Forrester's evaluation of this market contains a line that explains why buyers find it so hard to compare vendors: some customers want a total threat intelligence platform, some want curated alerts, and others just want the raw data.
Those are three different products. The first is software a team operates. The second is a service that delivers conclusions. The third is a data feed that goes into something you already own.
A category containing all three cannot produce a ranking that answers your question until you have decided which of the three you are actually buying. Most organisations have not, which is why threat intelligence procurement so often ends with an expensive platform that nobody logs into.
What external threat intelligence is
The argument for the category, in Forrester's framing, is that relying on fundamental security controls and monitoring internal logs is no longer sufficient, and that external cyber threat intelligence has become a necessary foundational component of enterprise defence.
Internal telemetry tells you what is happening inside your estate. It cannot tell you that a ransomware group has begun targeting your sector, that credentials belonging to your employees are being sold, that a vulnerability in software you run is being actively exploited in the wild, or that someone has registered a domain resembling yours.
External intelligence covers that space. In practice it spans several distinct things: adversary tracking and attribution, indicators of compromise, vulnerability intelligence with exploitation context, dark web and criminal marketplace monitoring, compromised credential detection, brand and domain abuse, third-party and supply chain exposure, and geopolitical risk analysis.
Those are collected differently, consumed differently, and valuable to different teams. Compromised credential data is operationally actionable by an identity team within hours. Adversary tracking informs architecture decisions over quarters. Bundling them under one heading is convenient for vendors and unhelpful for buyers.
Inside The Forrester Wave: External Threat Intelligence Service Providers, Q3 2023
The evaluation, authored by Brian Wrozek with Caroline Provost, scored twelve providers across current offering, strategy, and market presence.
Google placed as a Leader with the highest possible score in fifteen criteria, including cyber threat intelligence, analyst tradecraft expertise, and innovation.
Recorded Future also placed as a Leader, with Forrester positioning its intelligence platform for customers who need comprehensive threat intelligence delivered in an intuitive and usable interface.
Flashpoint placed as a Strong Performer, cited repeatedly for fraud and compromised credential capability and for its reputation and penetration in financial services.
CrowdStrike was assessed as delivering high-quality threat intelligence underpinning its wider platform, with Forrester noting that organisations should consider it for an overall threat intelligence programme even if they do not use its endpoint detection tooling.
That last observation is a specific and useful one. Intelligence bundled with a detection product is often assumed to be a captive feature. Forrester is saying it can be evaluated on its own merits, which matters if you run someone else's endpoint tooling.
The criterion that gives the category away
Among Google's maximum scores sits analyst tradecraft expertise.
That is not a technology criterion. It is an assessment of the humans doing the analysis, and its presence at the top of a scored evaluation tells you what this market actually sells.
Collection is largely commoditised. Multiple vendors scrape the same forums, ingest the same feeds, observe the same infrastructure, and see much of the same raw material. What differs is what happens next: whether an analyst recognises that three unconnected observations describe one campaign, whether an attribution claim is made with appropriate confidence or overstated, whether a report says what it does not know.
Threat intelligence inherited its methodology from national security intelligence work, and the good vendors show it. Confidence levels are stated explicitly. Assessments distinguish between what is observed, what is inferred, and what is assessed as likely. Sources are characterised without being exposed.
The weaker ones publish confident attributions that later prove wrong, or produce volume without judgement, which for a buyer is indistinguishable from good work right up until the moment it is not.
This has a consequence for evaluation. Feature comparisons are nearly useless here, because the differentiator is the quality of analytical judgement, and the only way to assess that is to read the actual finished intelligence over time and see whether it was right.
Relevance is the whole game
The failure mode in this category is not bad intelligence. It is intelligence about somebody else.
A global feed reports thousands of indicators, dozens of active campaigns, and a constant stream of newly exploited vulnerabilities. The overwhelming majority concern sectors you are not in, regions you do not operate in, and software you do not run. Delivered undifferentiated, that volume is noise that consumes analyst attention and produces nothing.
