Threat Intelligence Market Opening Overview
Why the Threat Intelligence Market Is Sustaining Structural Expansion?
The Threat Intelligence Market reached USD 9.86 Billion in 2025 and is forecast to advance to USD 30.07 Billion by 2035 at an 11.8% CAGR. This growth trajectory is compliance-anchored, adversary-driven, and structurally insulated from discretionary IT spending cycles in a way that few enterprise software markets are. Three structural forces are simultaneously expanding demand.
First, mandatory disclosure and sharing obligations: the U.S. SEC's cybersecurity disclosure rules (effective December 2023) require public companies to disclose material cyber incidents within four business days — creating an immediate commercial driver for pre-incident intelligence, because organizations that can identify an attack before it becomes material avoid the financial and reputational consequence of an SEC 8-K filing.
North America commands 44.2% of global Threat Intelligence Market revenue, driven by Fortune 500 SOC modernization, U.S. federal agency CISA mandates, and the concentration of cybersecurity vendor R&D investment on the East and West Coasts. Europe holds a 26.7% share, where DORA, NIS2, and GDPR collectively create a compliance-mandated floor for threat intelligence investment that cannot be deferred during budget cycles. Asia-Pacific is the fastest-growing region at a 14.3% CAGR through 2035
What Structurally Separates Market Leaders from the Field?
The competitive structure of the Threat Intelligence Market has three moats that are incredibly difficult to build organically. First, the volume of first-party intelligence data. The quality of a threat intelligence product is bounded by the uniqueness and recency of the telemetry it ingests. CrowdStrike tracks 200+ named adversaries from Falcon endpoint telemetry on 25,000+ enterprise networks. Palo Alto Networks Unit 42 investigates 1,000+ incidents per year. Google Threat Intelligence combines Mandiant IR, VirusTotal's 800K+ daily malware submissions, and Google's global internet scan data.
Top 10 Global Threat Intelligence Companies — MRFR Rankings (2026)
Revenue figures validated from official SEC filings, company investor relations disclosures, or published acquisition announcements. Threat intelligence is frequently embedded within larger platform revenues not separately disclosed. All such cases are explicitly noted.
|
# |
Company |
HQ |
Revenue (Validated) |
Geo. Presence |
Key Specialization |
Notable Highlight |
|
1 |
Palo Alto Networks |
Santa Clara, CA, USA (Nasdaq: PANW) |
USD 9.221B (FY2025, ended Jul 31, 2025) — Palo Alto Networks 8-K SEC Filing, Aug 18, 2025 (+15% YoY). NGS ARR: USD 5.6B (+32% YoY). RPO: USD 15.8B |
150+ countries |
Unit 42 Threat Intelligence, Cortex XSIAM AI-native SOC, Precision AI, AutoFocus TIM, XSOAR SOAR, Prisma SASE with threat intel overlay, Cortex XDR with threat-correlated detection |
Surpassed USD 10B annualized revenue run-rate by Q4 FY2025; Unit 42 incident response investigated 1,000+ incidents in 2024 generating proprietary first-party intelligence; Precision AI applied across all platforms embeds real-time threat intelligence into automated prevention — not just detection |
|
2 |
CrowdStrike Holdings |
Austin, TX, USA (Nasdaq: CRWD) |
USD 3.95B (FY2025, ended Jan 31, 2025) — CrowdStrike 8-K SEC Filing, Mar 4, 2025 (+29% YoY). Ending ARR: USD 4.24B (+23% YoY). Subscription revenue: USD 3.76B |
170+ countries |
CrowdStrike Adversary Intelligence (ATI), Falcon Adversary OverWatch managed threat hunting, Falcon Intelligence Recon dark web monitoring, Counter Adversary Operations (CAO), Falcon X Premium TIP |
