.jpg)

On March 7, 2017, Apache published a patch for a critical flaw in Struts. The next day, US-CERT notified Equifax directly that it needed to apply it. An internal order went out to staff, a scan meant to confirm the fix missed the exposed system, and the vulnerable application stayed unpatched until July 29. By then attackers had been inside for 76 days and had exposed data on more than 143 million people. The US House Oversight Committee's report lays out the timeline in full.
Every element of the intelligence Equifax needed existed and arrived on time. A named vulnerability, a direct government warning, a patch. What failed was operationalization: the distance between knowing and enforcing, measured here by months.
That distance is the CTI team's real adversary, and most days it's quieter than Equifax. A team identifies a threat, scores it, writes the advisory, and the recommended controls are sound. Then the advisory waits. In the common setup, context gets applied only when an alert fires and an analyst has a moment to query the threat intelligence platform for it, one case at a time. The intelligence was ready long before the environment acted on it.
Waiting carries a cost that's easy to underestimate, because adversary infrastructure doesn't sit still. Research compiled by Netresec found that most botnet command-and-control servers had a lifespan of two weeks or less. An indicator parked in a queue for manual handling can point at infrastructure that's already gone by the time anyone acts on it. Being right in a report and being right in the environment are separated by a latency that erases the indicator's value.
Feeds can’t rescue you from this on their own. When the researcher Xander Bouwman and colleagues compared two leading commercial threat intelligence feeds against each other, they found an average overlap of just 2.5% to 4% even for the threat actors both vendors claimed to track. Any single source captures a sliver of what's out there, so coverage can be less about buying another feed than operationalizing what you already have, quickly.
In the SANS 2025 CTI Survey, threat hunting was the top use case for cyber threat intelligence for the second year running, cited by 71% of respondents. Intelligence is being pulled toward operations, toward the question of what to do right now, and away from the report as the finished product.
The shift that makes that possible is to stop treating a CTI team's judgment as output and start treating it as infrastructure. The feed relationships, confidence thresholds, and curation standards a team has built can be fused into events as they land, so intelligence governs detection and response directly.
The shift that makes that possible is to stop treating a CTI team's judgment as output and start treating it as infrastructure. The feed relationships, confidence thresholds, and curation standards a team has built can be fused into events as they land, so intelligence governs detection and response directly.
This describes a change in where a CTI team's judgment lives. Managed Intelligence as a Service, powered by ThreatStream Next-Gen, is built to make that change concrete. The feed relationships, confidence thresholds, and curation standards a team has built become the governing intelligence fused into every event as it lands, rather than a service line an analyst queries after an alert fires. The judgment stops being output and starts being infrastructure.
None of this changes what a good CTI team already does, but it changes how quickly and how consistently it gets acted on; think fewer incidents where the team already had the intelligence to stop something and it didn't reach the environment in time.
The traditional measure of a CTI program has largely been what it produces: feeds curated, advisories published, questions answered. A future-looking measure is what it prevents. That only becomes possible when the team's judgment stops living in documents and starts living in the data every detection runs on.
The advisory was already right. Now the work is making sure something acts on it while it still matters.
Find out more about operationalized, actionable threat intelligence here.
FEATURED RESOURCES

.jpg)