{"id":1220,"date":"2026-09-13T20:04:40","date_gmt":"2026-09-13T20:04:40","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1220"},"modified":"2026-09-13T20:04:40","modified_gmt":"2026-09-13T20:04:40","slug":"threat-intelligence","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/threat-intelligence\/","title":{"rendered":"Threat Intelligence"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: THREAT INTELLIGENCE\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Most threat intelligence sold to small companies is a list of addresses that stops being true within days, and which the tools you already own were consuming anyway.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Detection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Threat intelligence is information about attackers, their methods and their infrastructure, processed so it can inform a decision. It ranges from board-level assessments of who is likely to target your sector down to individual addresses seen hosting malware last week. The value depends almost entirely on which of those you are buying, and whether anything in your organisation acts on it.<\/p>\n<\/div>\n\n<p>Threat intelligence nobody acts on is a subscription, not a control.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#tiers\">The three threat intelligence tiers<\/a><\/li>\n    <li><a href=\"#shelf\">Why indicators expire<\/a><\/li>\n    <li><a href=\"#already\">Threat intelligence you already have<\/a><\/li>\n    <li><a href=\"#worth\">When a feed is worth buying<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"tiers\">The three threat intelligence tiers<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Tier<\/th><th>What it contains<\/th><th>Who acts on it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Strategic<\/td><td>Which groups target your sector, how they are funded, what they are after and how that is shifting<\/td><td>Founders and the board, when setting budget and risk appetite<\/td><\/tr>\n    <tr><td>Operational<\/td><td>The methods behind a campaign. Which access route is being used, which software is being exploited, how the intrusion typically unfolds<\/td><td>Whoever decides what to patch, harden or monitor next<\/td><\/tr>\n    <tr><td>Tactical<\/td><td>Individual indicators. Addresses, domains, file hashes, sender addresses<\/td><td>Tools, automatically, with no human in the loop<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Buyers think they are getting strategic and receive tactical<\/p>\n  <p>The pitch describes attacker groups and sector targeting. The delivery is a feed of indicators. Both are called threat intelligence, and the gap between them is where most disappointment sits. Before signing anything, ask which tier you are being sold, what format it arrives in, and which system will consume it. If the answer to the last question is that somebody will read a weekly report, you are buying a newsletter.<\/p>\n<\/div>\n\n<h2 id=\"shelf\" class=\"c-sage\">Why indicators expire<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 268\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Indicator types ranked by how difficult they are for an attacker to change, from file hashes which are trivial to behaviour which is hard.\">\n  <text x=\"14\" y=\"18\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">EASY FOR AN ATTACKER TO CHANGE<\/text>\n\n  <rect x=\"14\" y=\"28\" width=\"620\" height=\"34\" rx=\"9\" fill=\"#e2eff7\"\/>\n  <text x=\"30\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">File hash<\/text>\n  <text x=\"180\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Recompile the file. New hash in seconds<\/text>\n\n  <rect x=\"14\" y=\"68\" width=\"560\" height=\"34\" rx=\"9\" fill=\"#e2eff7\"\/>\n  <text x=\"30\" y=\"89\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">IP address<\/text>\n  <text x=\"180\" y=\"89\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Rent another one. Minutes<\/text>\n\n  <rect x=\"14\" y=\"108\" width=\"500\" height=\"34\" rx=\"9\" fill=\"#e3f0e9\"\/>\n  <text x=\"30\" y=\"129\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Domain name<\/text>\n  <text x=\"180\" y=\"129\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Register a new one. Hours, and cheap<\/text>\n\n  <rect x=\"14\" y=\"148\" width=\"420\" height=\"34\" rx=\"9\" fill=\"#fbe9dc\"\/>\n  <text x=\"30\" y=\"169\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">Tooling<\/text>\n  <text x=\"180\" y=\"169\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Rebuild or switch tools. Weeks<\/text>\n\n  <rect x=\"14\" y=\"188\" width=\"330\" height=\"34\" rx=\"9\" fill=\"#efe4f0\"\/>\n  <text x=\"30\" y=\"209\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Behaviour<\/text>\n  <text x=\"180\" y=\"209\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#6b4576\">Retrain. Painful<\/text>\n\n  <text x=\"14\" y=\"248\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">HARD FOR AN ATTACKER TO CHANGE<\/text>\n  <text x=\"360\" y=\"248\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#1c267a\">Feeds sell the top rows. Detection value sits in the bottom ones.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>A feed of hashes and addresses blocks the attack that already happened somewhere else. That is worth having, and it is close to free, because everything in the top three rows can be replaced faster than most organisations can ingest the update.<\/p>\n\n<p>Detection built on behaviour survives the swap. An unusual sign-in followed by a new mailbox rule is the same pattern whichever address it came from, and that pattern comes from <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">your own logs<\/a> rather than a subscription.<\/p>\n\n<h2 id=\"already\" class=\"c-plum\">Threat intelligence you already have<\/h2>\n\n<p>Before buying a feed, it is worth knowing how much threat intelligence is already arriving inside products you have paid for.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Control<\/th><th>Intelligence already embedded<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">Web application firewall<\/a><\/td><td>Attack signatures, malicious source reputation, bot fingerprints, updated continuously by the vendor<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email security<\/a><\/td><td>Sender reputation, known phishing infrastructure, newly registered domain scoring<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a><\/td><td>Malicious and command and control domain lists, refreshed constantly<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">Endpoint detection<\/a><\/td><td>Behavioural rules mapped to known attacker techniques, not just signatures<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability management<\/a><\/td><td>Exploit availability and active exploitation status, which is what should drive patch order<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Paying separately for indicators your existing tools are already consuming is common, and it usually shows up as a feed connected to a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> that generates alerts nobody has the capacity to work.