Adversary Intelligence covers 200+ named tracked adversaries — the largest named threat actor library in the industry; Counter Adversary Operations unit disrupts threat actor infrastructure proactively; 97% gross retention post-July 19, 2024 Falcon sensor incident demonstrates intelligence platform stickiness across enterprise customers |
|
3 |
IBM Corporation (IBM Security / QRadar) |
Armonk, NY, USA (NYSE: IBM) |
IBM group FY2024: USD 62.8B — IBM 8-K SEC Filing, Jan 29, 2025 (+2% YoY). Software revenue USD 27.1B (+8.3%); Security sub-segment within Software not separately disclosed; IBM Security estimated USD 2B+ revenue (analyst est.) |
175+ countries |
IBM X-Force Threat Intelligence (X-Force Exchange), QRadar SIEM/SOAR with embedded threat intelligence, IBM Security Threat Intelligence Services, X-Force Incident Response, X-Force Red adversary simulation |
X-Force Threat Intelligence Index 2025 documents 70%+ of attacks exploiting valid credentials — proprietary incident response data from 1,500+ engagements annually; QRadar SIEM acquired by Palo Alto Networks (announced May 2024) adds Cortex distribution; IBM retains X-Force IR and intelligence services as standalone offerings |
|
4 |
Fortinet Inc. |
Sunnyvale, CA, USA (Nasdaq: FTNT) |
USD 5.96B (FY2024, ended Dec 31, 2024) — Fortinet 8-K SEC Filing, Feb 6, 2025 (+12% YoY). Service revenue USD 4.05B (+20%). Record FCF USD 1.9B. Unified SASE ARR +28% |
160+ countries |
FortiGuard Threat Intelligence Services (AI-powered, 100+ researchers globally), FortiAnalyzer SIEM, FortiSOAR orchestration, FortiDeceptor deception platform, OT/ICS threat intelligence (FortiGuard ICS/SCADA) |
FortiGuard Labs processes 100+ billion security events daily from 7M+ deployed sensors — the largest proprietary OT/IT threat telemetry footprint in the market; FortiGuard ICS/SCADA intelligence is the market reference for operational technology threat intelligence, serving energy, utilities, and manufacturing verticals with MITRE ATT&CK for ICS-aligned intelligence feeds |
|
5 |
Check Point Software Technologies |
Tel Aviv, Israel (Nasdaq: CHKP) |
USD 2.57B (FY2024, ended Dec 31, 2024) — Check Point Form 6-K SEC Filing, Jan 30, 2025 (+6% YoY). Security Subscriptions: USD 1.104B (+13% YoY). Calculated Billings: USD 2.66B (+9%) |
190+ countries |
Check Point ThreatCloud AI (50+ AI engines, 3B+ threat indicators), Check Point Threat Intelligence Feeds, Infinity AI Copilot, Cyberint External Risk Management (acq. Sep 2024), Horizon NDR with threat correlation |
ThreatCloud AI blocks 3B+ attacks/day using 50+ AI engines with real-time global sensor correlation; Cyberint acquisition (Sep 2024, USD 186M) adds external attack surface intelligence and dark web monitoring — the most commercially significant threat intelligence capability expansion in Check Point's history; 100,000+ protected organizations globally |
|
6 |
Recorded Future (Mastercard) |
Somerville, MA, USA (private, Mastercard subsidiary since Nov 2024) |
~USD 300M ARR (2024 est.) — private company; acquired by Mastercard for USD 2.65B (announced Jul 2024, closed Nov 2024). No standalone post-acquisition public financials |
75+ countries |
Intelligence Cloud platform (OSINT + dark web + technical TI + geopolitical), Insikt Group analyst research, Threat Actor Intelligence, brand protection, third-party risk intelligence, National Threat Intelligence (government) |
USD 2.65B Mastercard acquisition (Nov 2024) is the largest M&A transaction in Threat Intelligence Market history — validates the market's maturation from niche security service to enterprise risk intelligence platform. Mastercard integrates Recorded Future's threat intelligence into financial fraud prevention, payment network security, and bank client risk advisory services — creating a commercial TI distribution channel across 10,000+ financial institution clients |
|
7 |
Mandiant (Google Cloud) |
Milpitas, CA, USA (parent: Google LLC, Alphabet Inc., Nasdaq: GOOGL) |
