By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished March 10, 2026

TL;DR: The SANS 2023 CTI Survey shows that current events, geopolitics, and external news sources continue to shape analyst priorities, while threat intelligence is becoming more cross-functional across organisations, according to Anomali’s summary of the survey. That shift matters because CTI now has to support faster operational decisions, not just reporting.


At a glance

What this is: This white paper summarises SANS 2023 CTI survey findings showing that threat intelligence is becoming more cross-functional and increasingly driven by external events and sources.

Why it matters: It matters to IAM practitioners because threat-informed decisions increasingly affect access controls, identity risk prioritisation, and how security teams coordinate across human and machine identity programmes.

👉 Read Anomali's white paper on the SANS 2023 CTI survey results


Context

Threat intelligence programs fail when they are treated as a reporting function instead of an operational input into security decisions. In this white paper, the key governance issue is not whether CTI exists, but whether it can influence prioritisation quickly enough as the threat landscape shifts. The article also matters to identity programmes because intelligence about attacker behaviour increasingly informs account protection, privileged access decisions, and NHI risk response.

The survey points to a CTI function that is becoming more dependent on external context and more embedded across teams. That combination creates a governance challenge for security leaders: intelligence must be timely, trusted, and usable by operations, cloud, IAM, and SOC stakeholders. For identity teams, that means CTI can no longer sit apart from credential risk, privileged access monitoring, or machine identity exposure.


Key questions

Q: How should security teams turn CTI into practical control changes?

A: They should map intelligence inputs to specific control owners and response thresholds before incidents happen. A useful CTI program does not just brief stakeholders. It tells IAM, PAM, cloud, and SOC teams when to tighten access, inspect accounts, or increase monitoring based on defined threat conditions.

Q: Why do external intelligence sources matter so much for CTI programs?

A: External sources often surface emerging threats before local telemetry shows abuse. That makes them valuable for prioritisation, especially when attackers exploit exposed credentials, public infrastructure, or newly disclosed techniques. The risk is over-reliance, so teams should always validate external signals against their own identity and control data.

Q: What breaks when CTI is not shared across security functions?

A: The main failure is delayed action. If the SOC, IAM, cloud, and risk teams each interpret intelligence separately, no one owns the response path. That leads to inconsistent containment, slower privilege review, and missed opportunities to block attacker movement early.

Q: Who should own threat intelligence inside customer identity workflows?

A: Ownership should sit with the identity and security functions together, because the control affects both access policy and threat response. Identity teams need to define when a login is challenged or blocked, while security teams need to maintain the signals and escalation logic. That shared ownership prevents the connector from becoming a disconnected security add-on.


Technical breakdown

How CTI prioritisation is shaped by external events

Threat intelligence programs often begin with collection, but prioritisation is where value is won or lost. The survey indicates that current events and geopolitics strongly influence what CTI teams focus on, which means intelligence is being filtered through fast-changing context rather than fixed indicator feeds. That is a healthy shift, because adversaries do not operate in static cycles. The technical challenge is building a repeatable triage model that connects emerging events to the assets, identities, and attack paths most relevant to the organisation.

Practical implication: map intelligence intake to specific identity, cloud, and endpoint decision points so alerts change controls, not just reports.

Why external intelligence sources dominate CTI workflows

CTI teams increasingly rely on external news sources, vendor feeds, and community reporting because those inputs often provide earlier signal than internal telemetry alone. Internal data is essential for validation, but it usually arrives after exposure, discovery, or abuse has already started. A mature CTI function blends external context with internal control data to decide what is actionable. For identity security, that matters because exposed credentials, account abuse, and NHI compromise often surface first in outside reporting before they appear in local logs.

Practical implication: connect external threat feeds to identity telemetry, secret scanning, and privileged access monitoring for faster triage.

Cross-functional CTI needs shared operational ownership

CTI becomes more effective when it is used by the teams that can actually change controls. Cross-functional intelligence sharing means the SOC, IAM, cloud security, and GRC functions all consume the same threat picture, but each acts on different parts of it. That introduces a coordination problem unless ownership, escalation criteria, and response thresholds are defined in advance. The article shows CTI maturing beyond the analyst desk, which is typical of larger organisations but still uneven across the market.

Practical implication: define which teams own response for identity abuse, exposed secrets, and high-confidence threat indicators before an incident forces coordination.


NHI Mgmt Group analysis

CTI is shifting from insight production to decision support. The survey’s core signal is that intelligence teams are being judged less on volume and more on whether they help the organisation act faster. That raises the bar for collection, enrichment, and dissemination because intelligence that cannot change a control outcome is just reporting. For identity security teams, this is the same shift seen in NHI governance and privileged access management. The practical conclusion is that CTI must be measured by operational effect, not publication cadence.

