How the acceleration of attacks, SME inequality, the human factor and Europe’s cyber strategy are reshaping our understanding of threat
Author’s research article | August 2026
The global Threat Intelligence market was valued at USD 11.4 billion in 2025, while Market Glass, in a report distributed by Research and Markets, projects that it could reach USD 33.2 billion by 2032, representing a compound annual growth rate of 16.5%.[1] Such figures can easily become headlines in their own right: the market is growing, demand is increasing and the industry is expanding. Yet the more serious question is not how much money will be spent on threat intelligence, but why the need for it has become so pronounced — and whether greater investment genuinely means that organisations are becoming more resilient.
Threat Intelligence has traditionally developed around the ability to identify indicators of compromise, track attacker infrastructure and behaviour, link campaigns, and provide context to SOC analysts. Today, its position is changing because the economics of attack itself is changing. Generative and agentic AI do not create cybercrime from nothing, but they are dramatically reducing the cost and time associated with activities that previously required greater expertise, more people and considerably more manual effort. The UK National Cyber Security Centre assesses that AI is already making parts of cyber intrusion more effective and is almost certain to increase the frequency and intensity of cyber threats through to 2027. The NCSC specifically identifies reconnaissance, vulnerability research, exploit development, social engineering, basic malware generation and the processing of exfiltrated data as areas in which threat actors are already using AI.[2]

This is not a hypothetical discussion about what might happen at some point in the future. Verizon’s 2026 Data Breach Investigations Report finds that vulnerability exploitation now constitutes the initial access vector in 31% of breaches, while ransomware is present in 48% of the breaches analysed. Verizon also identified at least fifteen attack techniques already being enhanced by generative AI, ranging from vulnerability discovery to the generation of malicious code.[3] ENISA’s Threat Landscape 2025 adds another dimension: the popularity of AI is being exploited not only to improve offensive tools, but also as a lure. The report documents fake websites impersonating legitimate AI tools in order to distribute malware, trojanised packages, poisoned models and attacks targeting configuration files used by AI coding assistants.[4] AI is therefore becoming, simultaneously, a tool, a target and a new layer within the supply chain.
From Threat Information to Decision-Making Capability
In such an environment, it is no longer sufficient to ask whether an organisation has a Threat Intelligence feed. What matters increasingly is the time required to turn a signal into understanding, understanding into an assessment of business risk, and that assessment into a change in defence. If intelligence on a new technique arrives on Monday, but assessing dependencies, approving a change, procuring a solution, testing it and deploying it takes months, the organisation may formally possess intelligence while remaining operationally exposed. This is why Threat Intelligence can no longer function primarily as an isolated SOC discipline. Increasingly, it must become part of cyber strategy, architecture, supplier management, business continuity planning and executive decision-making.
This change is particularly evident in the case of known vulnerabilities. The NCSC warns that the interval between public disclosure of a vulnerability and its exploitation has already shortened to days, and that AI is almost certain to reduce that window still further.[2] This changes the practical value of almost every traditional process. A monthly patching cycle may be well defined and fully auditable, yet still prove too slow relative to the attacker’s timeline. An annual supplier assessment may be formally sound, but reveal little about what happened within that supplier’s environment last week. Modern Threat Intelligence must therefore assess not only the threat itself, but also the speed at which change translates into operational risk.
SMEs: The Same Digital Economy, Unequal Defensive Capacity
The greatest strategic asymmetry emerges in the small and medium-sized enterprise sector. SMEs today can use the same cloud platforms, business applications, identity systems, remote-access technologies and digital supply chains as large corporations, but they do not have comparable numbers of cyber specialists, their own 24/7 SOCs, or equivalent budgets for threat hunting, red teaming and continuous recovery testing. The World Economic Forum’s Global Cybersecurity Outlook 2026 finds that 46% of small organisations report a lack of cyber knowledge and expertise, compared with 29% of large organisations. More than half of all respondents — 54% — identify insufficient knowledge and skills as a barrier to implementing AI solutions in cyber security.[5]
This means that digital transformation has not produced an even distribution of resilience. On the contrary, it can create an environment in which the benefits of digitalisation are widely accessible while the capacity to manage the associated risks remains concentrated. A small company can adopt a new AI service and connect it to business data within hours; appropriate access controls, supplier assessments, identity management, monitoring, incident response and recovery capabilities cannot be built at the same speed. The enthusiasm an individual may experience when AI accelerates writing, analysis or prototyping therefore cannot simply be extrapolated to the economy as a whole. Within an organisation, every new capability simultaneously becomes a new dependency, a new point of access and a new locus of accountability.
European institutions are increasingly treating this inequality as a question of capacity rather than regulation alone. The European Cybersecurity Competence Centre, ECCC, together with the network of 27 National Coordination Centres, has an explicit mandate to strengthen Europe’s cyber capabilities and competitiveness and to support the participation of SMEs and start-ups in cross-border projects and funding programmes.[6] This is an important signal: the cyber resilience of small and medium-sized systems can no longer be regarded solely as the private problem of each individual company, because a weaker link within an interconnected ecosystem can readily become the route into a larger organisation or critical infrastructure.

