Threat intelligence sharing has one of the most persuasive arguments in security. Attackers reuse infrastructure, tooling and techniques across many victims. If the first organization hit publishes what it saw, everyone else can block it before they are targeted. Defenders currently operate in isolation while attackers operate at scale, and sharing inverts that asymmetry. The argument is correct in principle. In practice, a decade of sharing programmes has produced a wide range of outcomes — some genuinely valuable, some expensive theatre — and the difference between them is almost entirely about what gets shared and whether anyone can act on it.
Why Indicator Feeds Disappoint
Most sharing programmes deliver indicators of compromise: IP addresses, domain names, file hashes, URLs. This is the easiest thing to share because it is structured, unambiguous and contains no sensitive detail about the victim. It is also the least durable thing an attacker owns. Indicators expire almost immediately. Infrastructure is rotated in days or hours. File hashes change with a single byte. By the time an indicator has been observed, written up, reviewed for release, distributed and ingested, the adversary has frequently moved on. Volume-based feeds age into noise. Context is stripped out in the process of making sharing safe. The information that would actually help — how the attacker got in, what they did next, what the detection looked like, why the existing controls missed it — is exactly the information organizations are least willing to release. What remains is a list without a story. Consumption capacity is the real bottleneck. An organization receiving tens of thousands of indicators a week needs automation to ingest them, enrichment to prioritise them, tuning to avoid blocking legitimate traffic and analysts to investigate matches. Most organizations subscribed to feeds they had no capacity to use, then counted the subscription as a capability. And false positives carry business cost. A blocked supplier domain or a quarantined legitimate file is a real operational incident. Teams that were burned this way stop blocking automatically and start reviewing manually, at which point the feed is generating work rather than saving it. The honest summary is that indicator sharing has value as one input among several, mostly for retrospective hunting rather than prevention, and almost none as a standalone programme.
What Sharing Is Genuinely Good For
The programmes that work share something other than indicators. Techniques and behaviour, not artefacts. How an intrusion progressed, which legitimate tools were abused, what the persistence mechanism was, what the exfiltration looked like. Attackers change infrastructure trivially and change methods reluctantly, so behavioural detection built from shared technique descriptions survives far longer than a blocklist. The widespread adoption of a common vocabulary for adversary techniques is probably the single most useful thing to come out of this period, because it let organizations describe behaviour in terms others could act on. Sector-specific early warning. A regional bank learning that three peers are seeing the same targeted campaign this week is acting on information that no commercial feed will deliver with the same specificity or speed. Sector sharing communities work because the participants face the same adversaries, the same regulations and the same systems. Trusted small-group exchange. The most valuable sharing consistently happens between a handful of named practitioners who trust each other, frequently informally, frequently by phone. This does not scale and cannot be procured, and it outperforms every formal programme in speed and candour. And strategic reporting. Analysis of which adversaries are active against your sector, what they want, and how their operations are evolving informs investment decisions and board conversations better than any tactical feed. It is slower, more expensive and much more useful for planning.
The Obstacles Are Legal and Cultural, Not Technical
Two organizations that want to share can do so with simple tooling. The reasons they do not are almost never about formats or protocols. Nobody wants to disclose a compromise. Sharing implies being attacked, and being attacked implies failure. Legal counsel worries about regulatory exposure, litigation discovery and contractual notification triggers. Communications worries about reputation. The safest institutional position is to say nothing, and it is usually the position that wins. Regulatory notification complicates the timing. Where an incident may require disclosure to a supervisor, sharing informally with peers before that process is complete is legally uncomfortable, regardless of how useful it would be. Reciprocity is unbalanced. Many participants consume and few contribute, which is rational individually and destroys the commons collectively. Programmes that solved this did so by making contribution a condition of membership, or by having a trusted intermediary anonymise submissions. Competitive sensitivity is real. Sharing that reveals your architecture, your vendor choices or your weaknesses to competitors sitting in the same room is a genuine concern, particularly in concentrated markets. And the intermediary is the mechanism that works. Sector bodies, national cyber security centres and computer emergency response teams function because they can receive sensitive detail, strip attribution and redistribute the substance. Direct peer-to-peer sharing at scale rarely survives contact with legal review.
| Information | Possible operating use |
|---|---|
| Indicators | Search historical logs or review a context-specific match. |
| Techniques and behaviour | Develop and test detections for the described activity. |
| Sector warning | Check whether relevant exposures and dependencies apply. |
| Trusted exchange | Clarify an incident within agreed disclosure boundaries. |
| Strategic reporting | Inform investment and investigation priorities. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for a Threat Intel Program Review
- Define what decisions the programme should change before subscribing to anything. Intelligence that does not alter a control, a priority or an investigation is expensive news.
- Prioritise technique-level information over indicator volume. Behavioural detections outlive blocklists by a wide margin.
- Join the sector community for your industry and your country. Peer-specific warning is worth more than any general feed.
