What is Threat Intelligence?
"Threat intelligence" gets used for almost anything with an IOC attached. Here is what actually separates intelligence from raw data, the three tiers it operates at, and why the source matters as much as the volume.

What is Threat Intelligence?
Ask ten vendors to define threat intelligence and you'll get ten versions of the same sentence: information about threats that helps you make better security decisions. That's true, and it's also nearly useless. By that definition, a spreadsheet of IP addresses is threat intelligence. So is a well-argued analyst report on a nation-state campaign. Those are not the same thing, and treating them as interchangeable is how organisations end up paying for feeds while believing they've bought intelligence.
The actual distinction is simple: data becomes intelligence when it's been analysed, contextualised, and tied to a decision someone can act on. A list of malicious hashes is an input. Knowing that a specific actor is retooling their infrastructure ahead of a campaign that historically targets your sector, and what that means for what you should do this week, is intelligence. Most of what gets sold under the label is the former.
The three tiers, and why the distinction is not academic
Threat intelligence is usually described as operating at three levels, and the distinction matters because each one answers a different question for a different audience.
Strategic intelligence answers "what should we be worried about over the next six to eighteen months, and why." It's aimed at leadership and board-level risk decisions, geopolitical shifts, sector-wide targeting trends, regulatory pressure, and it rarely contains an indicator of compromise at all.
Operational intelligence answers "what is a specific actor or campaign actually doing right now, and what does that mean for us." This is where attribution, campaign tracking, and infrastructure analysis live, the layer that tells a SOC lead what to prioritise this month.
Tactical intelligence answers "what should our tools be looking for today." IOCs, signatures, TTPs mapped to detection rules, the layer that feeds directly into a SIEM.
Most commercial "threat intelligence" products are tactical feeds wearing a strategic label. That's not automatically a problem, tactical feeds are genuinely useful, but it becomes a problem when an organisation buys a feed subscription expecting it to answer strategic and operational questions it was never built to answer.
Why the source matters as much as the tier
The other place the generic definition breaks down is on sourcing. Intelligence is only as good as the vantage point it comes from, and a single feed, however large, is a single vantage point.
This is where fusion matters more than volume. We built SAFA on the premise that no single source, however good, gives you the full picture for a European organisation. Our own research, born out of offensive work, gives us a ground-level view of how vulnerabilities actually get exploited, not just reported on after the fact. TeamT5, our partner, brings deep visibility into the APAC and China-nexus threat landscape that we would not otherwise have, and that matters for organisations with exposure in the region. Neither replaces the other, and neither replaces the Russia-nexus and hybrid-threat picture that matters most for critical infrastructure and government bodies across Western Europe and the Nordics, which is where a meaningful share of our own research effort is focused.
The result is intelligence built for a specific buyer's actual threat model, rather than a single feed repackaged for whichever market will pay for it.
What this means in practice
If you're evaluating threat intelligence, three questions cut through most of the marketing:
Which tier does this actually operate at, and does that match the decision you're trying to make. A tactical IOC feed will not tell your board what to prioritise this year, and a strategic report will not populate your SIEM.
Where does the underlying research come from, and is it disclosed. A feed that can't tell you how it derived a piece of intelligence is asking you to trust a black box.
Is it fused, or is it one source with a new label. Single-source intelligence has a blind spot exactly where that source has a blind spot, and you generally won't find out where that is until it matters.
For a deeper look at how this plays out against a specific threat category, see our anchor piece on what an advanced persistent threat actually is, and why reading about an actor's tradecraft is not the same as testing against it.
Related posts
More content you might like
What is an Advanced Persistent Threat (APT)?
Most explanations of "APT" stop at the acronym. Here is what the term is actually describing, why it matters which actor is behind it, and why reading about tactics is no substitute for testing against them.
Seeing in the Dark: Managing Cyber Threats on the Deep and Dark Web
Almost every intelligence vendor now offers dark web monitoring. That's exactly why it's not the interesting part of the story. Here's what it's genuinely useful for, and what it takes to turn that visibility into something actionable.
Europe's Cybersecurity Crossroads: Why Sovereignty Is Now a Procurement Question
This isn't a forecast piece. DORA is live, NIS2 enforcement is closing the gap between member states, and the threat behind both is more specific than most coverage admits. Here's what's actually changed, and what it means for procurement.