Mandiant revenue embedded within Google Cloud (USD 43.2B FY2024 total Google Cloud revenue — Alphabet 8-K, Jan 2025); Mandiant Consulting + TI not separately disclosed. Mandiant last reported standalone revenue: USD 599M (FY2022, pre-acquisition) |
60+ countries (incident response + intelligence) |
Mandiant Threat Intelligence (MTI), Mandiant Advantage platform, Mandiant Security Validation, Managed Defense MDR, Google Threat Intelligence (GTI — combining Mandiant + VirusTotal + Google visibility), Gemini for Security |
Google Threat Intelligence (GTI) combines Mandiant's 1,800+ tracked threat groups, VirusTotal's 800K+ malware files/day, and Google's global internet visibility — creating the broadest threat telemetry combination in the market. GTI, launched February 2025, integrates GenAI Gemini 1.5 for 1M+ token threat report context windows — a breakthrough in threat intelligence analyst augmentation |
|
8 |
Anomali Inc. |
Redwood City, CA, USA (private) |
Private company — no public financials; revenue estimated USD 80–120M (2024, analyst estimates); Series E investor base includes GV (Google Ventures), IVP, Paladin Capital |
30+ countries |
Anomali ThreatStream TIP, Anomali Intelligence Platform, Anomali Copilot (GenAI threat analyst), STIX/TAXII feed integration hub, threat actor profiling, ISACs integration, Match SIEM-embedded intelligence |
Anomali Copilot — launched 2024 — is the first commercially deployed GenAI threat intelligence analyst copilot that writes threat actor profiles, generates detection rules, and correlates indicators with enterprise SIEM data in natural language. Anomali Match embeds threat intelligence directly inside SIEM without requiring TIP middleware — the architectural pattern most aligned with SOC consolidation trends |
|
9 |
Kaspersky Lab |
Moscow, Russia (private; U.S. operations terminated Sep 28, 2024) |
Private company — no public financials. Revenue estimated ~USD 700M (2023); U.S. market revenue lost after Commerce Department ban effective Sep 29, 2024 |
Remaining: non-U.S. 150+ countries. U.S. operations terminated by Commerce Dept. order (Sep 29, 2024) |
Kaspersky Threat Intelligence Portal (KTIP), Kaspersky APT Intelligence Reporting, GReAT (Global Research & Analysis Team) nation-state threat research, Threat Data Feeds, Digital Footprint Intelligence |
U.S. Department of Commerce ban effective Sep 29, 2024, terminated Kaspersky's U.S. business entirely — the first total national-security ban of a cybersecurity product in U.S. history. GReAT remains one of the world's most technically prolific APT research teams; Kaspersky APT intelligence reports continue serving non-U.S. government, enterprise, and telecom customers globally despite U.S. market exit |
|
10 |
Trend Micro Incorporated |
Tokyo, Japan (TSE: 4704) |
JPY 233.3B (~USD 1.56B) (FY2024, ended Dec 31, 2024) — Trend Micro official FY2024 results; platform revenue growth +20% |
170+ countries |
Trend Micro Threat Intelligence (Smart Protection Network — 17B+ daily queries), Vision One XDR with TI overlay, Zero Day Initiative (ZDI) vulnerability research, Trend Research APT reports, Trend Cloud Security posture intelligence |
Zero Day Initiative (ZDI) disclosed 1,000+ vulnerabilities in 2024 — the most prolific independent vulnerability disclosure program in the industry, giving Trend Micro an average 80-day intelligence lead over public CVE disclosure. Vision One platform consolidation strategy — integrating EDR, NDR, email, cloud, and OT security into a single intelligence-correlated console — grew platform ARR 20% in FY2024 |
* Group revenues cited where threat intelligence is embedded within larger platform. Private company revenues are analyst estimates where no official financials are available. Kaspersky U.S. operations terminated Sep 29, 2024 per Commerce Dept. ban.
