Threat intelligence teams have never had more data, more tooling, or more visibility into the threat landscape. And yet, in many organizations the same problem persists: the intelligence gets produced, the report is issued, but it doesn’t get acted on. Senior leaders file it. Risk teams don’t know what to do with it. Budget conversations go unaddressed. The intelligence function is present but not yet indispensable.

That was the starting point for a recent SANS webcast, Bridging the Gap Between Threat Intelligence and Business Risk, in which Kevin Garvey of SANS and I discussed both why this problem persists and what it takes to solve it. What follows is a summary of the most important points, and a case for thinking about intelligence more broadly than most organizations currently do.

The stakeholder gap is a communication problem

Intelligence teams serve multiple audiences at once. Senior leaders want to know what risk the organization is carrying and what decisions they should be making. Cybersecurity teams want to understand what to prioritize. Business units want intelligence relevant to their specific operations. Each group is looking to the intelligence team for different things, and most intelligence outputs are not calibrated for any of them.

Kevin identified four recurring objections that intelligence teams face from stakeholders. “I don’t understand this”: the content is too technical for the audience receiving it. “This isn’t useful”: there is no clear expected action or decision. “What’s in it for me?”: the output arrives without connecting to the reader’s own priorities, and they disengage before reaching the substance. “It’s too expensive”: the value delivered is not visible to the people controlling the budget.

Each of these objections has a practical fix. Every intelligence output should open with a clear, audience-specific summary of what the reader needs to know and do. Strategic intelligence requires a framing closer to international relations than to technical security. Working directly with stakeholders to understand what outputs they actually need – rather than what the team assumes they need – closes the usefulness gap. And demonstrating value in business terms, not security terms, changes the budget conversation entirely.

Connecting intelligence to enterprise risk management

One of the most impactful steps a mature intelligence team can take is integrating their program directly into the enterprise risk management (ERM) function. Senior leaders and boards are already highly focused on risk tolerances, financial, reputational, strategic, compliance, and operational. Threat intelligence outputs that feed into an existing framework land very differently from outputs that arrive as standalone security briefings.

This means learning the language of your ERM colleagues, understanding how they frame risk appetite, risk acceptance and avoidance options, and then building shared workflows around those concepts. When threat-driven risk assessments flow into board-level risk reporting the intelligence function stops being a security team input and starts being an enterprise risk input. That distinction matters enormously for how the function is perceived; and, frankly, funded.

Metrics that demonstrate value at the right level

If the value of the intelligence team is not visible outside it, the pushbacks Kevin described are inevitable. The metrics that resonate at board and executive level are not the ones that resonate in the SOC.

Reduction in risk uncertainty, demonstrating that better intelligence leads to better decision-making, is a core part of the value proposition. Time-to-decision improvement tracks how quickly a threat moves from identification to escalation to action, demonstrating operational efficiency in terms executives already understand. Influence on capital allocation shows how intelligence is driving priority-based investment decisions. And contribution to incident prevention, demonstrating that the team identified and helped prevent a specific threat, may be the most powerful metric available, because the cost of incidents is tangible and quantifiable to every senior leader in the room.

Intelligence as a whole-of-business function

Improving how CTI teams communicate the value of cyber threat intelligence is necessary, but it is not sufficient. The real competitive advantage lies in fundamentally expanding what threat intelligence means inside an organization. Threat intelligence is not a cyber function. It never was. It is a whole-of-business function, and the sooner organizations operate that way, the stronger their intelligence capabilities become.

In a typical CTI team, work is focused on cyber indicators: indicators of compromise, threat actor TTPs, vulnerability intelligence, and dark web monitoring. Meanwhile, elsewhere in the organization, a geopolitical risk team is conducting country-level assessments. A physical security team is monitoring facility threats. A corporate affairs team is watching reputational risks. A procurement team is managing supply chain risk. In most organizations, these teams are not talking to each other.

