Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What is the difference between a threat intelligence…
Threats, Abuse & Incident Response

What is the difference between a threat intelligence hub and an attack glossary for email security teams?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

A threat intelligence hub tracks emerging campaigns, trends, and analysis that help teams understand what is happening now. An attack glossary explains attack types in a stable, reusable way so analysts and defenders can recognise patterns consistently. Together, they support both situational awareness and shared terminology, which improves triage, communication, and response across security teams.

How a threat intelligence hub differs from an attack glossary

A threat intelligence hub is built for change: it collects and updates current reporting, emerging campaigns, actor activity, and contextual analysis so defenders can understand what is happening now. An attack glossary is built for stability: it defines attack types, labels, and shared terminology so teams can recognise and communicate patterns consistently. The first supports awareness, the second supports classification.

That difference matters because email security teams need both time-sensitive insight and durable language. If analysts are chasing live phishing waves or BEC variants, they need current intelligence. If they are triaging alerts, writing detections, or briefing non-specialists, they need a stable glossary that keeps everyone aligned on the same attack description.

Why email security teams use both sources together

Email threats move quickly, but the operational language used to describe them should not. A hub helps a team spot campaign shifts, infrastructure reuse, lure themes, and changes in attacker tradecraft. A glossary helps the same team avoid ambiguity when one person says “phishing,” another says “credential theft,” and a third means “business email compromise.”

That pairing improves triage and reporting. The hub can point analysts toward the latest CISA cyber threat advisories and other current-source analysis, while the glossary gives them the vocabulary to map a live incident to repeatable labels. For teams that need broader adversary context, the MITRE ATT&CK Enterprise Matrix is useful for turning observed email abuse into techniques that can be hunted, detected, and reported consistently.

For defenders who need an evidence-backed view of current activity, an external threat landscape source such as the ENISA Threat Landscape is a good example of the hub model in practice: it emphasises current trends and recurring patterns rather than fixed definitions.

How to decide which one you need in a given workflow

Use a threat intelligence hub when the question is “what is happening, who is doing it, and how is it changing?” Use an attack glossary when the question is “what do we call this, how do we describe it, and how do we keep that description consistent?” In practice, the same incident often needs both, but at different moments in the workflow.

A hub is better for watchlists, briefing notes, and escalation meetings because it helps a team prioritise new signals and correlate them with current campaigns. A glossary is better for playbooks, taxonomies, detection names, and executive summaries because it reduces drift in terminology. The right operating model is usually hub for context, glossary for language, and both for response quality.

Risk and Threat Considerations

When teams confuse the two, they can end up with either stale context or unstable terminology. Too much reliance on a glossary can make analysts recognise the label but miss the latest attacker variation; too much reliance on a hub can leave the team with rich intelligence but inconsistent naming that slows handoffs and weakens reporting.

Failure mechanism: Analysts treat changing campaign intelligence as if it were a fixed definition, or they let a glossary carry more operational context than it was designed to hold. That creates gaps in triage, detection tuning, and incident communication.

Impact: Slower response, inconsistent case handling, duplicated effort, and weaker cross-team alignment when email attacks evolve faster than the organisation’s terminology.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKEnterprise MatrixMaps adversary email attack techniques into a stable technique taxonomy.
Recommendation — Map observed email abuse to ATT&CK techniques and use that taxonomy in detections and triage.
NIST CSF 2.0ID.RA-01 — Threat and Vulnerability InformationThreat hubs support current threat and vulnerability awareness for email defenders.
PR.AT-01 — Role-Based TrainingShared attack terminology improves team understanding and response execution.
Recommendation — Use threat intelligence to inform risk assessment and response priorities. Train staff on attack labels and response language so incidents are handled consistently.
CIS Controls v817 — Incident Response ManagementEmail threat intelligence and attack terminology both support coordinated incident handling.
Recommendation — Maintain response playbooks that use current threat context and consistent attack naming.

Practitioner Guidance

What to prioritise: Keep the intelligence hub tied to current campaign intake, then use the glossary to standardise how incidents are labelled in tickets, detections, and reports. If one source starts doing both jobs, the team usually loses either freshness or clarity.

What to verify: Check whether analysts can trace a reported email attack from live context to a stable term without changing meaning midstream. Good operating hygiene is visible when the same incident can be briefed, detected, and escalated using consistent language.

Practitioner takeaway: A hub helps you understand the newest threat, but a glossary helps your team agree on what that threat is called; mature email security operations need both, kept deliberately separate.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org