Detailed Company Profiles
1. Palo Alto Networks | Nasdaq: PANW | Santa Clara, CA, USA
Palo Alto Networks’ position in the Threat Intelligence Market is propelled by the most aggressive platform consolidation strategy in cybersecurity. Its ‘platformization’ thesis — moving enterprises from multi-vendor security point products to a single Palo Alto stack — puts threat intelligence as the connective tissue that justifies every incremental platform adoption. Palo Alto’s financial trajectory reinforces that the platformization bet is commercially validated with FY2025 total revenue of USD 9.221 Billion (ended July 31, 2025, +15% YoY) and Next-Generation Security ARR of USD 5.6 Billion (+32% YoY). Unit 42: Palo Alto’s intelligence and incident response practice
2. CrowdStrike Holdings | Nasdaq: CRWD | Austin, TX, USA
CrowdStrike’s competitive position in the Threat Intelligence Market is the most technically credentialed of any pure-play cybersecurity firm: its Counter Adversary Operations (CAO) unit — the operational successor to the Intelligence team that attributed the 2016 DNC hack to Russian APT28 — proactively disrupts threat actor infrastructure rather than just tracking and reporting on it
3. IBM Corporation (IBM Security / X-Force) | NYSE: IBM | Armonk, NY, USA
IBM X-Force Threat Intelligence holds a structurally distinct position in the Threat Intelligence Market: it is simultaneously a commercial threat intelligence product, a research publication brand, and an incident response service — three revenue streams that each strengthen the others in a data virtuous cycle. X-Force Incident Response investigators handle 1,500+ incidents annually across 130+ countries, generating first-party intelligence on adversary TTPs that no subscription-based feed or OSINT aggregation can replicate. IBM FY2024 total revenue of USD 62.8 Billion (Software segment USD 27.1 Billion, +8.3%) reflects the scale of IBM's enterprise client relationships through which X-Force intelligence is distributed
4. Fortinet Inc. | Nasdaq: FTNT | Sunnyvale, CA, USA
Fortinet's competitive position in the Threat Intelligence Market is anchored in FortiGuard Labs — a 100+ analyst threat intelligence operation that processes over 100 Billion security events daily from 7 million+ deployed FortiGate firewalls, FortiClient endpoints, and FortiMail email gateways globally. This sensor footprint — the largest proprietary OT/IT dual-technology threat telemetry network in the industry
5. Check Point Software Technologies | Nasdaq: CHKP | Tel Aviv, Israel
Check Point's ThreatCloud AI is the most vertically integrated threat intelligence architecture in the Threat Intelligence Market: it applies 50+ AI engines in parallel to 3 Billion daily threat indicators sourced from Check Point's 100,000+ protected organization network, shared intelligence feeds, and now — following the September 2024 Cyberint acquisition — external attack surface intelligence and criminal forum monitoring. Check Point FY2024 total revenue of USD 2.57 Billion (+6% YoY), with Security Subscriptions growing 13% to USD 1.104 Billion, demonstrates that ThreatCloud AI's intelligence-first positioning is generating subscription revenue growth faster than overall company revenue growth
6. Recorded Future (Mastercard) | Private (Mastercard subsidiary) | Somerville, MA, USA
Recorded Future's November 2024 acquisition by Mastercard for USD 2.65 Billion — the largest M&A transaction in Threat Intelligence Market history — is simultaneously a validation of the market's maturation and a transformation of Recorded Future's commercial model. Pre-acquisition, Recorded Future was the largest pure-play threat intelligence company globally, with approximately USD 300 Million in ARR from enterprise, government, and financial sector clients using its Intelligence Cloud platform for operational security intelligence, brand protection, third-party risk monitoring, and geopolitical risk assessment. Post-acquisition, Recorded Future becomes the intelligence engine for Mastercard's financial services risk advisory business
7. Mandiant (Google Cloud) | NYSE: GOOGL | Milpitas, CA, USA
Google's integration of Mandiant into Google Cloud has produced the most comprehensive threat intelligence data combination in the Threat Intelligence Market: Google Threat Intelligence (GTI), launched in February 2025, merges Mandiant's 1,800+ tracked threat groups with proprietary first-party IR intelligence, VirusTotal's crowdsourced malware database of 800K+ daily submissions, and Google's hyperscale internet infrastructure visibility spanning 2 Billion+ crawled URLs and global DNS resolution patterns. The application of Gemini 1.5's 1 Million-token context window to threat intelligence analysis
8. Anomali Inc. | Private | Redwood City, CA, USA
Anomali's competitive position in the Threat Intelligence Market is built on the most pragmatic commercial model in the sector: rather than competing for threat intelligence data quality against CrowdStrike's endpoint telemetry or Mandiant's IR depth, Anomali built a threat intelligence platform that aggregates intelligence from 200+ sources — ISACs, commercial feeds, government sharing programs, OSINT — and embeds the correlated output directly inside enterprise SIEM platforms without requiring a separate TIP appliance purchase. This architecture —
9. Kaspersky Lab | Private | Moscow, Russia (U.S. operations terminated)
Kaspersky Lab's position in the Threat Intelligence Market underwent the most dramatic commercially consequential regulatory action in the industry's history on September 29, 2024, when the U.S. Department of Commerce's Bureau of Industry and Security prohibited the sale and distribution of Kaspersky products in the United States — the first total national-security ban of a cybersecurity company's products in U.S. history. This ban eliminated Kaspersky's U.S. market revenue entirely, forcing existing U.S. enterprise customers — approximately 300,000
10. Trend Micro Incorporated | TSE: 4704 | Tokyo, Japan
