Key Takeaways
Tactical intelligence supports immediate defense, while strategic intelligence guides longer-term priorities.
Vulnerability exploitation is a leading source of breaches, making remediation a key security priority.
Ransomware is becoming more fragmented, with more groups targeting organizations.
Effective CTI turns threat data into clear actions for executives and security teams.
Strong CTI programs align intelligence with business questions, relevant threats, and security operations.
A board member interrupts a CISO’s briefing to ask one specific question: which vendor, exactly, is the weak point? The CISO doesn’t have a crisp answer, because the deck in front of both of them is organized around CVE counts and malware family names, categories that make sense to a SOC analyst and mean almost nothing to someone deciding where next year’s security budget goes.
Strategic threat intelligence exists to close that kind of gap, and it has for years. What’s changed by 2026 is how wide the gap has gotten in practice: SANS Institute’s 2026 Cyber Threat Intelligence Survey[1] found 91% of CISOs call threat intelligence valuable, but only 26% say it actually shapes their decisions, a 65-point gap between valuing something and using it. AI lowering the price of running an attack, and ransomware crews splintering into dozens of smaller operations that are harder to track as a group, have only made that gap more expensive to leave open.
Where Strategic Threat Intelligence Sits, and Where the Model Gets Messy
Fidelis, like most of the industry, splits threat intelligence into four altitudes, each with its own audience and time horizon.
AltitudeWho it’s forTime horizon
StrategicExecutives and the board6 to 18 months outOperationalThreat hunters, IR leadsWeeks to months, tracking specific campaignsTacticalSOC analysts, detection toolsReal time – weeksTechnicalForensics, malware researchersPer incident, individual pieces of malware
That’s the clean version. The messier version shows up in SANS Institute’s 2026 Cyber Threat Intelligence Survey, which asked CISOs what they actually want out of their intelligence programs:
Generates High-Confidence Alerts
Disrupts Autonomous and AI-Assisted Attacks
Extends Detection Across Hybrid Environments
79% wanted actively exploited vulnerabilities
77% wanted specific adversary TTPs
49% cared about quarterly strategic reports
41% wanted business-focused reporting
The executives who are supposedly strategic intelligence’s core audience spend most of their attention on tactical detail wrapped in business language. That’s worth sitting with before anyone builds a program around a four-box diagram, because it points at what strategic intelligence actually is, and isn’t. It isn’t simply long-term intelligence, the same content as everything else just pushed further out on a calendar.
Its value comes from translation: taking one underlying threat reality and putting it in front of the SOC, the IR team, the CISO, and the board in whatever form each of them can act on.
The fact that a particular ransomware group is expanding into your industry has to reach a SOC analyst as a detection rule, an IR team as a response plan, and a board member as a dollar figure, and a program that only speaks one of those languages is only strategic for one of those audiences.
The 2026 Threat Landscape, Up Close
Three reports published in 2026 tell a consistent story, even though none of them were written with each other in mind.
IBM’s 2026 X-Force Threat Intelligence Index[2] puts public-facing applications at the top of the initial access list, with attacks against them up 44% year over year, and it tracked 109 distinct ransomware extortion groups active in 2025, up from 73 the year before, as the dominance of the largest operations dropped by roughly a quarter, enough that a threat model still built around “the five ransomware groups everyone talks about” is already out of date.
Verizon’s 2026 Data Breach Investigations Report[3] adds a detail that matters more than it might look at first: vulnerability exploitation overtook credential abuse as the leading initial access vector, at 31% of breaches, while remediation of known exploited vulnerabilities actually fell during the same period, from 38% to 26%, which is the kind of number that gets buried under a flashier ransomware headline but probably shouldn’t be, since it means the gap between finding a hole and closing it widened in the exact year attackers got better at finding holes.
ReportHeadline 2026 statWhat it means for the budget conversation
IBM X-Force Threat Intelligence IndexAttacks on public-facing apps up 44%; 109 active ransomware extortion groups, up from 73A fixed watch-list of “the groups that matter” is obsolete before the report finishes printingVerizon Data Breach Investigations ReportVulnerability exploitation leads initial access at 31%; known-exploited-vuln remediation fell from 38% to 26%Patch management funding is losing ground to the exact threat it exists to coverWEF Global Cybersecurity Outlook94% of executives name AI the top risk driver; 65% flag third-party and supply chain exposureExecutive attention is on AI even though this year’s actual breach data mostly isn’tSANS 2026 CTI Survey91% of CISOs call threat intelligence valuable; only 26% say it drives decisionsMore intelligence spend doesn’t fix a program nobody’s acting on
The World Economic Forum’s Global Cybersecurity Outlook 2026[4] shows where this lands at the top of the org chart. Third-party and supply chain exposure jumped from 54% of large companies flagging it as their toughest challenge to 65%, and CEOs are shifting their personal worry away from ransomware toward cyber-enabled fraud, with 73% reporting some kind of personal or network exposure to it over 2025.