- Match feed volume to your ability to consume it. A single well-integrated source beats six that nobody ingests.
- Use indicators for retrospective hunting as well as blocking. Searching historical logs for a newly published indicator frequently finds something blocking would have missed.
- Agree the legal position on sharing in advance. Deciding what you can disclose during an incident guarantees that you disclose nothing.
- Contribute something, even anonymised through an intermediary. Communities where everyone consumes stop producing.
- Measure detections created, not indicators ingested. Volume metrics make a useless programme look productive.
The Regional Dimension
Threat intelligence sharing in the Gulf has developed differently from the model most Western guidance assumes, and the differences matter. National authorities are the central node. Cyber security authorities and national computer emergency response teams in the UAE and Saudi Arabia distribute advisories, coordinate on significant incidents and, for critical sectors, impose notification requirements. In practice this makes the government channel the primary sharing mechanism rather than a supplement to peer exchange — which is faster to establish and comes with obligations attached. Sector communities are concentrated and effective. The relatively small number of major banks, telecommunications operators, energy companies and government entities in each market means the practitioners largely know each other. Trusted small-group sharing — the format that works best anywhere — is unusually achievable here, and much of it happens through personal networks rather than formal programmes. Concentration cuts both ways. A small number of shared dependencies — the same integrators, the same core banking providers, the same telecommunications infrastructure — means a campaign against one is frequently relevant to all. That makes sharing more valuable and makes a single compromised supplier a systemic concern. Regional threat activity is geopolitically shaped. The adversaries that matter most to Gulf critical infrastructure are not the ones dominating commercial threat reporting written for other markets. Destructive attacks against energy and industrial targets are part of the region's direct history, and generic international feeds underweight exactly the activity that matters here. Regional sources are not a nice-to-have. Disclosure reluctance is stronger than average. In markets where reputation, relationships and government standing carry significant commercial weight, admitting an incident to peers is a harder decision than in jurisdictions with mandatory public breach disclosure. Anonymised submission through a trusted intermediary is not a refinement here; it is the only model that produces contributions. And analyst capacity is the binding constraint. Security teams in the region are frequently small, staffed through partners, and competing in a tight market for experienced people. Programmes that assume a dedicated intelligence analyst will curate and action feeds will fail on staffing. Buying curated, prioritised intelligence — or receiving it through a managed service — is usually the realistic path, and it should be recognised as such at the outset rather than after a year of unread reports.
Where It Landed
The automated indicator exchange that dominated discussion a decade ago settled into a commodity layer — useful, cheap, integrated into security platforms by default, and not something anyone builds a programme around any more. Standard formats and transport protocols became plumbing rather than strategy, which is the correct outcome for plumbing. The centre of gravity moved to behaviour. Shared technique frameworks changed how detection engineering is done, how coverage is measured and how teams communicate about adversaries, and that is the sharing story that actually delivered. Detection rules written against behaviour, shared as open content, proved far more durable than any indicator distribution. Sector communities matured and, in many jurisdictions, became mandatory in effect through regulation and notification requirements. And the commercial market bifurcated: cheap bulk feeds at one end, expensive analyst-led strategic reporting at the other, with the middle hollowed out because it was the least useful segment. AI is reshaping both sides again. On the defensive side, it makes unstructured intelligence — reports, advisories, incident write-ups — tractable at volume, correlating what would previously have gone unread and drafting detections from narrative descriptions. That addresses the consumption bottleneck, which was always the real constraint. On the offensive side, it lowers the cost of generating novel infrastructure and varied tooling, which further reduces the shelf life of any artefact-based indicator. The direction of travel is clear enough: sharing what attackers do will keep mattering, and sharing what they used last Tuesday will keep mattering less.
Common Questions
Does threat intelligence sharing actually work?
Selectively. Sharing techniques, sector-specific early warning and strategic analysis delivers real value. Bulk indicator feeds mostly do not, because infrastructure rotates faster than the distribution cycle and most organizations lack the capacity to consume the volume.
Why do organizations consume more than they contribute?
Because sharing implies disclosing a compromise, with legal, regulatory, contractual and reputational consequences. The safest institutional position is silence, which is why trusted intermediaries that anonymise submissions are the mechanism that actually produces contributions.
What should a programme be measured on?
Detections created, investigations triggered and decisions changed — not indicators ingested or feeds subscribed to. Volume metrics make an unused programme look productive.
What is different about the GCC?
National cyber security authorities act as the central sharing node rather than a supplement, concentrated sectors make trusted peer exchange unusually achievable, shared suppliers create systemic exposure, regional threat activity is geopolitically shaped and underrepresented in international feeds, disclosure reluctance is high, and small analyst teams make curated or managed intelligence the realistic option.
Threat Intel Program Review — Outpace checks whether your intelligence changes any decision, and cuts the feeds nobody reads.
