Every major cybercriminal operation relies on collaboration. Ransomware groups share infrastructure, initial access brokers sell compromised credentials to multiple buyers, malware developers reuse successful code, and threat actors openly exchange techniques that have already proven effective. Modern cybercrime has become an efficient, highly connected ecosystem where knowledge travels quickly and success is shared.
Many defenders, however, still approach cybersecurity as though every attack is unique. Organisations continue to investigate incidents in isolation, consume intelligence as static reports, and make security decisions based largely on what they can see within their own environment. At a time when attackers are learning from one another every day, defenders cannot afford to rely solely on what they know about themselves and their organisations.
The organisations that become more resilient over the next decade will not necessarily be those with the largest security budgets or the most sophisticated technology. They will be those that learn from the experiences of others before those same threats arrive on their own doorsteps.
Cybercriminals already understand the value of collaboration
Cybercrime has become remarkably efficient because attackers rarely start from scratch. A successful phishing campaign quickly becomes a template for the next one. A newly discovered exploit is incorporated into attack kits within hours. Techniques shared on underground forums can be replicated thousands of times across different victims, industries and geographies.
The result is that organisations are no longer facing isolated attacks. They are facing industrialised campaigns that have already been tested, refined and repeated elsewhere. By the time a security team encounters a particular tactic, there is a good chance another organisation has already experienced it. That reality should fundamentally change how defenders think about preparation. If attackers are constantly learning from previous operations, shouldn’t defenders be doing exactly the same?
We have no shortage of intelligence. We have a shortage of action.
Most organisations would argue they already consume threat intelligence. Security operations centres receive intelligence feeds, vulnerability notifications, indicators of compromise and reports from commercial and open source providers every day.
The challenge is making that information useful.
Filigran’s 2026 State of Threat Management Report found that almost every organisation uses threat intelligence within its security operations centre, yet fewer than half have fully integrated and operationalised it. On average, organisations consume 14 different threat intelligence feeds, many of which still require analysts to manually correlate, contextualise and prioritise the information before it becomes actionable.
Adding another feed does not necessarily improve security. In many cases, it simply creates another stream of information competing for already limited attention. Threat intelligence only delivers value when it changes what an organisation decides to do next and how quickly it can help make that decision.
Intelligence should influence decisions, not just dashboards
Security leaders should ask themselves a difficult question: When was the last time a piece of threat intelligence genuinely changed a decision?
Did it alter patching priorities? Did it trigger additional validation of critical systems? Did it lead to changes in detection rules or executive risk discussions? Or did it simply become another report stored alongside dozens of others?
The distinction is important because information has very little value on its own. Intelligence only becomes meaningful when it influences behaviour.
This is where many organisations continue to struggle. According to the same research, 84% of organisations say the attacks they experience exploit risks they already knew about but had failed to prioritise, while 97% report difficulties determining whether identified exposures are actually exploitable.
Those figures suggest the industry’s biggest challenge isn’t just about discovering the threats to their organisations. It is understanding which ones are meaningful enough to deserve immediate attention.
Sharing intelligence as a strategic capability
The conversation around threat intelligence has traditionally focused on sharing indicators of compromise or exchanging reports between trusted organisations. While those activities remain valuable, the conversation needs to move further.
The real objective should be operational learning.
If another organisation has already identified how a ransomware group gains initial access, that knowledge should influence how others assess their own exposure. If an adversary is exploiting a particular vulnerability in a specific way, organisations should understand whether the same attack path exists within their own environment before they become the next victim.
"Cybercriminals have demonstrated the advantages of collaboration. Defenders can learn from this."
Governments are beginning to recognise the significance of this approach. We have already seen greater emphasis on open standards that make threat intelligence easier to exchange between government organisations, allowing information to move more quickly and consistently across different security platforms. This kind of standardisation is vital since intelligence loses much of its value when it cannot be shared efficiently.
However, technology standards alone are only part of the answer to help increase long term resilience. Organisations also need a culture that values collaboration over isolation. Threat intelligence should become something that actively shapes security operations, rather than something that is simply collected and archived.
Cyber resilience depends on learning from everyone else's mistakes
One of the most expensive habits in cybersecurity is repeatedly solving problems that others have already solved.
Every incident should contribute to collective understanding, making future attacks easier to recognise and quicker to contain. For example, open source communities, industry information sharing groups, government partnerships and trusted security networks all contribute to this objective. They allow organisations to benefit from knowledge that extends far beyond the limits of their own environments.
This does not mean blindly applying every external recommendation. Context, of course, will always matter. Every organisation has different assets, different priorities and different levels of risk. But shared intelligence provides the starting point. It allows security teams to ask better questions, validate assumptions earlier and focus effort where it is most likely to make a difference.
The future belongs to connected defenders
Frameworks such as Continuous Threat Exposure Management (CTEM) reflect this mindset change by encouraging organisations to connect threat intelligence with exposure management, validation and remediation as part of a continuous process, rather than treating them as separate activities. The principle is simple. Intelligence should help organisations understand which threats are significant, validate whether they are exposed and continuously improve their defensive posture, instead of existing as an isolated security function.
This is becoming more important as attackers move faster than ever with artificial intelligence helping adversaries discover vulnerabilities, automate reconnaissance and adapt campaigns at unprecedented speed. Defenders cannot respond effectively if threat intelligence remains trapped inside reports that require hours of manual interpretation before action can begin.
Creating shorter paths between learning about a threat and acting on it and treating intelligence as a living operational capability that informs decisions every day will be the goal posts by which successful security teams are measured.
Stop defending alone
Cybersecurity has never been a competition between individual organisations and individual attackers. It has always been a contest between two communities that learn, adapt and improve over time. Cybercriminals have demonstrated the advantages of collaboration. Defenders can learn from this.
The distinguishing factor in today’s elite security teams is whether they are using the collective experience of the wider security community to strengthen their own defences before an attack occurs. Because the next organisation targeted by a familiar campaign should never have to learn the same lesson twice.
Matthew Neville
Matthew Neville is Manager of Customer Cuccess at Filigran.


