My cybersecurity career didn’t start in threat intelligence. It started in malware analysis for a global antivirus company protecting consumer PCs. It taught me to look at security from the attacker’s side. I learned what the bad guys actually did on systems, how they operated, what they were trying to achieve, and how their actions impacted people. Over the next 16 years, across security operations roles at Symantec, DXC, National Australia Bank and Westpac, I was fortunate enough to carry that perspective through different levels of security operations. One problem kept showing up. There is a huge gap between understanding the threat and understanding the controls designed to defend against it. A lot of technologists deploying security products have never actually faced the threat the control is supposed to stop. They know how to deploy the technology, but not always how an adversary would interact with it. You could see it in things like IDS and IPS deployments. Controls would be switched on, configured broadly and left largely untuned because there wasn’t enough understanding of what needed to be detected relative to the attacks and the environment. The reverse happens too. Traditional threat intelligence analysts can understand an adversary incredibly well but may never have had to deploy the controls, write the detections or hunt through an environment to actually defend against them. So what happens when those two worlds don’t meet? The problem gets pushed downstream or put in the ‘too hard’ bucket. The SOC has to tame it. The SIEM engineer inherits enormous amounts of signal, detection engineers don’t understand the threat context, and eventually a Level 1 SOC analyst is sitting in front of an alert trying to understand why it exists, what it means and whether it matters to their environment. And then we wonder why we have alert fatigue. Now we’re trying to solve that symptom by putting AI SOC agents on top of the alerts. That has always seemed a little backwards to me. Illogical, actually. Because alert fatigue, detection coverage and effective mitigation should ultimately start with a much simpler question: What are the threats we actually need to defend against relative to our organisation and assets? If you understand the threats, your business and assets, you can make much better decisions about what should be detected, what should be hunted and which controls actually matter. If an adversary relevant to your organisation is sending malicious attachments, that should inform your email security capabilities. If organisations similar to yours are being compromised using a particular behaviour, a mature threat program should be asking: Could they do that to us? Would we see it? Could we stop it? How prepared are we? That is what threat intelligence should enable, but doing this properly is hard. It isn’t enough to simply map a report to MITRE ATT&CK and call the adversary understood. The real value is in understanding how the attacker actually performed the technique, whom they targeted, and why. That means continuously understanding and recording the behaviour, victimology and target selection across many reports and analysed sources. Traditionally, a lot of this ends up in spreadsheets and analyst notes. The more intelligence you process, the more behaviour you can understand. The more behaviour you understand, the greater your potential defensive coverage. But that scales with analyst time, skill and the availability of intelligence. There is always more intelligence than people have time to process. That is the problem that eventually led to Elezar. We, as an industry, still haven’t realised what threat intelligence can do to transform how we defend. Too often, threat intelligence is treated as a feed of indicators of compromise (IOCs). That isn’t intelligence. That is data. Intelligence gives you context. It tells you what matters, why it matters and what you should do about it. Used strategically, it should help organisations prioritise investment and resources. Used operationally, it should determine what you hunt for, what you detect, what you validate and what you mitigate. Relevant adversary behaviour should continuously shape your defences. The challenge has always been turning that knowledge into a framework for defensive operations at the scale and speed required to keep up with changing threats. Historically, that translation has depended on people. Elezar exists to change that. We’re building a Threat-led AI SOC that applies threat intelligence to the way organisations hunt, detect, validate and mitigate threats. Because knowing how the adversary operates should change how you defend. From Jorell Magtibay Founder & CEO