As cyber-crime gangs splinter and nation-states step up their hacking campaigns, keeping up with operational threat intelligence is now a core part of the CISO’s job, but new research suggests many security leaders are struggling to act on that intelligence effectively.
The latest study from cybersecurity firm Trellix, Mind of the CISO: Closing the gap between reaction and readiness, found nearly all chief information security officers (98%) face barriers when acting on threat intelligence, with their main concerns being staying on top of developing threats (45%), integration issues (39%), and regulatory constraints (38%).
As a result, threat intelligence is defaulting to a reactive function, rather than an embedded, proactive strategy that builds resilience, accelerates response, and keeps firms ahead of threat actors.
Trellix found that the majority of CISOs report their organisations’ approach to collecting (82%), analysing (78%), incorporating (79%), and monitoring (80%) threat intelligence needs significant improvement, or even a complete overhaul.
However, despite threat intelligence taking a backseat at most firms, nearly all CISOs (94%) agree that it is essential for identifying and mitigating emerging cybersecurity concerns.
To take one prominent example, Trellix’s study, which draws on the insights of over 500 security leaders worldwide, revealed that CISOs are more focused than ever on counteracting hostile nation-state actions, with most (89%) being frequently asked about these threats by their CEO and Board.
These threats are having a particularly profound effect on cybersecurity strategies and budgets, with the majority of CISOs reporting that their organisation’s cybersecurity spending (85%) and strategy (87%) are being influenced by the rising volume of nation-state threats.
To meet these challenges head-on, most CISOs (95%) agree that being part of a threat intelligence sharing network would vastly improve their defence preparations, with the majority (89%) agreeing CISO communities allow security leaders to navigate high-stakes decisions using trusted insights and shared experiences.
According to the report, the most forward-thinking leaders are embedding information sharing and collaboration on operational threat intelligence into their cybersecurity strategies.
Recommended reading
- Two-thirds of CISOs Have Had Budgets Slashed Due to AI
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Organisations with this kind of proactive approach to threat intelligence are also more likely (44%) to implement advanced threat detection technologies over the next twelve months, however, the study found that more than half (60%) of firms have not yet even fully integrated threat intelligence into their wider cybersecurity strategies.
“CISOs are now tasked with staying ahead of these adversaries who are becoming more organised, well-resourced, and faster, partially due to the growing use of AI,” said John Fokker, head of threat intelligence at Trellix.
“Moving beyond a traditional tactical approach to utilising operational threat intelligence allows CISOs to better understand the behaviours and objectives of threat actors, anticipate potential threats, and proactively prepare defence strategies.”