Trend Micro's competitive position in the Threat Intelligence Market is built on two structurally distinct intelligence capabilities that, together, create a threat intelligence moat no single-capability competitor can replicate. First, the Smart Protection Network — a globally distributed threat telemetry infrastructure processing 17 Billion+ daily queries from 250 Million+ sensors across endpoint, network, email, and cloud deployments — provides the breadth of environmental coverage that gives Trend Micro visibility into emerging threat patterns before they reach critical mass in threat actor operations. Second, the Zero Day Initiative (ZDI) — Trend Micro's independent vulnerability disclosure program that disclosed 1,000+ zero-day and n-day vulnerabilities in 2024 — gives
M&A Activity Tracker
Key verified transactions and strategic events reshaping the Threat Intelligence Market competitive landscape (2023–2024):
|
Year |
Acquirer / Partner |
Target / Event |
Deal Value |
Strategic Objective |
|
2024 (Nov, completed) |
Mastercard Incorporated |
Recorded Future |
USD 2.65B |
Mastercard's acquisition of Recorded Future is the largest M&A transaction in the Threat Intelligence Market history and the event that most clearly validates the market's maturation from niche security product to enterprise risk intelligence platform. Mastercard integrates Recorded Future's Intelligence Cloud into its financial network threat intelligence services, enabling proactive identification of payment fraud campaigns, account takeover threats, and nation-state disruption risks against financial infrastructure — distributed across Mastercard's 10,000+ financial institution client base. The acquisition transforms Recorded Future's standalone enterprise TI sales motion into an embedded financial services risk intelligence product with the broadest possible distribution channel in the BFSI vertical. |
|
2024 (Sep) |
Check Point Software Technologies |
Cyberint Ltd. (External Risk Management) |
USD 186M net cash |
Check Point acquired Cyberint — an Israeli external attack surface intelligence and dark web monitoring specialist — to add first-party external threat intelligence to its ThreatCloud AI platform. Cyberint's brand protection, phishing detection, and criminal forum monitoring capabilities extend Check Point's threat intelligence from network-perimeter telemetry to the external threat landscape: threat actor forum conversations, stolen credential markets, and pre-attack reconnaissance activity. The acquisition positions Check Point's Infinity Platform as an external risk management (ERM) platform rather than purely a prevention-focused security product — a strategic evolution that competes directly with Recorded Future, Mandiant, and Digital Shadows for the external threat intelligence budget. |
|
2024 (May, announced) |
Palo Alto Networks |
IBM QRadar SaaS (SIEM business) |
Undisclosed (industry estimates USD 500M–1B in deal structure with reverse commission arrangement) |
Palo Alto Networks acquired IBM's QRadar SaaS SIEM business to accelerate Cortex XSIAM adoption by converting IBM QRadar's 3,000+ enterprise customer base into XSIAM platform migration candidates. For the Threat Intelligence Market, the strategic significance is that SIEM is the primary consumption point for external threat intelligence feeds: every enterprise that migrates from QRadar to XSIAM becomes a Palo Alto unit 42 threat intelligence consumer as part of the Cortex platform bundle. This migration pipeline is the most commercially efficient threat intelligence distribution channel expansion in the market — converting existing SIEM customers rather than winning net-new threat intelligence accounts from scratch. |
|
2024 (Feb, completed) |
Google (Alphabet) |
Google Threat Intelligence (GTI) platform — organic integration, not M&A |
Internal R&D investment (no acquisition cost); launched publicly Feb 2025 |
Google combined Mandiant's threat intelligence (1,800+ tracked threat groups), VirusTotal's malware intelligence (800K+ daily submissions), and Google's global internet infrastructure visibility into a single Google Threat Intelligence (GTI) platform launched in February 2025 with Gemini AI augmentation. The GTI launch is the most consequential organic product investment in the Threat Intelligence Market because it combines three previously distinct intelligence sources — incident-response first-party intelligence (Mandiant), crowdsourced malware intelligence (VirusTotal), and hyperscale internet telemetry (Google) — under a unified AI-native analyst interface. This combination creates a data diversity moat that no single-source threat intelligence vendor can match. |
|
2023 (May, completed) |
Palo Alto Networks |
Talon Cyber Security (enterprise browser security) |
USD 625M |
Palo Alto Networks acquired Talon Cyber Security to embed enterprise browser security — the collection point for user behavior, credential, and application access intelligence — into its Cortex threat intelligence and XSIAM platform. For the Threat Intelligence Market, the browser is the single highest-volume threat telemetry source in the modern enterprise: credential phishing, session hijacking, and drive-by malware all originate at the browser layer. Acquiring Talon gives Palo Alto proprietary first-party browser telemetry that enriches Unit 42 threat intelligence with the endpoint context that network-layer and cloud-layer sensors cannot capture. This intelligence-at-the-browser strategy directly competes with CrowdStrike Falcon's endpoint telemetry advantage. |
Key Trend: The Threat Intelligence Market M&A landscape in 2023–2024 is bifurcating between enterprise risk intelligence platform consolidation (Mastercard/Recorded Future converting TI into financial services risk infrastructure), SIEM-platform pull-through deals (Palo Alto/QRadar converting SIEM customers into TI bundle consumers), and external threat intelligence capability acquisition (Check Point/Cyberint adding attack surface and dark web intelligence to network-perimeter platforms).