It would be easy to read all of this as an AI story. John Pirc of Fidelis pushed back on that framing during a recent webinar on hybrid network security: “We spend a lot of time talking about AI, zero-days and advanced threats, but attackers will always take the simplest path that works.“
The numbers back him up, since the leading initial access vector is still an unpatched public application and the metric sliding in the wrong direction is patch remediation. The 31% of breaches Verizon traced to vulnerability exploitation deserves defensible, prioritized investment ahead of whatever category a vendor happens to be selling this year.
Worth saying plainly: that argument is a convenient one for a network security company to make, since it points budget toward exactly the kind of basic visibility Fidelis sells rather than the AI-defense tooling everyone else is pitching this year. It’s also not obviously wrong. The WEF’s 94% figure describes what’s keeping executives up at night more than it describes what’s actually breaching networks in 2026. Attention and attack surface don’t move at the same speed, and there’s no guarantee this year’s breakdown holds through next year’s budget cycle.
Critical Attack Categories: Ransomware, Supply Chain, and State-Sponsored Threats
Three categories of attack account for most of the risk serious enough to reach a board agenda, and the mistake most programs make is treating them as one undifferentiated threat picture instead of three sets of decisions that each need their own intelligence to make well.
Ransomware remains the one everyone already worries about, though the shape of it has shifted from a handful of well-known operators to a wide, fragmented field that’s harder to profile group by group.
Supply chain attacks are growing faster than almost anything else in the data; IBM found major supply chain incidents have increased nearly fourfold over the past five years, largely because attackers have realized it’s easier to compromise a trusted developer identity or a SaaS integration than to break into the target directly.
Gaurav Bahadur, who leads cloud security work at Fidelis, points at a less dramatic cause sitting underneath a lot of that exposure: cloud environments are open by default under the shared responsibility model, and unless an organization actively enforces its own half of that split, the gaps that get exploited first are rarely novel. They’re the basic controls nobody finished configuring.
State-sponsored activity is the odd one out, because it rarely announces itself. These campaigns are built for espionage, infrastructure disruption, or slow intellectual property theft, and they can run for months before a single tactical indicator surfaces. Strategic intelligence is nearly the only lens built to track this category at all.
Same threat picture, three different sets of decisions, which is exactly why a single quarterly report built around one risk score rarely serves all three well.
CategoryWhat executives should askWhat the SOC needs to watch forWhat decision this should change
RansomwareWhich extortion groups are actively naming our sector this quarter, and does our incident response retainer account for a fragmented field instead of the five or six names everyone already knowsDouble-extortion patterns, lateral movement, and exfiltration staging, since a new group won’t match a signature built for last year’s known operatorsWhich systems get prioritized for backup testing and isolation, and how fast the SOC escalates instead of triagesSupply chainWhich vendors and SaaS integrations hold write access to our environment, and when that access was last reviewedAnomalous authentication from trusted third-party accounts, and unexpected changes in CI/CD pipelines or registry imagesWhich vendor relationships get extra monitoring or added security requirements before the next renewalState-sponsoredWhether the organization’s sector or geography puts it in the documented interest of a nation-state actor, and whether anyone would actually notice if it didLong-dwell-time indicators, unusual outbound traffic, and identity misuse quiet enough to sit under a standard alert thresholdWhether segmentation and IP-protection investment gets weighted toward slow, quiet threats instead of only the loud ones
One Threat Picture, Different Decisions
This is the same translation problem from a few sections back, narrowed to the two audiences a strategic report has to satisfy most often.
Executives don’t need to read packet captures, and nobody expects them to. What they need is narrower: a defensible reason to weight the budget toward the vector causing most breaches rather than split it evenly across whatever a vendor is pitching that quarter, the same likelihood-and-impact language the board already uses for every other operational risk, and enough context going into an incident that the first hour of response stays calm instead of turning into a scramble.
Jim Skelly of Fidelis makes a point that applies at both ends of the org chart: one event, looked at by itself, can pass for either an isolated compromise or nothing at all. It’s only against the full picture across the security landscape that it resolves into a high-fidelity alert or a false positive worth ignoring. He’s usually talking about SOC-level triage. A board looking at a raw incident count, or a dollar figure spent on tooling, is running the same risk of mistaking one data point for the whole picture.
Translating a strategic report into daily SOC work is where most programs succeed or fail. It starts with mapping the specific threat actors coming after an industry to detection logic, rather than treating every alert as equally worth chasing. SOC teams already field an overwhelming number of alerts every day, and cutting that volume down only helps if the alerts getting suppressed are the actual noise. A generic ransomware tabletop exercise is a fine baseline; one built around the specific extortion groups actually targeting your sector, using this year’s campaign data, teaches a team something a generic version can’t.
Where This Breaks Down, and What Closes the Gap
This is the part worth being honest about, because plenty of strategic threat intelligence programs produce a quarterly deck and not much else. That’s the 91/26 gap from the opening: valued in principle by nearly every CISO, but only actually shaping decisions for about a quarter of them.
Part of that gap is a format mismatch. Executives are asking for actively exploited vulnerabilities and adversary TTPs, and a CTI team that keeps producing quarterly strategic decks regardless is going to keep watching the value fail to land. Part of it is resourcing.
