Site navigation

82% of IT Leaders Fear Missing Critical Threats, Google Survey Finds

Graham Turner

,

google Cyber threat data
A new report, commissioned by Google Cloud, urges companies to embrace AI and smarter operational strategies to stay ahead of attacks.

A new global survey reveals that security and IT leaders are struggling to keep pace with a growing flood of cyber threats and data, leaving many organisations stuck in a reactive security posture and vulnerable to attack.

The Threat Intelligence Benchmark, a commissioned study conducted by Forrester Consulting on behalf of Google Cloud, surveyed more than 1,500 IT and cybersecurity leaders across eight countries and 12 industries. The findings highlight a critical challenge: while threat intelligence is widely valued, most organisations lack the resources and processes to effectively operationalise it.

Data Overload and Analyst Shortages

According to the report, the combination of overwhelming threat data and a shortage of skilled analysts is eroding organisations’ ability to detect and respond to cyber-attacks.

“Rather than aiding efficiency, myriad [threat intelligence] feeds inundate security teams with data, making it hard to extract useful insights or prioritise and respond to threats,” the study warns. “Security teams need visibility into relevant threats, AI-powered correlation at scale, and skilled defenders to use actionable insights, enabling a shift from a reactive to a proactive security posture.”

The survey found that 82% of respondents worry they are missing critical threats due to the sheer volume of alerts and data, and 72% admit their organisations remain mostly reactive when facing cyber-attacks.

However, the challenges go beyond data overload.

Eighty percent of respondents said senior leadership underestimates the severity of threats facing their organisations, while 66% struggle to share threat intelligence with relevant teams. The report also found that 86% of leaders believe their organisations need to improve their understanding of the threat landscape, and 85% want to focus more energy on emerging, critical threats.

AI as a Force Multiplier

The study points to artificial intelligence as a vital tool for security teams. Eighty-six percent of respondents say AI is essential to improving their ability to operationalise threat intelligence, with 69% highlighting AI’s role in generating clear, actionable summaries.

“AI can synthesise raw data, manage repetitive tasks, and reduce analyst workload,” the report states. “This frees human defenders to focus on strategic decision-making and proactive threat hunting.”

The report lists the top hurdles organisations face in making threat intelligence actionable:

  • Too many feeds (61%).
  • Too few analysts (60%).
  • Difficulty deriving clear action from data (59%).
  • Challenges determining which threats are valid (59%).

Despite these obstacles, more than 80% of organisations are already using threat intelligence or plan to do so across eight major use cases, underscoring its growing importance.

A Path to Proactive Security

The Threat Intelligence Benchmark outlines four strategic steps for organisations to better operationalise threat intelligence:

1. Identify High-Stakes Intelligence Needs

Organisations should focus on threats most relevant to their critical assets and operations. This involves defining “crown jewels” – data, systems, or processes that would cause significant damage if compromised – and understanding the adversaries and tactics most likely to target them.

Establishing a feedback loop with incident response (IR) and security operations center (SOC) teams can refine threat priorities and ensure intelligence aligns with real-world challenges.

2. Build a Tactical Threat Intelligence Pipeline

To move from raw data to actionable insight quickly, organisations should centralise threat intelligence feeds using a Threat Intelligence Platform (TIP) and Security Information and Event Management (SIEM) tools. Automated enrichment of indicators — such as IP addresses or domain names — and rule-based prioritisation can streamline detection and response.

Direct integration with security controls like firewalls, endpoint detection and response (EDR), and intrusion prevention systems ensures that high-priority intelligence is acted on immediately.

3. Empower Security Teams

Freeing analysts from repetitive data processing allows them to focus on proactive activities like threat hunting and custom detection development. The survey found that 79% of respondents believe external threat intelligence providers should help upskill junior staff or embed analysts within teams.

4. Measure and Continuously Adapt

The report emphasises ongoing evaluation of threat intelligence effectiveness. Metrics such as mean time to detect (MTTD), mean time to respond (MTTR), false-positive reduction, and the number of proactively blocked threats can indicate progress.

Regular reviews of intelligence priorities and post-incident lessons learned ensure strategies remain aligned with evolving threats.

Commenting, Graeme Gordon, CEO of IFB.net: “It’s asking a lot for organisations to effectively run security internally. Firstly, it’s a fulltime job, secondly, protections must run 24/7, while thirdly, there are often far too many threat alerts for small teams to manage. But these important alerts cannot be ignored, because one missed threat could lead to a full scale breach.


Recommended reading


“The world has recently witnessed major attacks on some of the globe’s largest retailers, and many people have been surprised by the impact these have had. Food suppliers have been disrupted, sales figures have dropped to record lows, while the shopping habits of consumers have also been directly hit. These incidents highlight the dangerous world of cyber crime today.

“It only takes one successful phishing scam and attackers can change everything.

These figures highlight that organisations are clearly struggling to find the resources in house to manage security, which could be increasing their vulnerability to attacks.

“For organisations that fall into this category, it may be time to consider working with a partner that can alleviate the task of security from internal teams.

Gambling with security is no longer an option. If an organisation recognises a problem with its internal defences, don’t ignore it, fix it”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data