Contact Bar
Sri Lanka
India
Sri Lanka
Bangladesh
Middle East

Your threat intelligence analyst has been at their desk since before the rest of the floor filled up, and by mid-morning on Monday will have produced the weekly threat report: fourteen pages, a colour-coded severity table, and a distribution list of thirty-one people.

Open the read receipts. Four people opened it, two for under twenty seconds. Nobody replied.

By Wednesday, the CISO forwards an article about a campaign targeting regional banking infrastructure and asks a reasonable question: does this affect us? The answer arrives on Friday afternoon, after the analyst has cross-checked indicators against the asset inventory, chased the network team for firewall logs, and confirmed that two of the listed domains were never blocked because the SIEM ingestion pipeline was paused in March after a weekend of false positives.

Nobody here is incompetent. The analyst is good. The CISO is asking the right question. The SOC made a defensible call when it muted a noisy feed. And yet the organisation pays for three commercial intelligence subscriptions, two ISAC memberships and a vendor newsletter, and the practical output of all of it is a document four people skimmed.

This is the state of most threat intelligence programmes across the region. Not a shortage of intelligence. A shortage of decisions.

Busy at the front, empty at the back

On the org chart, threat intelligence looks solved. There is a line item in the budget, a named owner, a subscription list and a reporting cadence. If the board asks whether the organisation has threat intelligence, the answer is yes.

The trouble is that the org chart describes inputs, and security outcomes are made of outputs. The question that matters is not whether intelligence arrives. It is whether anything downstream changed this week: a detection rule written, a domain blocked, a patch reprioritised, a supplier questioned, a board decision reversed. For most teams that audit is uncomfortable. Intelligence arrives in volume and leaves as a PDF, and the distance between the two is filled with human effort that does not scale.

That distance has a shape. Collection is cheap now: anyone can subscribe to more feeds tomorrow. Analysis is expensive, because it requires someone who knows both the threat landscape and your specific environment. Dissemination is where almost everything dies, because it means converting analysis into prose, and prose is the one format no security control can consume. The result is a programme that is busy at the front and empty at the back. Thousands of indicators a week enter. A handful of paragraphs leave.

Meanwhile a second problem runs in parallel and gets almost none of the budget. The most damaging exposures often have nothing to do with your perimeter. They are already outside it, already public, and already being used.

The real challenges

  • Volume without relevance

Three commercial feeds, two ISAC memberships and a vendor newsletter will comfortably produce several thousand indicators in a week. The overwhelming majority of them are irrelevant to you.

They describe threat actors targeting sectors you are not in, exploiting technologies you do not run, in geographies where you have no presence. A bank in Colombo or Dhaka receives the same undifferentiated stream as a manufacturing group in Europe. The feed does not know your sector, countries of operation, technology stack or third parties, so it cannot filter for any of them.

Filtering is therefore left to a human, and a human filtering several thousand items a week is not doing intelligence work. They are doing triage, badly, under time pressure, and they will miss things.

  • The SIEM ingestion that quietly died

The standard advice is to pipe indicators straight into the SIEM. Most teams have tried it. Many have quietly stopped.

The failure mode is consistent. Raw indicator lists arrive without confidence scoring, without context on why an indicator was flagged, and without expiry logic. Old infrastructure long since reassigned to a legitimate service stays on the list. The SIEM matches it, an alert fires, an analyst spends twenty minutes proving it is nothing.

Multiply that by a weekend and you get an alert queue nobody trusts. The rational response is to narrow the ingestion scope, then narrow it again, and eventually leave the integration technically enabled but functionally muted. The pipeline exists in the architecture diagram. It stopped influencing anything months ago.

  • The analyst who formats instead of hunts

Ask a threat intelligence analyst how they spend a week and the answer is rarely “hunting”. It is reading, summarising and formatting.

Two days go into the weekly report. Sources are read, notes taken, the template opened, the severity table rebuilt, screenshots pasted, the executive summary rewritten three times for people who will not read past it.

This is skilled work spent on document production. The same person, given the same two days, could have written detection logic for the techniques in that report, validated it against your telemetry, and handed the SOC something that fires when the campaign reaches you. Instead they produced a PDF, and next Monday they will produce another.

For MSSPs the arithmetic is worse. Client-specific intelligence means the same formatting work repeated per client, per week, and serving thirty clients properly is impossible with the headcount available. So most send a generic report with the client’s logo on the cover and hope nobody notices the sector section does not match their business.