Cross-functional CTI exposes a governance gap in ownership. Once intelligence starts influencing IAM, cloud, SOC, and risk decisions, unclear handoffs become a control weakness. Organisations often assume someone else will translate threat context into action, but that assumption breaks in incidents involving compromised credentials or third-party abuse. The result is delayed containment and inconsistent enforcement. The practical conclusion is that CTI governance has to define who acts, who approves, and who validates across the full response chain.

External-signal dependency creates a prioritisation risk. When teams rely heavily on external news and vendor feeds, they can become reactive unless those inputs are weighted against business-critical identity and asset exposure. The challenge is not the use of external sources itself, but the absence of a consistent model for turning external signal into local action. That matters for machine identity, where exposed tokens or service accounts may be abused long before internal detections mature. The practical conclusion is to formalise a decision model for when external intelligence triggers identity control changes.

Threat intelligence should now inform identity risk, not sit beside it. The article reinforces a broader market pattern: attacker behaviour, exploit timing, and public disclosures all affect how quickly identity controls need to adapt. That is especially true for non-human identities, where standing credentials and delegated access create narrow response windows. The practical conclusion is that CTI and identity governance should share escalation logic for exposed secrets, privileged accounts, and suspicious automation.

What this signals

CTI programmes are becoming more operational, which means identity teams need a faster way to convert threat context into control changes. For programmes that still separate intelligence from access governance, the result will be slower response to exposed accounts, service credentials, and delegated access paths.

The next maturity step is not more intelligence volume, but better routing. Security leaders should expect CTI to become part of identity risk orchestration, especially where exposed secrets, privileged access, or automation abuse can move faster than manual review cycles.


For practitioners

  • Define CTI-to-control escalation paths Document exactly which threat signals trigger action in IAM, PAM, cloud, and SOC workflows. Include thresholds for exposed credentials, third-party compromise, and high-confidence abuse indicators so teams do not improvise during an incident.
  • Integrate external intelligence with identity telemetry Correlate news, vendor reporting, and community indicators with logins, token use, secret exposure, and privileged access events. The goal is to identify which external signals should alter monitoring, not just increase analyst attention.
  • Assign one owner for identity-related threat intake Establish a clear handoff model for alerts tied to accounts, service identities, and access paths. When multiple teams receive the same intelligence, one team must own validation and one team must own containment decisions.

Key takeaways

  • CTI is moving from analysis to action, and programmes that cannot influence controls will lose relevance.
  • External threat context now matters because attackers often exploit identity weaknesses before internal teams fully observe the pattern.
  • The strongest CTI programmes are cross-functional, with clear ownership for identity-related alerts, escalation, and containment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0RS.AN-1CTI maturity depends on analysing and interpreting threat data for response.
NIST SP 800-53 Rev 5SI-4Security monitoring and alerting align with CTI collection and analysis workflows.
MITRE ATT&CKTA0006 , Credential Access; TA0010 , ExfiltrationCTI often tracks attacker behaviour tied to credential abuse and data theft.
CIS Controls v8CIS-13 , Network Monitoring and DefenseThreat intelligence supports monitoring and prioritisation across control environments.

Map threat reports to ATT&CK tactics so intelligence informs detection and response.


Key terms

  • Threat Intelligence: Threat intelligence is contextualised information about adversaries, techniques, and signals that helps teams decide what matters and what to do next. In practice, it becomes useful when it is tied to detection, identity scope, and response actions rather than remaining a feed of indicators.
  • Operational intelligence: Operational intelligence is the use of live or historical activity data to make better security and business decisions. In identity programmes, it means using access evidence not just for audit, but to improve productivity, reduce waste, and justify where controls should be tightened or redesigned.
  • Identity risk signal: A measurable indicator that an identity may be unsafe to trust at the moment of access. Common examples include compromised credentials, unusual movement patterns, or elevated severity scoring. The signal becomes useful only when it is wired into an enforcement path that can act on it.

What's in the full report

Anomali's full white paper covers the survey detail this post intentionally leaves for the source:

  • The survey methodology and respondent mix behind the CTI findings.
  • The full set of trend observations on how CTI priorities changed over time.
  • Additional context on how vendors and customers collaborate in CTI operations.
  • Expanded discussion of where the field can mature next.

👉 The full Anomali white paper includes the survey context, respondent breakdown, and broader CTI trend discussion.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect identity control decisions to the broader security programme they operate every day.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org