The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2023
External cyber threat intelligence has become a necessary foundational component of any organization's cybersecurity defenses, as relying solely on fundamental security controls and internal logs is no longer sufficient. Organizations need help prioritizing threats efficiently and require long-term guidance about emerging threats for strategic planning. Since building comprehensive internal threat intelligence teams is challenging, customers need providers offering diverse threat intelligence services. The market has evolved to where customers pay for an average of seven commercial threat feeds. ETISPs are expanding their use cases by investing in AI/ML algorithms for collection, processing, analysis, and dissemination; improving usability; and offering more APIs for integration. Customer needs vary from total threat intelligence platforms to curated alerts to raw data feeds.
No common features specified.
Vendors must, among other requirements:
A: This research evaluates 12 major external threat intelligence service providers (ETISPs) across 29 criteria grouped into three categories: current offering (50% weight), strategy (50% weight), and market presence (0% weight). The evaluation assesses vendors' capabilities in gathering diverse threat intelligence sources, simplifying consumption through APIs and reports, and acting as force multipliers through value-added services. It covers cyber threat intelligence, digital risk protection, special services, portal experience, and strategic vision.
A: Security and risk (S&R) professionals should use this research to select the right external threat intelligence service provider for their organization's needs. The report helps buyers understand which providers excel at gathering diverse intelligence sources, simplifying threat intelligence consumption, and providing value-added services. It includes detailed vendor profiles with strengths and weaknesses, customer feedback, and best-fit recommendations to guide purchasing decisions based on specific organizational requirements and use cases.
A: To be included in this Forrester Wave evaluation, vendors must have: 1) At least $20 million in annual threat intelligence services revenue, demonstrating market scale and viability; 2) Core functionality that solves multiple threat intelligence use cases across a comprehensive spectrum including brand protection, vulnerability management, compromised asset detection, and threat-hunting; 3) A diverse skill set with broad threat intelligence experience and dedicated analysts who can gather information from various sources; 4) The ability to deliver both machine-readable threat intelligence (for automation) and human-readable intelligence (for analyst consumption and executive reporting); and 5) Strong Forrester mindshare, meaning clients frequently discuss them during inquiries, or they possess significant technical capabilities and market presence warranting inclusion.
A:
A:
A:
A: Strength of Current Offering (50% weighting) evaluates the technical capabilities, functionality, and features vendors provide today, including intelligence gathering, processing, dissemination, use case coverage (CTI and DRP), portal experience, and analyst expertise. Strength of Strategy (50% weighting) assesses vendors' future direction and market approach, including their vision for the market, innovation investments (especially in AI/ML), product roadmap, partner ecosystem breadth, pricing models, and community engagement. Current Offering focuses on what vendors deliver now, while Strategy evaluates how well-positioned they are for future market needs and growth.