  • The three-day answer to a one-hour question

“Does this campaign affect us” is the single most common question leadership asks, and it is the question intelligence programmes are worst at answering quickly.

Answering it properly requires four things at once: the campaign’s indicators and techniques, an accurate inventory of your assets, your telemetry to check for historical matches, and someone with the judgement to interpret gaps. In most organisations those four things live in four places, three are out of date, and the fourth requires a ticket to another team.

So the answer takes three days. By then leadership has moved on, and the lesson is learned on both sides: do not ask, because the answer will not arrive while it is useful.

  • Intelligence that never becomes an artefact

Here is the clearest test of a threat intelligence programme. Take last month’s reports and count the artefacts they produced.

How many detection rules were written and deployed? How many domains or IPs were added to a block list? How many vulnerabilities were reprioritised because a specific actor was observed exploiting them against your sector? How many supplier conversations were triggered? How many board decisions changed?

For many programmes the honest count across a full month is close to zero. Not because the intelligence was wrong, but because it stayed in the format it arrived in. Narrative in, narrative out. Nothing in that chain was ever expressible as a Sigma rule, a STIX bundle or a firewall entry, so nothing in the security stack could consume it.

  • The exposure that is already outside your perimeter

While the intelligence team reads about nation-state campaigns, the incident that actually hurts is usually simpler, and already in progress somewhere you are not looking.

An employee reused a corporate password on an unrelated consumer service breached two years ago, and those credentials are now in a combolist being sprayed against your VPN. A look-alike domain registered eleven days ago with a homograph substitution in your brand name is already serving a convincing login page to your customers, and the first you hear of it is a call centre complaint. A developer pasted a configuration file containing a live key into a public paste site while debugging. A forgotten subdomain from a 2021 campaign microsite is still resolving, still running an unpatched framework, and is in no asset inventory. A supplier with VPN access into your environment was compromised last week and has not told you.

None of these appear in a commercial threat feed, and none will be found by a SIEM, because none touch your logs until the damage is done. They are visible only from the outside looking in, which is the vantage point most security programmes never occupy.

  • Regional targeting that generic intelligence misses

Across South Asia, Southeast Asia and the Middle East, this outside-in problem has a distinctly local shape.

Phishing increasingly arrives in local languages and scripts rather than generic English, defeating content filters tuned on English corpora. Brand impersonation of regional banks, telcos and airlines is a persistent and growing pattern, because these brands carry high consumer trust and comparatively less international scrutiny. Fraudulent apps mimicking Gulf and South Asian financial brands appear in third-party stores no Western-centric monitoring service watches.

A globally sourced feed is structurally unlikely to surface any of this. It watches different languages, registrars, marketplaces and fraud economies. Your exposure is regional. Your intelligence is not.

Why hiring one more analyst does not fix this

The obvious response to everything above is headcount. If one analyst cannot keep up, hire a second.

It rarely works, for three reasons.

The first is that the bottleneck is not analytical capacity, it is throughput on repetitive production work. A second analyst spends their week doing the same reading and formatting as the first. You now produce two reports instead of one, and the read-receipt problem is unchanged.

The second is that experienced CTI analysts are scarce across the region, and the ones you can hire are expensive and mobile. A programme that depends on two or three named individuals carries a resignation risk. When the senior analyst leaves, the sector knowledge, the source relationships and the informal filtering criteria leave with them, because none of it was ever written down in a form a machine could hold.

The third matters most. Human analysts do not scale to the volume of the input. Several thousand indicators a week, across dozens of sources, in multiple languages, correlated against a live asset inventory, is not solved by adding people. It is solved by changing what people are asked to do: stop asking them to read and format, start asking them to judge.

The same logic applies to buying a fourth feed. More collection into a pipeline already blocked at dissemination makes the blockage worse, and it does nothing about the exposure outside your perimeter, because feeds report on the threat landscape in general, not on your brand, credentials, domains and suppliers.

Two changes are needed at once. Compress collection, analysis and reporting so intelligence arrives already relevant and already in a format your tools can consume. And add an outside-in view, so you learn about your own exposure from the vantage point an attacker uses.

How Liberty91 approaches the intelligence pipeline differently

Liberty91 is an AI-powered cyber threat intelligence platform, and the design decision that matters is where the automation sits. This is not a feed with a chat interface bolted on. Collection, analysis and the production of finished intelligence are machine-driven, with the human at the judgement layer rather than the transcription layer.

