Last week, Forrester published The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026 | Forrester. Since our last evaluation in 2023, the market has undergone a significant transformation. This transformation has been driven not only by the growing sophistication and breadth of threat intelligence requirements, but also by the rapid adoption of agentic AI as organizations race to counter the asymmetry between AI-powered attackers and increasingly overstretched defenders.

What’s New In This Wave?

The prior iteration of the Wave, The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2023 | Forrester, evaluated 12 vendors against 14 current offering criteria, 6 strategy criteria, and 2 market presence criteria. The 2026 evaluation reflects a supercharged market. Several vendors from the 2023 assessment, including Trellix, CybelAngel, Microsoft, Rapid7, and IBM, were not included in the latest evaluation.

This iteration evaluates 10 vendors: CrowdStrike, Recorded Future, Google, Flashpoint, ReliaQuest, Netcraft, ZeroFox, Fortinet, TrendAI, and Doppel against 17 current offering criteria and across 6 strategy criteria. Participants were categorized as Leaders, Strong Performers, and Contenders based on analysis of tailored questionnaire responses from vendors, executive briefings, product demos, and customer reference interviews. Key takeaways from the evaluation include:

  • Priority Intelligence Requirements (PIRs) have moved from passive onboarding to active adoption. Previous evaluations examined how providers gathered intelligence requirements. The most recent assessment evaluates how effectively Priority Intelligence Requirements (PIRs) are embedded within the platform, operationalized across workflows, and translated into actionable outcomes and tracked risk reduction.
  • Digital risk protection gets the depth it deserves. The evaluation disaggregates Digital Risk Protection into distinct areas, including brand protection, executive protection, and fraud intelligence. This helped capture the depth and maturity of vendor capabilities meaningfully. With growing sophistication of deepfakes, disinformation campaigns, social engineering, impersonation attacks, and geopolitical instability, organizations need intel providers to act as domain experts to help identify, analyze and respond accordingly.
  • Agentic AI has become a product strategy battleground. While AI has been embedded across threat intelligence platforms for several years, this evaluation places greater emphasis on how vendors use AI to operate at scale, particularly across threat hunting, detection engineering, and intelligence processing and analysis. Just as importantly, the evaluation scrutinizes how vendors measure the effectiveness of their AI-driven capabilities and hence demand evidence of efficacy, operational impact, and return on investment (ROI); rather than an opaque promise of automation. The market remains sharply divided: some vendors continue to treat AI as a black box, and a few provide evidence of continued transparency or customization. Most, however, fall somewhere in between.

Threat Intelligence Consumer Market Dynamics

Today’s External Threat Intelligence Service Providers (ETISP) vendor strategies generally fall into two camps:

  1. Pure-play threat intelligence platform player that spans multiple use cases with varying levels of depth.
  2. Specialists that dominate a single intelligence domain (or sub-domain).

The challenge for buyers is that neither approach guarantees comprehensive coverage. Forrester’s evaluation highlights three realities for security leaders:

  1. Use-case excellence over platform breadth. Threat intelligence requirements vary widely across industries, geographies, and stakeholder groups. Corporate security teams care about executive protection, fraud teams focus on fraud intelligence, and cyber threat intelligence teams require rich collection, analysis, and operationalization capabilities. No vendor leads every category. Organizations must align vendor strengths to their most critical use cases rather than chasing an all-in-one promise.
  2. A balanced roadmap beats an AI-only roadmap. AI is rapidly becoming a competitive differentiator, but differentiation should not be mistaken for value. Vendors that invest heavily in AI-driven operationalization can deliver significant benefits, but only if those capabilities are built on strong intelligence collection, correlation, and contextualization. Think of it as advanced weaponry loaded with rusted ammunition. Prioritize vendors with a realistic roadmap that balances intelligence enhancements with AI-powered execution, and demand transparency instead of accepting AI as a black box.
  3. They need to build partnerships or in-house capabilities to close vendor gaps. Every ETISP vendor has strengths and weaknesses. Some excel at intelligence collection and enrichment but struggle to translate intelligence into high-fidelity detection content, policies, or automated actions at scale. While others shine in supporting capabilities but fall short on visibility and operational areas. Security leaders should assume that gaps will continue to exist and plan accordingly. Hence, enterprises must augment their intelligence providers with internal tooling and strategic partnerships. Whether it is an in-house detection engineering tool tailored to the enterprise’s technology stack or a regional partner that executes takedowns where vendor coverage is limited. Robust security posture will be achieved by organizations that compliment such gaps in their ETISP vendors.

For a closer look into this evaluation, scoring, and the overall market, Forrester clients can read the full report: The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026 | Forrester. Clients can also book an inquiry or guidance session with me if they have questions about the evolution of this market or need support navigating it.

Join us at Forrester’s Security & Risk Forum from November 9–10. I’ll be leading a session and a roundtable discussion focused on threat intelligence and its intersection with AI. Check out the full agenda to learn more about other sessions on Zero Trust, securing AI, GRC, AppSec, and many more topics.

Share