that enforce something with it, which for a company without a security team is the only form that reliably gets used. Attack signatures and reputation in the web application firewall, malicious domain lists in DNS filtering and inbound email security, behavioural rules in endpoint detection, and exploitation status in vulnerability management so remediation is ordered by what is actually being used against people.
The more useful signal for a team of your size is local. Because endpoint, identity, network and application events land in one SIEM rather than five consoles, behaviour that no external feed would ever describe becomes visible: a sign-in from an unfamiliar location, followed by access to a system that user has never touched, followed by an unusual outbound transfer. No indicator list contains that. Correlation across your own stack produces it.
Where a framework expects a threat intelligence capability, that expectation is generally satisfied by showing that external sources inform your controls and that you monitor for relevant threats. SOC 2, ISO 27001 Annex A and NIST CSF all address it at that level rather than requiring a named subscription.
Platform walkthrough
Signal from your stack, not a subscription
Endpoint, identity, network and application events correlated in one SIEM, with vendor intelligence already enforcing inside every module.
Book a demoEvidence from live controls · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is threat intelligence?
Information about attackers, their methods and their infrastructure, processed so it can support a decision. It spans strategic assessments of who targets your sector, operational detail on how campaigns run, and tactical indicators such as addresses and file hashes.
What is the difference between threat intelligence and a threat feed?
A feed is raw data, usually tactical indicators. Intelligence is that data assessed for relevance to you and turned into something actionable. Most products described as intelligence are feeds.
Do small companies need it?
Rarely as a separate purchase. Your firewall, email security, DNS filtering and endpoint tools already consume vendor intelligence continuously. A standalone feed adds most value once somebody is paid to investigate alerts.
How long do indicators stay useful?
Not long. A file hash changes on recompilation, an address can be swapped in minutes and a domain registered in hours. Detection built on behaviour rather than indicators survives those changes.
Is threat intelligence required for compliance?
NIST CSF and ISO 27001 Annex A both expect the capability, and several sector regulators name it. None require a specific subscription. Showing that external sources inform your controls and that you monitor relevant threats usually satisfies the expectation.

