Press "Enter" to skip to content

Cyber threat intelligence

SANS Institute’s 2026 Cyber Threat Intelligence (CTI) Survey Insights report draws on responses from 401 qualified cybersecurity professionals globally, with a dedicated module capturing responses from 67 CISOs and CSOs.

The new CISO module gives practitioners and security leaders direct visibility into how the other side experiences CTI. 91% of CISOs value CTI, but only 26% say it drives decisions. Security executives’ top priorities for the next 12 months are information about vulnerabilities being actively targeted by attackers (79%) and specific adversary TTPs (77%). Business-focused intelligence ranks last among report types at 41%, a number the report attributes to a production gap rather than lack of demand.

Lack of time to implement new processes and lack of funding are the top barriers to effective CTI implementation, each cited by 44% of respondents. 57% of programs do not track maturity over time, and 49% do not gather systematic feedback on effectiveness. Programs that cannot demonstrate improvement cannot defend their budgets with data.

The structural picture extends beyond headcount. 45% of organisations are using AI in CTI programs today, primarily for data summarisation and report writing, with the human-in-the-loop model holding firm. 55% of organisations lack legally reviewed CTI sharing processes, even as NIS2 and the Cyber Resilience Act impose new obligations in 2026.

www.sans.org

Author

Get in touch with us today!