Spotlight

Report:

The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2023

How does Forrester define the External Threat Intelligence Service Providers market in 2023?

External cyber threat intelligence has become a necessary foundational component of any organization's cybersecurity defenses, as relying solely on fundamental security controls and internal logs is no longer sufficient. Organizations need help prioritizing threats efficiently and require long-term guidance about emerging threats for strategic planning. Since building comprehensive internal threat intelligence teams is challenging, customers need providers offering diverse threat intelligence services. The market has evolved to where customers pay for an average of seven commercial threat feeds. ETISPs are expanding their use cases by investing in AI/ML algorithms for collection, processing, analysis, and dissemination; improving usability; and offering more APIs for integration. Customer needs vary from total threat intelligence platforms to curated alerts to raw data feeds.

Key Facts for The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2023 in 2023

How did the External Threat Intelligence Service Providers market evolve in 2023?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the External Threat Intelligence Service Providers space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research evaluates 12 major external threat intelligence service providers (ETISPs) across 29 criteria grouped into three categories: current offering (50% weight), strategy (50% weight), and market presence (0% weight). The evaluation assesses vendors' capabilities in gathering diverse threat intelligence sources, simplifying consumption through APIs and reports, and acting as force multipliers through value-added services. It covers cyber threat intelligence, digital risk protection, special services, portal experience, and strategic vision.

Q: Who should use this research?

A: Security and risk (S&R) professionals should use this research to select the right external threat intelligence service provider for their organization's needs. The report helps buyers understand which providers excel at gathering diverse intelligence sources, simplifying threat intelligence consumption, and providing value-added services. It includes detailed vendor profiles with strengths and weaknesses, customer feedback, and best-fit recommendations to guide purchasing decisions based on specific organizational requirements and use cases.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this Forrester Wave evaluation, vendors must have: 1) At least $20 million in annual threat intelligence services revenue, demonstrating market scale and viability; 2) Core functionality that solves multiple threat intelligence use cases across a comprehensive spectrum including brand protection, vulnerability management, compromised asset detection, and threat-hunting; 3) A diverse skill set with broad threat intelligence experience and dedicated analysts who can gather information from various sources; 4) The ability to deliver both machine-readable threat intelligence (for automation) and human-readable intelligence (for analyst consumption and executive reporting); and 5) Strong Forrester mindshare, meaning clients frequently discuss them during inquiries, or they possess significant technical capabilities and market presence warranting inclusion.

Q: What are some reasons for not being included in this report?

A:

  • Annual threat intelligence services revenue below $20 million threshold
  • Limited functionality addressing only narrow or single threat intelligence use cases rather than comprehensive spectrum
  • Lack of dedicated threat intelligence analysts or limited skill diversity in gathering intelligence from multiple sources
  • Inability to deliver both machine-readable and human-readable threat intelligence formats
  • Insufficient market presence or Forrester client mindshare
  • Declined to participate in the evaluation process
  • Only partially participated in the evaluation, not providing complete information by the May 18, 2023 cutoff date
  • Primary focus on adjacent markets rather than external threat intelligence services

Q: What should buyers consider when evaluating products in this market?

A:

  • Look for providers who gather diverse sources of threat intelligence including open source, dark web, malware analysis, attack telemetry from honeypots, and proprietary sources like firewalls and EDR
  • Ensure providers have deep repositories of historical data and routinely expand into new areas while refreshing existing sources from all regions
  • Seek providers with rich API sets to facilitate integration and automation across your technology portfolio
  • Evaluate the quality of human-readable reports containing detailed TTPs suitable for both technical and executive audiences
  • Assess portal user experience for visualization quality and ability to pivot from reports to supporting information
  • Prioritize providers that add contextual information, prioritization, and risk scoring to cut through noise
  • Consider value-added services that promote better decision-making including recommendations, competitive peer benchmarking, executive briefings, takedown services, and threat hunting support
  • Verify providers regularly solicit feedback on threat intelligence quality and applicability
  • Evaluate pricing models for transparency and flexibility based on your consumption needs
  • Assess partner ecosystem breadth for integration capabilities and community engagement

Q: How has the External Threat Intelligence Service Providers market evolved in 2023?

A:

  • External threat intelligence is now a necessary foundational cybersecurity component, not optional
  • Organizations pay for an average of seven commercial threat feeds
  • ETISPs are investing heavily in AI/ML algorithms to collect, process, analyze, and disseminate threat intelligence
  • Providers are expanding use cases beyond traditional IOC feeds
  • Increased focus on usability improvements and API integrations
  • Growing demand for both machine-readable and human-readable threat intelligence formats
  • Customers need diverse sources including dark web, open source, malware analysis, and attack telemetry
  • Rise of digital risk protection capabilities including brand protection and EASM
  • Integration of threat intelligence with broader security operations platforms
  • Expansion of value-added services like threat hunting, incident response, and domain takedowns

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Strength of Current Offering (50% weighting) evaluates the technical capabilities, functionality, and features vendors provide today, including intelligence gathering, processing, dissemination, use case coverage (CTI and DRP), portal experience, and analyst expertise. Strength of Strategy (50% weighting) assesses vendors' future direction and market approach, including their vision for the market, innovation investments (especially in AI/ML), product roadmap, partner ecosystem breadth, pricing models, and community engagement. Current Offering focuses on what vendors deliver now, while Strategy evaluates how well-positioned they are for future market needs and growth.

Reference

View Leaders
View Vendor Movements