What gets missed as a result is significant. Nation state actors do not choose one domain; they operate simultaneously across cyber and physical space. Geopolitical shifts and sanctions regimes often precede cyber campaign surges by weeks or months. Supply chain threats are visible in open-source economic data long before they manifest as a security incident. Organizations that fuse these signals have a fundamentally different picture of the threat landscape than those that do not.

The disciplines that matter most, when fused with cyber intelligence, are geopolitical intelligence, which provides context on why a particular actor is targeting your sector right now and can give four to eight weeks of predictive lead time before a campaign hits; physical security intelligence, which surfaces hybrid attack patterns such as physical reconnaissance preceding cyber intrusion; structured OSINT, which provides cost-effective broadband coverage across all domains simultaneously; and financial and reputational intelligence, which reveals adversary financing and target selection logic that pure cyber signals cannot surface. The point is not that CTI teams should absorb every other intelligence function. The point is that opening structured channels with colleagues who already hold these signals produces a dramatically better threat picture for very little additional cost.

Expanding the remit also opens entirely new domains of intelligence product across the business. Executive and personnel protection, providing early warning of targeted harassment, travel risk, and physical threats to senior leaders, is intelligence that goes directly to the CEO and board. Supply chain and logistics risk, critical infrastructure proximity, pandemic and health risk, financial fraud, and coordinated reputational attacks are all areas where your CTI skills and access to threat data translate directly into business value. Every one of those domains has a named senior stakeholder who cares about it. That is your expanded customer base.

Why cross-domain intelligence matters

Consider a CTI team that detects a significant spike in phishing campaigns targeting the energy sector. Standard practice: attribute to a known threat actor group, recommend patching a relevant CVE, update email filters, brief the SOC. The escalation to senior leadership: “we’re seeing increased phishing activity.” The response, entirely predictably: “so what?”

Now apply a whole-of-business intelligence view to the same signal. The geopolitical team has flagged bilateral energy sanctions announced six weeks earlier. The threat actor group is linked to the sanctioned country. The physical security team has reported increased drone activity near energy infrastructure substations in the region. OSINT analysts have found forum posts referencing critical national infrastructure targeting. Financial intelligence signals that the group has recently received increased operational funding.

The escalation looks completely different: “We believe we are observing the early stages of a state-sponsored hybrid campaign targeting critical energy infrastructure. We recommend a physical security review of operational sites, enhanced monitoring of OT networks, executive communication protocols, and engagement with sector sharing groups. This is a board-level risk event.” Same underlying signal. Completely different intelligence output. One gets filed. The other gets acted on.

The impact on budget and organizational resilience

When budgets tighten, cyber threat intelligence sounds like a technical function that lives inside the security team and can be scaled back when the security budget is squeezed. But if an intelligence team protects the CEO from targeted harassment, alerts the board to geopolitical risks affecting the supply chain, provides early warning of threats to physical operations, and models the financial impact of fraud campaigns, that is enterprise risk management. Every senior leader in the organization understands and values that. It is much harder to cut.

The teams that survive budget cycles are the teams that senior leaders cannot imagine operating without. Cyber-only intelligence is a cost centre. Risk intelligence is a strategic asset.

The question is not whether intelligence is valuable

The organizations that will have the strongest, most valued, and most resilient intelligence functions over the next five years are not the ones with the most cyber tools. They are the ones that treat intelligence as a whole-of-business capability, fusing signals across cyber, geopolitical, physical, financial, and reputational domains into a single, coherent picture that every senior leader can act on.

The question is not whether threat intelligence is valuable. The question is whether you have made that value impossible to ignore.

Holistic business intelligence provides both greater insights and greater return on investment for CTI teams that expand their reach across multiple business functions. That is the argument I’d encourage you to take back to your organizations, and the capability that Silobreaker’s intelligence platform is built to support.

Watch the full SANS webcast, Bridging the Gap Between Threat Intelligence and Business Risk, on demand now.