The Relevance Doctrine, Part 1: The Threat Intelligence Noise Problem and Why Relevancy Is the Way Out

Chief Product Officer, Cyware

This is the first in a five-part blog series, The Relevance Doctrine. Across five installments, I will make the case that relevancy, not volume, is what determines whether a threat intelligence program actually works, and lay out what it takes to make relevancy computable, operational, and driven into action at enterprise scale. Here is where that case starts.
Let me start with a thought experiment. Two enterprises, Customer A and Customer B. Both well-run, both with capable teams. Facing a tougher threat landscape this year, both do the sensible-looking thing: they add more feeds and more detection to keep up. Twelve months on, both are measurably worse off. More data, more alerts, more CVEs to chase, and no more clarity on what actually matters to them. That, in one picture, is the state of our industry. We have solved for volume and left relevancy unsolved.
What follows is the landscape that got us here: three shifts that turned an intelligence advantage into an intelligence overload.
The attacker changed pace
AI has collapsed the skill barrier to offense and compressed the timelines that used to work in the defender's favor. Reconnaissance, targeting, lure generation and payload adaptation now happen in minutes, at scale, with little human effort. This is no longer a projection. In Darktrace's research, 78% of CISOs say AI-powered attacks are already affecting their organizations, and Acronis, reviewing 2025, concluded that attackers are using AI to act faster and at greater scale. When offense personalizes and automates, defense cannot stay generic and manual.
The attack surface now includes your suppliers
For a globally connected enterprise, the perimeter effectively ends at the edge of every vendor, integration and dependency you have ever trusted. That is exactly where adversaries have moved. The Verizon 2025 DBIR found that third-party involvement in breaches doubled from 15% to 30% in a single year, the largest single-year jump it has recorded. Your suppliers are, in practice, an extension of your attack surface.
The mechanics are unforgiving because they weaponize trust. When the Drift OAuth tokens were stolen in 2025, the attacker inherited legitimate, pre-authorized access into the Salesforce environments of 700+ organizations, with no perimeter breached. Open source tells the same story at developer scale, with Sonatype counting 450,000+ new malicious packages in 2025, up roughly 75% year over year.
The intelligence itself imploded into noise
Here is the part that keeps me up at night, because it is self-inflicted. The systems meant to help us keep pace have become a second source of overload. In 2025 defenders faced 46,000+ published CVEs, roughly 127 a day. The volume finally broke the reference system we all leaned on: NIST has moved the NVD to a triage model, citing a 263% rise in submissions between 2020 and 2025, and enriching only a fraction going forward. The SOC feels the same flood from the other side. Analysts now field roughly 3,000 alerts a day, of which about 63% go unaddressed. Adversaries understand this and use alert-flooding as a recognized evasion technique. Noise is not a nuisance. It is cover.
30% of breaches now involve a third party, double the prior year- Verizon DBIR 2025
46K+ CVEs published in 2025, roughly 127 per day- Zafran / NVD
63% of daily SOC alerts go uninvestigated-Vectra AI
Two problems, and we only talk about one
When I look at where CTI programs actually struggle, I see two problems, and we tend to talk only about the first.
The observed problem. Analysts cannot triage the volume. This is visible, everyone feels it, and it is where most tooling is aimed.
The unobserved problem, and likely the bigger one. The total cost of ownership of making all this data relevant and contextual, meaning the resources, integration effort and complexity required to operationalize it, is what quietly breaks programs. It rarely shows up on a dashboard, but it is where the money and the fatigue go.
This pattern is not new. Across previous generations of security tooling, the technology was rarely the real constraint. Operationalization was. Threat intelligence platform and threat intelligence management adoption hits the same wall whenever the underlying data, relevancy and context are hard to manage, integrate and leverage.
My view: relevancy, not volume
The way out is not more intelligence. It is relevant, contextual and operationalized intelligence, personalized to each enterprise and each attack surface, then driven all the way to action. This is the conviction we are building the Cyware Intelligence Suite around, powered by Cyware AI. Our threat intelligence platform, Cyware Intel Exchange, already ingests any format, then deduplicates, normalizes, enriches, correlates, scores and maps to MITRE ATT&CK, with AI agents doing the heavy lifting so analysts do the analysis. The frontier we are driving toward is personalization: intelligence computed against your specific environment, and carried through to the action it should trigger.
This series gets specific from here. Part 2 covers how we compute relevancy from context and correlation. Part 3 covers how Priority Intelligence Requirements turn that computation into an operating discipline. Part 4 covers how it becomes proactive defense rather than another report nobody acts on. Part 5 will cover how Cyware can tie this all together for enterprises of all sizes.
See it in Action
See how the Cyware Intelligence Suite turns high-volume threat data into prioritized, operational intelligence, with AI agents built in. Book a demo or Explore the Cyware Intelligence Suite
About the Author

Sachin Jade
Chief Product Officer, Cyware