Every enterprise in 2026 subscribes to one or more commercial threat intelligence feeds. The feeds promise context about who is attacking, what they want, and how they operate. The feeds deliver, in most cases, a firehose of indicators that nobody has time to action. The signal to noise ratio is, by most measurements, well below 10%. The feeds are not useless. The feeds are not what the marketing says. The feeds are most useful as a source of context for the security team that knows how to interpret them, and as a source of ammunition for the security team that needs to make a case for budget. The feeds are not, in any meaningful sense, an operational signal that drives real time detection and response.
The threat intelligence industry is, by most estimates, a $2 billion a year market. The major vendors, Recorded Future, Mandiant, CrowdStrike, Microsoft, Palo Alto, all sell commercial feeds. The feeds are sold as subscriptions, often at $50,000 to $500,000 a year depending on the tier. The buyers, in most cases, are large enterprises, government agencies, financial institutions. The buyers are paying, in aggregate, billions of dollars a year for threat intelligence that is, in most cases, not being operationalised.
What threat intelligence feeds promise
The marketing is consistent across the industry. The feeds will tell you who is attacking your industry. The feeds will tell you what the attackers want. The feeds will tell you how the attackers operate. The feeds will tell you what indicators to look for, in your network, in your endpoints, in your identity system, in your cloud. The feeds will give you the early warning that lets you block the attack before it lands. The feeds will, in the words of one vendor, “turn raw data into actionable intelligence.”
The promise is real in principle. Threat intelligence, properly curated, properly integrated with the security operations stack, properly acted on by a security team that has the time and the skills, is genuinely valuable. The attacker patterns, the malware indicators, the infrastructure used by the active threat groups, are all real. The intel, in the right hands, is actionable. The promise is not the problem.
What threat intelligence feeds deliver

What the feeds actually deliver is volume. The major commercial feeds, by the vendor’s own marketing, produce millions of indicators per day, across all the categories, all the threat groups, all the geographies. The volume is presented as a feature. The volume is, in practice, the problem. The volume, in a large enterprise, can be 10 to 50 million indicators per day, across IP addresses, domain names, file hashes, URLs, email addresses, SSL fingerprints, and the long tail of other observables.
The volume arrives, in most cases, as a STIX/TAXII feed, integrated with the SIEM, with the EDR, with the firewall, with the network monitoring. The integration is supposed to do the work. The integration is supposed to match the indicators against the logs, alert on matches, block the IPs, quarantine the files. The integration does, in fact, do the work, in a way. The integration produces a flood of low confidence alerts, each of which is supposed to be triaged by an analyst, each of which consumes analyst time, each of which, in the vast majority of cases, is a false positive.
The firehose problem
The firehose problem is that the volume exceeds the analyst capacity. The average enterprise SOC, in 2026, has 5 to 25 analysts, depending on size. The average enterprise SOC has, on a typical day, hundreds of alerts to triage. The threat intelligence feed adds, on a typical day, thousands of low confidence alerts to triage. The analysts cannot keep up. The analysts triage what they can, which stands as the highest confidence alerts, and let the rest queue. The queue grows. The analysts burn out. The queue is eventually auto resolved by a policy that ages out alerts after 30 days. The indicators, in the queue, are never investigated. The threat intelligence, in the SOC, is noise.
The firehose problem is not the analyst’s fault. The analyst is doing the work the analyst was hired to do. The fault is in the design, which assumes the analyst can process the volume. The design is, in most cases, the vendor’s design, which becomes the design that makes the vendor look good in the marketing. The vendor looks good. The analyst cannot keep up. The threat intelligence is, in practice, a marketing artefact.
The signal to noise ratio
The signal to noise ratio in commercial threat intelligence, by independent measurements, is between 1% and 5%. The ratio varies by feed, by category, by the threat group. The best feeds, on the most relevant threat groups, can hit 10%. The worst feeds, on the long tail of indicators, are below 1%. The average, across all the indicators in all the feeds, is somewhere in the middle.