The same survey found 56% of organizations now run a formal CTI function, but most of those teams have fewer than four full-time staff supporting nine or more distinct use cases, which the survey’s authors described as operating in triage mode instead of strategy mode. When a two- or three-person team is fielding requests from IR, red team, SOC, and the board at once, the board report is what gets rushed, because it’s the least urgent item on any given Tuesday.
Worth admitting, since this piece is ultimately making the case for strategic intelligence: per that same SANS survey, most programs don’t close this gap. The 26% who say it actually shapes decisions are the exception, not an early cohort on its way to becoming the norm. Nothing below is a guarantee that a given program moves from the 74% into the 26%, only a reasonable case that skipping it makes that less likely.
None of it takes an elaborate program, but it does take a short list of things done consistently. For each, it’s worth asking what capability a platform actually needs to support it, rather than treating the practice and the tooling as separate conversations.
Start with the business questions intelligence needs to answer before collecting anything.
Which vendors carry the most third-party exposure, which regions carry geopolitical risk specific to your operations, and which regulatory deadlines are coming up? What capability does this take? A platform that can be configured around those priorities directly, instead of handing back a generic feed and leaving prioritization as a manual exercise.
Pull from more than one kind of source.
OSINT, commercial feeds, breach disclosure data, and internal telemetry each catch things the others miss, and a program built on a single vendor feed inherits that vendor’s blind spots.
What capability does this take? A unified platform built to ingest and correlate across those sources natively, network, endpoint, cloud, and external feeds together, rather than one that only sees its own slice of the environment.
Profile the threat actors relevant to your own sector, not the ones getting the most press coverage that week.
IBM’s research still puts manufacturing and financial services at the top of ransomware targeting, but the group actually worth tracking depends on your own vendor list, geography, and data, which is exactly why a regional hospital system and a payments company can read the same threat feed and come away with two completely different priority lists.
What capability does this take? A platform that can map threat actor behavior against your specific assets and vendors, not just a generic industry vertical.
Write the reports so a CFO can act on them without a translator.
Dollar exposure, likelihood, and recovery time land, malware family names rarely do.
What capability does this take? A platform that retains enough context, asset value, business impact, session history, to translate a technical finding into those terms in the first place, rather than handing over a raw list of indicators.
Close the loop between the strategic report and the SOC floor, the step most programs skip.
The strategic team needs incident data flowing back up, and the SOC needs the strategic report’s priorities flowing back down.
What capability does this take? Strategic and tactical teams drawing from the same underlying telemetry, instead of two separate tools that were never designed to talk to each other.
The New Reality of AI-Driven Breaches
The Visibility Gap That Puts CISOs at Risk
Strategic Recommendations for CISOs
Where Fidelis Fits In
Fidelis Elevate® approaches the translation problem from the platform side. The fastest way to shrink the gap between a strategic report and a SOC alert is to stop asking one team to watch network telemetry, another to watch endpoint behavior, and a third to watch cloud posture, then hoping somebody downstream connects the three. Fidelis Elevate consolidates that signal into one place, retaining detailed session metadata that lets an analyst, or a strategic report, trace an IP address, a behavior pattern, or an anomaly back through its full history whenever a board-level question needs a tactical answer.
Skelly describes the target outcome as building “the complete picture across the user, the endpoint, their behavior, what they’re doing on the network, and even the time of day they’re accessing particular assets.” That same correlation is what makes deception technology worth deploying in the first place: a decoy convincing enough to mimic a real device on the network, including an end-of-life system nobody’s gotten around to retiring, exists to produce one high-fidelity alert instead of another entry in an already overloaded queue.
None of this fixes the resourcing gap described above. A platform can hand a two-person CTI team better correlated data, but it can’t hand them the two additional analysts they’d need to turn that data into a report the board actually reads, and deciding which threat actors matter to a given industry is still a judgment call no dashboard makes on its own.
Frequently Asked Questions
How is strategic threat intelligence different from a general cyber risk assessment?
A risk assessment is a point-in-time inventory: what’s exposed, what controls are missing, scored against a framework like NIST or ISO. Strategic threat intelligence adds a forecast on top, asking who’s likely to exploit those gaps right now. One without the other either treats every finding as equally urgent or has nothing concrete to aim that urgency at.
Can you explain the role of strategic intelligence in cyber incident detection?
Strategic intelligence doesn’t generate the alert. It decides ahead of time what a detection system should watch for, and how urgently a team should react once something fires. Knowing whether the actors circling an industry are financially motivated or state-sponsored changes the first call, fast containment or careful evidence preservation, before the alert ever happens.
Who should own strategic threat intelligence inside an organization?
Officially, the CISO or a dedicated threat intelligence lead. Unofficially, whoever wins the argument with legal over what’s allowed to leave the building, which happens more often than most org charts admit. My honest take: that fight matters less than one thing everyone should agree on regardless of who wins it, the report reaching the board directly, not after three people have softened it.
The post Strategic Threat Intelligence for Critical Attacks: What Executives and Security Leaders Need to Know appeared first on Fidelis Security.
No Responses