A feed is not intelligence. The question is who reads it.
A global feed is raw material an analyst turns into a decision. Who is going to read it decides which of two very different products you need.
Two subscriptions can both be sold as threat intelligence, watch the same forums and markets, and produce findings that are accurate. What separates them shows up after the contract is signed, in who has to open the platform, work out whether an item refers to your organisation, and turn it into something a person will act on. That work is either done when the finding arrives, or it becomes a job on your side of the line.
The raw material and the decision are two different purchases
A feed of indicators is a list of facts about the internet. An address that hosted a command and control panel last week, a file hash seen in a campaign, a domain registered an hour ago under a pattern that matches a phishing kit. Each can be true and none is a decision. The decision is whether the item touches your estate and what somebody changes because of it.
Between the fact and the decision sits a person. The UK National Cyber Security Centre, in its guidance on building a security operations centre, states the dependency plainly. Where you write your own detection use cases, threat intelligence is a key part of the work, and where you buy a commercial detection tool, the vendor does that part. The same guidance asks that analysts have time to read and digest intelligence reports. Reading time is a headcount question, and headcount never appears on the quotation.
Scoping is a commercial difference and not a convenience
Scoping means the platform is told what you are before it is told to look. Domains you own, brands you trade under, executive names that get impersonated, supplier names on your invoices. Monitoring then runs against that list, and a finding arrives attached to an asset you recognise. Without scoping, the same monitoring runs against the internet, and matching results back to your estate is a task with an owner, a rota and a queue depth.
The size of that task is set by the market the evidence sits in, not by your company. The ENISA Threat Landscape 2025, which analysed 4,875 incidents between 1 July 2024 and 30 June 2025, reports that 68.6 percent of the intrusions it recorded led to breached data being leaked for sale on cybercriminal forums. A forum listing is written by a seller who wants buyers and not investigators, so it can describe the victim by sector, size and country without naming it. Deciding whether a listing is about you is reading work, the same work for a bank with an intelligence team as for a manufacturer whose IT manager also owns security.
The obvious objection is that reading got cheap. It did. A language model summarises a long report, translates a forum post, clusters near duplicate listings and turns a week of feed into a page. The scoping did not get cheap. Knowing that a leaked credential belongs to your finance director and not to somebody with the same name, that a lookalike domain targets your brand and not a homonym in another country, and that a forum post concerns your customer records and not a similarly named company requires knowing what you own and who works for you. A model pointed at a global feed returns a shorter global feed, not yours. So what you feed a model decides more than which model you chose.
What changes when you do have an analyst
A team with an analyst of its own has the opposite problem. The findings are wanted, but an interface is the wrong place for them, because the reader is a detection pipeline rather than a person watching a dashboard. This is what the two standards published by OASIS exist for.
STIX is, in the specification's words, a language for expressing cyber threat and observable information. It defines object types including indicator, campaign, intrusion set, malware and threat actor, plus relationship objects that connect them, so a finding carries the campaign and the actor it is attributed to instead of arriving as a bare address. TAXII is the protocol that moves it, defining a collection as a logical grouping of threat intelligence exchanged between a client and a server in a request-response manner, with filters that include object type and a timestamp after which objects were added, so a client polls for what is new instead of the whole collection again.
Those two acronyms on a datasheet change what is being bought. A platform that exports CSV and PDF hands an analyst a file to parse and a parser to maintain. One that publishes a TAXII collection hands the analyst's tooling an endpoint to poll and a format the enrichment stage already understands. Recorded Future and Intel 471 both deliver intelligence on the assumption that an analyst reads and routes it, which is right for that buyer and wrong for a team with nobody in that seat.
Five questions that separate the two during an evaluation
Both kinds demonstrate well, because the vendor's own analyst drives the demonstration. These questions move it onto the ground you will operate on.
- Ask what the platform was watching before you gave it anything. If the answer is the internet, the scoping has been left with you.
- Ask what a single finding names. One that names your subdomain, your executive or your reseller has been resolved to your estate. One that names an address has not.
- Ask how the severity score is calculated and against which list. A score computed without your asset inventory was computed before you became a customer.
- Ask for the machine output during the trial. Request a TAXII collection URL, an API key and one STIX object, and see whether they arrive.
- Ask who receives an alert at two in the morning and what that person does next. The answer names the team that must exist for the subscription to produce anything.
If those answers come back as capability statements instead of a finding about your own domain, you are being shown raw material, and the analysis is still unbought.
Where this stops and exposure management starts
The two overlap on the surface. Both start outside the perimeter, enumerate subdomains, certificates and open ports, and find assets that reached nobody's inventory. What separates them is what happens to the output.
Exposure management monitors external assets in order to tell you what to fix, and every finding ends in a change somebody can make. Close the port, renew the certificate, finish the DMARC record, decommission the server left running after the project ended. The ticket has an owner in IT operations and closes when a configuration changes.
Threat intelligence maps external assets in order to know what to watch for, and what it finds sits on infrastructure you do not own. A lookalike domain is registered on somebody else's account. A credential set is already in somebody else's hands. An executive is impersonated on a messaging platform you do not administer. The actions differ in kind, including a takedown request, a forced password reset, and a warning to finance about an invoice about to arrive. An evaluation that treats the two as one survives to the end, because both answer what sits outside correctly. The gap appears when a finding lands and nobody has been named to act on it.
The product this note points to
Threat intelligence in our portfolio is Cyberthint. Domains, brands and executives are defined first, and surface, deep and dark web monitoring runs against that list, so a finding arrives scored against an asset you named rather than as an entry in a global feed. Where an analyst exists, the same findings leave in STIX and TAXII and through the API. The product page and the area page carry the detail.