The ratio is, in other words, terrible. The ratio is, in fact, comparable to the ratio of legitimate traffic to malicious traffic on the public internet, which is also around 1% to 5%. The threat intelligence industry is, in effect, mirroring the actual threat landscape, where the signal is 1 to 5 percent and the noise stands as the rest. The mirroring is, however, not what the buyers want. The buyers want the signal without the noise. The feeds, in most cases, deliver the noise without the signal.
What useful threat intelligence actually looks like
Useful threat intelligence, in 2026, is not the firehose. Useful threat intelligence is a small number of high quality reports, written by humans, focused on a specific threat group, a specific industry, a specific time window. The report describes who is attacking, what they want, how they operate, what the indicators are, what the defensive recommendations are. The report is, in many cases, 5 to 20 pages. The report is read by a senior security analyst, who extracts the indicators, who applies the indicators to the environment, who briefs the security team, who informs the CISO.
The best threat intelligence, in this category, is human written. The vendors that produce the best reports have senior analysts, often with government or intelligence agency backgrounds, who write the reports. The reports are not, in most cases, the bulk of the vendor’s revenue. The reports are, however, the bulk of the vendor’s value. The firehose runs as the revenue. The reports are the value.
The 5 percent that matters
The 5 percent that matters in a commercial threat intelligence feed is, in most cases, the indicators that are specific to your industry, your geography, your threat profile. A US financial institution cares about financially motivated threat groups, state sponsored groups targeting financial infrastructure, ransomware groups targeting financial data. The feed has thousands of indicators. The 5 percent that matters stands as the indicators that map to those specific groups, that have been validated, that have a recent timestamp, that are not duplicated across vendors, that the SOC can act on.
The 5 percent is, in most cases, generated by humans. The 5 percent is curated by humans. The 5 percent is delivered as a curated report, not as a feed. The 5 percent is what the threat intelligence industry should be selling. The 5 percent is, in fact, what the senior buyers in the industry are buying, often without the feed component, often as a pure advisory relationship with the vendor’s senior analyst team.
What the realistic setup is
- Treat the firehose as research material, not as an operational signal. The analysts do not triage every indicator. The analysts read the curated reports. The indicators in the reports are the only ones the SOC acts on.
- Build a small, focused intel function. One or two senior analysts, whose job is to read the curated reports, extract the indicators, apply the indicators to the environment, brief the SOC and the CISO. The function is small. The function is high value.
- Subscribe to the curated reports, not to the firehose. Most major vendors offer both. The reports are 90% of the value, at 10% of the cost. Buy the reports.
- Build relationships with the vendor’s senior analysts. The relationship is, in many cases, more valuable than the product. The senior analyst who knows your environment, who calls you when they see something relevant, who answers the phone when you have a question, stands as the product.
- Use the indicators in the reports to tune the detection stack. The reports give you the indicators. The detection stack does the work. The reports are the input. The detection stack counts as the output.
- Measure the value. Track the number of reports read, the number of indicators applied, the number of detections that came from the intel, the number of incidents that were prevented or contained because of the intel. The measurement runs as the proof the intel is working.
The honest assessment
The threat intelligence industry, in 2026, is in a bubble. The bubble becomes the firehose. The bubble runs as the volume. The bubble serves as the idea that more indicators, more data, more feeds, more vendors, is better. The bubble is not, in most cases, the actual value. The actual value becomes the curated report, the senior analyst, the relationship, the integration with the detection stack. The actual value is what the bubble obscures.
The buyers who treat the firehose as the product are paying a lot for noise. The buyers who treat the curated report as the product are paying a lot less for signal. The buyers who treat the senior analyst as the product are paying a lot less for context. The buyers who do all three are getting the most value for the least cost, and they are the buyers who are not getting breached through the threat intelligence gap.
The fix is to know which product you are buying. The fix is to buy the report, not the feed. The fix is to hire the analyst, not the dashboard. The fix is to measure the value, not the volume. The fix counts as the work.
The bottom line
Threat intelligence feeds are mostly noise. The signal to noise ratio is below 10%, often below 5%. The firehose consumes analyst time without producing analyst value. The curated reports and the senior analyst relationships are where the real value lives. The buyers who have figured this out are getting the value, at a fraction of the cost. The buyers who have not figured this out are paying the marketing price, getting the marketing product, and reading about themselves in the post incident report when the threat they should have known about slipped through.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