The value is in the filter: which of this applies to us, given our sector, our geography, our technology estate, our suppliers, and our brand.
This is why the vendors compete on context rather than coverage, and why Flashpoint's financial services depth is cited as a differentiator rather than as a limitation. Sector specialisation means the collection is aimed at the adversaries who actually target that sector, and the analysts understand what matters to it.
It also explains why threat intelligence programmes fail without an asset inventory. Vulnerability intelligence saying a flaw is being actively exploited is only actionable if you know whether you run the affected software and where. Organisations that cannot answer that reduce every intelligence report to a fire drill of manual checking, and the programme collapses under its own alerting.
The uncomfortable sequencing is that the prerequisite for getting value from external intelligence is internal visibility, which is the less exciting purchase.
Three buyers, three products
Return to the segmentation, because it converts directly into how you should approach this market.
The raw data buyer already has a security operations centre, a threat intelligence platform, and analysts. What they want is high-quality collection they can process themselves, and the relevant criteria are coverage, freshness, format, API quality, and the ability to filter at ingestion. A polished portal is irrelevant to them and they should not pay for one.
The curated alerts buyer wants conclusions. They have a small team without dedicated intelligence analysts, and what helps is a short, prioritised set of things that matter to them specifically, arriving with enough context to act. Here the analytical quality and the sector fit are everything, and raw volume is actively harmful.
The platform buyer wants a system their team operates: a place to store, correlate, enrich, and investigate, integrating with their existing tooling. This is the most expensive path and the one that most often disappoints, because a platform without analysts to run it is a very well-organised backlog.
The mismatch that recurs is a mid-sized organisation buying the platform when it needed curated alerts. The platform is impressive in a demonstration, it justifies the budget request, and it requires a function the organisation does not have.
What the 2023 evaluation predates
Three years is a long time in this field, and the current scored research was published before several things that now shape it.
Generative AI changed the attacker economics on the social engineering side, making convincing pretexting cheap and multiplying the volume of credible phishing and business email compromise attempts. It also changed the defender side, with intelligence vendors applying models to summarisation, correlation, and translation of foreign-language criminal forums.
Ransomware ecosystem structure kept shifting, with groups fragmenting, rebranding, and re-forming at a pace that makes attribution and tracking harder than the 2023 criteria anticipated.
And the exposure that matters has expanded. Third-party and supply chain intelligence, non-human and machine identity exposure, and now the risk surface introduced by AI systems themselves are all live concerns that a 2023 evaluation could only partially cover.
The vendor set remains a reasonable map of who is serious. The relative positions are three years old, and the sensible approach is to treat the criteria as a starting checklist and ask each provider directly what they do about AI-enabled social engineering, exposed model endpoints, and agent-related exposure.
Where it stops being a product
Threat intelligence has a boundary worth stating plainly, because vendors are incentivised not to.
Intelligence informs decisions. It does not make them, and it does not implement them. A report saying an adversary targeting your sector uses a particular initial access technique is valuable only if someone can change the control that would stop it, and that someone sits in a different team with a different backlog.
The organisations that get value from this category have a defined path from intelligence to action: a named owner, a regular cadence where findings are reviewed against the control environment, and authority to change something. The ones that do not accumulate a subscription, a portal, and a monthly report that circulates and changes nothing.
That is the same pattern visible in cloud cost management, conversation intelligence, and employee experience research: the analysis is not the constraint, and the tooling cannot supply the organisational willingness to act on it.
Threat intelligence has one feature the others do not, which is that the consequence of ignoring it is occasionally catastrophic rather than merely wasteful. That raises the stakes without changing the mechanism.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of external threat intelligence. The Q3 2023 Wave, authored by Brian Wrozek with Caroline Provost, scored 12 providers across current offering, strategy, and market presence, and remains the most recent scored evaluation of this market.
Source research
- The Forrester Wave: External Threat Intelligence Service Providers, Q3 2023
Forrester does not endorse any provider named here, and tier placement should not be read as a recommendation to buy.