This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

The new playbook for Threat Intelligence teams
Threat Intelligence teams do their jobs well, and then some. They live up to industry expectations - building collection programs, operationalizing feeds, automating IOC ingestion, and routing intelligence into their detection and response systems.
But 'industry expectations' have fallen behind attack timelines. Today, attack timelines have compressed so dramatically that even the fastest detection and response cannot limit the damage. And it's not a team performance issue. The indicators TI teams depend on simply don't exist until the attack is already underway.
In this e-book, we'll lay out four stages of TI maturity - each one tied to where on the attack timeline your program can act.
The goal is to help you identify your current position, understand the transition ahead, and map the path from detection-led intelligence to pre-attack disruption.
Key findings
- Attack timelines have outpaced detection: eCrime breakout time averaged 29 minutes in 2025, down from 48 minutes the year before.
- Feed investment produces volume, not outcomes: 71% of organizations report significant overlap across their feeds, and 84% still rely on manual workflows to process what comes in.
- 91% of organizations plan to increase their TI investment in 2026; the question is whether it moves the control point upstream or adds more data than teams can use.
- Dark web monitoring has hit structural limits: the data it surfaces has already been stolen, sold, or abandoned, and sophisticated actors have moved to encrypted channels monitoring tools cannot reach.
- TI maturity comes down to where on the attack timeline your program can act, defined across four stages from IOC review to policy-driven pre-attack disruption.
- Gartner projects preemptive cybersecurity solutions will account for nearly 50% of IT security spending by 2030.
What is inside
- Executive Summary
- The Control Point Has Moved
- Stage 1: IOC Reviews and Dark Web Monitoring
- Stage 2: IOC Ingestion and Feed Management
- Stage 3: Early Warning and Pre-Attack Signal Detection
- Stage 4: Pre-Attack Disruption
- How to Operationalize Pre-Attack Disruption at Scale
- Own the Timeline
- About Malanta
Frequently asked questions
What is the TI maturity model?
The TI maturity model defines four stages based on where on the attack timeline a program can act. Stage 1 is IOC reviews and dark web monitoring, Stage 2 is IOC ingestion and feed management, Stage 3 is early warning and pre-attack signal detection, and Stage 4 is policy-driven pre-attack disruption.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. In practice, IoPAs cover the domains, certificates, servers, and tooling that adversaries stage in advance of an attack.
How is an IoPA different from an IOC?
An IOC documents malicious activity that already occurred. An IoPA identifies validated evidence of infrastructure preparation before execution. They describe different phases and support different actions.
What is MTTP?
MTTP means Mean Time to Preempt. It measures the interval between observing adversary preparation and taking defensive action against it. The clock starts when the pre-attack signal appears, not when an incident is confirmed.
Why is dark web monitoring no longer enough?
Data that surfaces on the dark web has already been stolen, sold, or abandoned by the time it reaches your team. The forums that once made it viable have largely been seized or shut down, pushing sophisticated actors into encrypted channels that no monitoring tool can reach.
Does pre-attack disruption require replacing existing tools?
No. Your feeds, SIEM, enforcement controls, and team workflows stay in place. Pre-Attack Prevention extends them into the setup phase with a new class of signal, IoPAs, and a new set of decisions about when and how to act.