The platform is built around what it calls Intelligence Requirements: ongoing knowledge bases covering sectors, malware families, threat actors and your own organisational assets. This solves the relevance problem structurally rather than by triage. You describe your sector, geographies, technology stack, assets and supply chain once, and every subsequent piece of collection is assessed against that profile. A campaign targeting Gulf financial services is relevant to a bank in Riyadh and not to a logistics group in Colombo, and the platform knows the difference because you told it, not because an analyst read the headline. Documents can be uploaded and extracted automatically into the asset inventory and supply chain records.

Collection runs continuously across real-time threat monitoring, security news aggregation, premium intelligence sources, social media and the dark web, and Liberty91 operates as a group of AI agents split by function. Knowledge agents maintain currency on the threats matching your requirements. Tradecraft agents apply analytical method to what has been collected, including structured techniques such as Analysis of Competing Hypotheses, the discipline that separates intelligence from summarising. The platform describes the effect as a real-time junior threat intelligence analyst available continuously, and that framing is right: it does the reading, the correlation and the first draft, and your senior people judge.

The output side is where the PDF problem gets solved. Analysis is emitted as artefacts, not only prose. Extracted indicators of compromise. Detection rules in Sigma, YARA and KQL. STIX bundles for structured exchange. Branded PDF reports where a human-readable document genuinely is the deliverable, such as a board pack. A daily Morning Report email for standing awareness.

The distinction is not cosmetic. A Sigma rule can be deployed. A KQL query can be run against your telemetry today to answer whether a campaign already touched you. A STIX bundle imports without anyone retyping it. Producing these by hand is what consumes an analyst’s week.

Delivery runs through a distribution capability called Mailroom, alongside integrations into SIEM and SOAR platforms, ticketing systems and threat intelligence platforms, so intelligence lands inside the tools your SOC already runs, in the format those tools expect.

For MSSPs this changes the economics, not just the effort. Intelligence Requirements can be maintained per client and tailored products generated per client on a schedule. What made thirty clients impossible was the repeated production, not the analysis.

How Brandefense covers the half you cannot see

Liberty91 addresses the pipeline from collection to decision. Brandefense addresses the other problem: what the internet already knows about you. It is a unified threat intelligence platform for external cyber risk, organised into four modules that map onto the outside-in gaps described earlier.

External Attack Surface Management provides continuous asset discovery from an attacker’s vantage point, mapping root domains and all subdomains, IP ranges across full CIDR blocks and cloud instances across AWS, Azure and GCP, using certificate transparency logs as a source. That is how forgotten assets surface: shadow IT, unauthorised deployments, orphaned cloud resources and unknown domains that exist in reality but not in any inventory. Findings are prioritised with real-time risk scoring combining exploitability, active threat actor activity, CVE severity and business context.

Digital Risk Protection Services covers brand, credential and fraud exposure across the open, deep and dark web: continuous dark web monitoring, credential leak and account takeover protection aimed at the combolist and credential stuffing problem, and impersonation detection that identifies phishing infrastructure before customers are exploited. Phishing domain detection covers typosquatting and look-alike domains, homograph attacks, newly registered domains, and SSL certificate and DNS anomalies. Executive exposure tracking follows impersonation of key personnel across social media, the dark web and email.

Critically, detection is paired with mitigation rather than ending at an alert: automated phishing and social media reporting to registrars and hosting providers, domain takedown coordination across global registrars, and direct escalation to social platforms for impersonation removal. A look-alike domain detected but not removed is still collecting your customers’ credentials, so the takedown workflow is what converts a finding into an outcome.

Third-Party Risk Management extends the same view to your suppliers. Vendor assets are discovered automatically, including domains, subdomains, IPs and cloud assets, then monitored continuously with dynamic risk scoring rather than an annual questionnaire. Predictive models surface early warning signals for vendors showing pre-breach risk indicators, which is the difference between hearing about a supplier compromise from the supplier and hearing about it from the news. A fourth module, Cyber Threat Intelligence, adds industry-tailored threat and vulnerability intelligence.

EGUARDIAN distributes both Liberty91 and Brandefense across its territories, and they are carried together for a reason. One compresses the path from raw collection to a deployable artefact inside your existing stack. The other watches the part of your risk surface that stack cannot see at all.

What this looks like in practice

Consider a bank in the Gulf with retail operations, a mobile app and forty suppliers holding network or data access. A campaign targeting regional financial institutions breaks on a Tuesday. Liberty91 collects it, assesses it against the bank’s Intelligence Requirements, and confirms it matches sector, geography and two technologies in the asset inventory.