The common strategic logic: standalone threat intelligence point products have a bounded commercial ceiling — the largest revenue opportunities lie in embedding threat intelligence natively into security platforms where it is consumed automatically rather than requiring dedicated analyst procurement decisions.
R&D Investment & Innovation Signals
Leading vendors are investing across GenAI-native intelligence analysis, adversary disruption operations, OT/ICS intelligence expansion, autonomous threat hunting, and quantum-safe threat modeling:
• Google Threat Intelligence (GTI) with Gemini 1.5 is the most significant AI innovation in the Threat Intelligence Market for 2025. The application of a 1 Million-token context window to threat intelligence analysis enables security analysts to query the complete contextual history of a complex nation-state campaign — spanning years of indicator data, analyst reports, MITRE ATT&CK mappings, and infrastructure tracking — in a single natural language prompt.
• CrowdStrike Counter Adversary Operations (CAO) — the proactive threat actor infrastructure disruption capability that actively takes down adversary command-and-control servers, poisons adversary reconnaissance data, and alerts law enforcement to active criminal operations — represents the frontier of threat intelligence evolution: moving from observation and reporting to active disruption. No other commercial threat intelligence vendor offers an equivalent proactive disruption capability at CrowdStrike's operational scale. MRFR estimates that CAO's operational disruption activities prevent an estimated USD 2–4 Billion in adversary-enabled enterprise losses annually, a counterfactual value proposition that represents the most defensible pricing premium in the Threat Intelligence Market.
• OT/ICS-specific threat intelligence is the fastest-growing sub-segment within the Threat Intelligence Market, projected to reach USD 2.8 Billion by 2030 from approximately USD 600 Million in 2025. The convergence of IT and OT networks in manufacturing, energy, and utilities — driven by Industry 4.0 digital twin adoption and remote asset monitoring — exposes industrial control systems to threat actors previously confined to IT environments. Fortinet FortiGuard ICS/SCADA, Dragos Platform Threat Intelligence (the OT-native TI leader), Claroty, and Nozomi Networks are the primary commercial platforms in this sub-segment. MRFR projects that NIS2 compliance requirements for critical infrastructure operators across 18 EU sectors will add USD 800 Million in OT threat intelligence procurement between 2025 and 2027.
• Managed threat intelligence services for SMEs are the highest-growth commercial model in the Threat Intelligence Market, driven by cyber insurance underwriters requiring documented threat intelligence programs as a condition of coverage at premium rates below USD 5 Million per year.
• Autonomous threat hunting — AI systems that proactively search enterprise environments for adversary presence without analyst-initiated queries — is the R&D frontier that will define the next competitive separation point in the Threat Intelligence Market. CrowdStrike OverWatch processes Falcon endpoint telemetry to autonomously hunt for adversary indicators across all customer environments 24/7/365, generating intelligence on previously unseen TTPs that feeds back into the Adversary Intelligence product.
• Threat intelligence for AI system attacks is an emerging sub-category that will represent USD 1.5 Billion by 2030. As enterprises deploy LLM-powered applications, agentic AI workflows, and AI-integrated security tools, threat actors are developing prompt injection, model poisoning, training data extraction, and adversarial example attacks against AI infrastructure
• Threat intelligence sharing via Information Sharing and Analysis Centers (ISACs) and the CISA Joint Cyber Defense Collaborative (JCDC) is generating a government-accelerated threat intelligence distribution infrastructure that reduces the cost of structured threat intelligence for participating organizations.