Only 1 in 4 CISOs use cyber threat intelligence to drive decisions – despite vast majority saying it’s important, new SANS survey finds
2026 SANS CTI Survey reveals structural barriers and widening gap between intelligence production and executive action
The 2026 SANS Cyber Threat Intelligence (CTI) Survey reveals a stark contrast: 91% of CISOs say CTI is important, yet only 26% report that it meaningfully influences strategy, budgets, or action.
For the first time, the annual survey includes two separate data sets – one from CTI analysts and the other from CISOs, giving a direct comparison between the analysts who produce intelligence and the executives who rely on it. The findings highlight a shared recognition of CTI’s importance but also the structural and operational barriers preventing it from becoming a true decision driver.
Executive priorities and needs
Executives are clear about what they need. Their top priorities for the next 12 months are intelligence on vulnerabilities actively targeted by attackers (79%) and specific adversary TTPs (77%). Business‑focused intelligence ranks lowest at 41%, a gap the report attributes to under‑production, not lack of demand.
Barriers to programme effectiveness
Yet CTI teams are struggling to deliver at the level leaders expect. Most formal programmes still operate with fewer than four full‑time staff, even as CTI use cases expand across security operations, threat hunting, vulnerability management, and executive reporting.
Lack of time and lack of funding are top barriers to effective implementation, each cited by 44% of respondents. The report also reveals that CTI programmes aren’t maturing year over year. 57% of CTI programmes aren’t measuring their own maturity over time, and 49% don’t gather systematic feedback on effectiveness. Without evidence of improvement, teams struggle to demonstrate impact, defend budgets or refine their processes – further preventing programmes from maturing.
CTI adoption outpacing governance
Meanwhile, the operational landscape is shifting. Security operations (71%) has reclaimed the top CTI use case for the first time since 2022, signalling that intelligence is increasingly embedded into daily defensive workflows. AI adoption is also accelerating, with 45% of organisations using AI for summarisation and report writing, while maintaining human‑in‑the‑loop oversight.
However, 55% lack legally reviewed CTI sharing processes, a structural risk as NIS2 and the Cyber Resilience Act introduce new obligations in 2026.
“CTI programmes have spent years proving their value. The 2026 data shows the next challenge is converting that recognition into decisions, budgets, and action,” said Rebekah Brown, Senior Researcher at SANS Institute and co‑author of the report.
Key findings from the 2026 SANS CTI Survey:
- 91% of CISOs value CTI, but only 26% say it drives decisions
- CISOs prioritise:
- Intelligence on actively targeted vulnerabilities (79%)
- Adversary TTPs (77%)
- Most CTI teams have fewer than four FTEs
- Top barriers: 44% cite lack of time and 44% cite lack of funding
- 57% do not track CTI maturity; 49% do not collect systematic feedback
- 45% use AI in CTI workflows, mainly for summarisation and report writing
- Despite new regulations, 55% lack legally reviewed CTI sharing processes
- Security operations (71%) is now the top CTI use case
Read more stories like this on our LinkedIn page.