Within the same working session the finished product is available: an assessment, extracted indicators, Sigma and KQL detection rules, and a STIX bundle. The KQL runs against the bank’s telemetry that morning and answers the leadership question directly. There is no historical match, and the evidence for that is a query, not an opinion. The Sigma rules deploy to the SIEM through the existing integration, indicators reach the block list, and a vulnerability referenced in the campaign moves up the patch queue because it is now tied to observed exploitation against the bank’s own sector.

In parallel, Brandefense flags three items. A look-alike domain registered nine days ago using a homograph substitution in the bank’s name, now serving a login page, which enters the takedown workflow. Employee credentials surfacing in a dark web dump from an unrelated consumer breach, triggering targeted resets rather than a global one. And a supplier whose external risk score dropped after new exposed services appeared on their perimeter, which becomes a conversation this week instead of at the next annual review.

By Thursday the week has produced deployed detection logic, a blocked domain, a reprioritised patch, a credential reset, a takedown in progress and a supplier escalation. It also produced a report, but the report is now a record of decisions taken rather than a substitute for them.

Mapping the failures to the fix

Where intelligence programmes breakWhat Liberty91 addressesWhat Brandefense addresses
Thousands of weekly indicators, most irrelevant to your sectorIntelligence Requirements profile collection against sector, threat actors, malware families and your assetsIndustry-tailored CTI, scoring weighted by business context
SIEM ingestion abandoned after false positivesDeployable Sigma, YARA and KQL rules and STIX bundles, not raw indicator listsPrioritised, contextualised findings instead of scan output
Analysts reading and formatting instead of huntingMachine-produced assessments, reports and Morning Report summariesAutomated detection and takedown replacing manual brand monitoring
“Does this affect us” answered in three daysCorrelation against your asset inventory with ready-to-run queriesContinuous external asset discovery keeping exposure current
Leaked credentials, look-alike domains, forgotten subdomainsDark web and social media collection feeding the profileEASM, dark web monitoring, credential leak and ATO protection, impersonation detection with takedown
Supplier compromise learned about too lateSupply chain tracked in the organisational profileVendor attack surface monitoring, dynamic scoring, pre-breach signals
MSSPs unable to produce client-specific intelligence at scalePer-client Intelligence Requirements with automated productionPer-client external monitoring and takedown as a service line

Who benefits most

Banks, insurers and payment providers across South Asia and the Gulf, where brand impersonation and credential-based fraud are persistent, regulators expect demonstrable threat awareness under frameworks such as RBI, SAMA, MAS and central bank guidelines in Sri Lanka and Bangladesh, and the customer-facing brand is itself an attack surface.

Telcos, airlines and critical infrastructure operators, carrying high public trust, messy external estates accumulated over years of campaigns and acquisitions, and a supplier base wide enough that third-party compromise is routine.

Government and public sector entities, subject to regionally targeted campaigns and local-language phishing, with small intelligence teams carrying a national-scale remit.

MSSPs and managed SOC providers, for whom client-specific intelligence has been the promise that could not be kept at scale, and for whom automated per-client production plus external monitoring is a sellable service line rather than an internal efficiency.

Intelligence is measured by decisions, not documents

The reframe is this. The purpose of a threat intelligence programme is not to produce intelligence. It is to change what the organisation does.

If your reporting cadence is impeccable and your detection rules have not changed in a quarter, the programme is not working, however good the analysis. If you can describe the threat landscape in detail but cannot say whether a look-alike domain is harvesting your customers’ credentials right now, you are informed about the world and blind about yourself.

The metric worth adopting is deliberately awkward: how many decisions changed this month because of intelligence? Detection rules deployed. Domains blocked and taken down. Patches reprioritised. Credentials reset. Suppliers challenged. Board positions revised.

Measured that way most programmes score badly, and the reason is not the quality of the intelligence. It is the distance between the intelligence and the decision, and that distance is made of manual work: reading, filtering, formatting, retyping. Compress it and the same team produces outcomes instead of documents. Add an outside-in view and it finally sees what no internal tool will surface.

Talk to our experts at EGUARDIAN. If your threat intelligence programme is producing more reports than decisions, or if you suspect your real exposure is sitting outside your perimeter where none of your tools are looking, let us look at your sources, your tooling and what a decision-first programme would look like for your organisation. Reach out to us at hello@eguardian.com.