<\/p>\n\n<h2 id=\"worth\" class=\"c-sky\">When a threat intelligence feed is worth buying<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Situation<\/th><th>Verdict<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Under 50 people, no dedicated security staff<\/td><td>No. The intelligence embedded in your existing controls is the right level. Spend on coverage gaps instead<\/td><\/tr>\n    <tr><td>Someone is paid to investigate alerts<\/td><td>Yes, for enrichment. Intelligence that answers what an address is while an analyst looks at it saves real time<\/td><\/tr>\n    <tr><td>Sector-specific sharing group exists<\/td><td>Yes. Financial and healthcare sharing communities carry attacks aimed at organisations that look exactly like yours<\/td><\/tr>\n    <tr><td>Regulator or framework requires it<\/td><td>Yes, and scope it to what is required. Several regimes name intelligence as an expected capability<\/td><\/tr>\n    <tr><td>Your brand is being impersonated<\/td><td>Yes, but the product is takedown and lookalike domain monitoring rather than a general feed<\/td><\/tr>\n    <tr><td>Bought to reduce alert volume<\/td><td>No. It adds sources. Volume is a tuning and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soar\/\">automation<\/a> problem<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The capacity question comes first<\/p>\n  <p>Threat intelligence only becomes a control when something consumes it. Either a system blocks on it automatically, or a person uses it to make a decision they were already going to make. If neither is true on the day the contract starts, the feed will accumulate quietly and be discovered at renewal. Decide who acts on it before deciding what to buy.<\/p>\n<\/div>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not a threat intelligence vendor and does not sell a feed. Intelligence arrives embedded in the modules that enforce something with it, which for a company without a security team is the only form that reliably gets used. Attack signatures and reputation in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a>, malicious domain lists in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> and inbound <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">email security<\/a>, behavioural rules in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">endpoint detection<\/a>, and exploitation status in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">vulnerability management<\/a> so remediation is ordered by what is actually being used against people.<\/p>\n\n<p>The more useful signal for a team of your size is local. Because endpoint, identity, network and application events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a> rather than five consoles, behaviour that no external feed would ever describe becomes visible: a sign-in from an unfamiliar location, followed by access to a system that user has never touched, followed by an unusual outbound transfer. No indicator list contains that. Correlation across your own stack produces it.<\/p>\n\n<p>Where a framework expects a threat intelligence capability, that expectation is generally satisfied by showing that external sources inform your controls and that you monitor for relevant threats. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a> all address it at that level rather than requiring a named subscription.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Signal from your stack, not a subscription<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Endpoint, identity, network and application events correlated in one SIEM, with vendor intelligence already enforcing inside every module.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is threat intelligence?<\/summary>\n  <p>Information about attackers, their methods and their infrastructure, processed so it can support a decision. It spans strategic assessments of who targets your sector, operational detail on how campaigns run, and tactical indicators such as addresses and file hashes.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between threat intelligence and a threat feed?<\/summary>\n  <p>A feed is raw data, usually tactical indicators. Intelligence is that data assessed for relevance to you and turned into something actionable. Most products described as intelligence are feeds.<\/p>\n<\/details>\n\n<details>\n  <summary>Do small companies need it?<\/summary>\n  <p>Rarely as a separate purchase. Your firewall, email security, DNS filtering and endpoint tools already consume vendor intelligence continuously. A standalone feed adds most value once somebody is paid to investigate alerts.<\/p>\n<\/details>\n\n<details>\n  <summary>How long do indicators stay useful?<\/summary>\n  <p>Not long. A file hash changes on recompilation, an address can be swapped in minutes and a domain registered in hours. Detection built on behaviour rather than indicators survives those changes.<\/p>\n<\/details>\n\n<details>\n  <summary>Is threat intelligence required for compliance?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> both expect the capability, and several sector regulators name it. None require a specific subscription. Showing that external sources inform your controls and that you monitor relevant threats usually satisfies the expectation.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soar\/\">SOAR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/xdr\/\">XDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/easm\/\">EASM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Most threat intelligence sold to small companies is a list of addresses that stops being true within days, and which\u2026<\/p>\n","protected":false},"author":8,"featured_media":1221,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[624,622,621,623],"class_list":["post-1220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-indicators-of-compromise","tag-tactical-vs-strategic-threat-intelligence","tag-threat-intelligence","tag-threat-intelligence-for-small-companies"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1220"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1220\/revisions"}],"predecessor-version":[{"id":1222,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1220\/revisions\/1222"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1221"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}