AI Enthusiasm and the Human Factor: Productivity Is Not the Same as Capability
The second layer of the problem concerns the human factor, but not in the simplistic sense that “the human is the weakest link”. In the age of LLMs, the more important question is what happens to human competence when an increasing proportion of cognitive work is delegated to a system that is faster, always available and sufficiently capable for users to lose the motivation to verify their own understanding. The OECD Digital Education Outlook 2026 makes a crucial distinction here: generative AI can improve the quality of a completed task, but this does not automatically translate into better learning outcomes. The OECD reviews research in which the advantage enjoyed by GenAI users disappears — and in some cases reverses — when the tool is removed, and warns of the risks associated with cognitive offloading and metacognitive passivity.[7]
For the cyber community, this has direct consequences. If an analyst receives faster triage, log summaries, response recommendations or generated code, productivity may increase. However, if at the same time that analyst’s ability to independently identify a faulty correlation, a hallucinated source, poor code or a risky recommendation deteriorates, the organisation has not gained resilience; it has acquired a new and less visible dependency. Human-in-the-loop is not in itself a guarantee of control if the human within that loop has lost sufficient depth of expertise to challenge the system. In the same analysis, the WEF reports that 41% of organisations view the requirement for human oversight as a challenge or constraint when implementing AI in cybersecurity.[5]
This also changes the responsibility of education. It is neither rational to try to return generations growing up with AI to a world without AI, nor safe to reduce education to training in how to obtain results more quickly. What is required is the ability to understand a problem before delegating it, verify the output, recognise an unknown assumption, evaluate a source and accept responsibility for the decision. In cyber security, such competence is not an additional advantage; it is the final line of defence when an automated system fails or when an adversary deliberately manipulates it towards an incorrect conclusion.
Cyber Resilience: From Preventing Incidents to Ensuring Survival
This brings us to the point at which a conventional cyber security strategy becomes insufficient if it is reduced to prevention alone. In SP 800-160 Vol. 2, NIST defines cyber resiliency in terms of the ability of systems to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks and compromises.[8] The significance of this definition lies precisely in the fact that it does not assume that every attack will be detected in time or that every control will perform as intended. It begins from the reality that a degree of risk is unavoidable and that the quality of an organisation is also demonstrated by what happens after the first line of defence has been breached.

Cyber resilience is therefore not synonymous with cyber security. An organisation may have strong protective controls but insufficiently tested recovery capabilities. It may have backups yet remain dependent on a single identity provider. It may possess advanced detection capabilities but have no operational model for continuing to function when a critical SaaS service becomes unavailable. Genuine resilience encompasses incident tolerance, continuity of critical functions, recovery, post-incident adaptation and the management of technological and supplier dependencies. Within such a model, Threat Intelligence acquires a different purpose: it does not merely tell us who is attacking us, but identifies which dependency, process or underlying assumption must change before a threat becomes a business disruption.
Europe’s Response: From Regulation to Collective Resilience
During 2026, the European Union began to connect these issues far more explicitly. The EU Action Plan on Cybersecurity and Artificial Intelligence, published on 7 July 2026, starts from the dual-use nature of AI: the same technology can help identify vulnerabilities and protect critical infrastructure while also enabling malicious actors to automate attacks, discover weaknesses and operate at greater speed and scale. The Plan connects the AI Act, the Cyber Resilience Act, NIS2, DORA and the Cyber Solidarity Act, and provides for coordination between Member States, industry, the research community and EU institutions.[9] This represents an important shift away from viewing cyber security primarily as a technical problem affecting individual systems and towards understanding it as a question of European strategic capability.

The ECCC and the network of National Coordination Centres provide an industrial and developmental dimension to this strategy, while the Cyber Solidarity Act and European response-coordination mechanisms seek to strengthen collective preparedness and recovery capabilities. The value of this approach will not be measured solely by the number of regulations adopted or projects funded, but by the time required to translate new threat intelligence into changes in practice across states, companies and supply chains. If offensive capability proliferates within weeks while institutional implementation takes years, then the European system itself has an adaptation gap.

What Does the Growth of the Threat Intelligence Market Really Tell Us?
The forecast of USD 33.2 billion by 2032 is not merely a market story. It is an indicator that the value of timely context is increasing in an environment in which the volume of signals is greater, automation is more powerful and the time available for response is shorter. Yet simply purchasing intelligence does not solve the problem. Without integration with business priorities, architecture, incident response, dependency management and recovery planning, it remains another layer of information that may increase noise rather than resilience.
The most important strategic shift, therefore, is not from less Threat Intelligence to more Threat Intelligence, but from intelligence that describes the threat to intelligence that changes the decision. Organisations will need to understand how quickly they detect change, how quickly they assess its relevance, how quickly they can modify a control, and how effectively they can continue operating when that control fails. For the SME sector, this means access to defensive capabilities that have historically been economically out of reach; for education, it means preserving the capacity for human verification; for European policy, it means connecting technological sovereignty, cyber capability and collective resilience; and for executive management, it means accepting that cyber risk is no longer a technical adjunct to business strategy.
In the age of AI, the question is no longer whether we have enough information about threats. Information will only become more abundant. The real question is whether an organisation is fast enough, competent enough and resilient enough to turn information into change before an adversary derives a new advantage from the very same technological revolution. It is at precisely this boundary that Threat Intelligence ceases to be merely a market category and becomes one of the critical instruments of cyber resilience.
References and Sources
[1] Research and Markets / Market Glass, Inc. Threat Intelligence – Global Strategic Business Report. 2026. Source: https://www.researchandmarkets.com/reports/4806357/threat-intelligence-global-strategic-business Market estimate: USD 11.4 billion in 2025; USD 33.2 billion by 2032; CAGR 16.5%.
[2] UK National Cyber Security Centre (NCSC). Impact of AI on cyber threat from now to 2027. 2025. Source: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027 Assessment of AI’s impact on reconnaissance, vulnerabilities, exploit development, social engineering and the speed of exploitation.
[3] Verizon. 2026 Data Breach Investigations Report. 2026. Source: https://www.verizon.com/business/resources/reports/dbir/ 31% of breaches begin with the exploitation of software vulnerabilities; ransomware is present in 48%; 15 attack techniques are being enhanced by GenAI.
[4] European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025. 2025. Source: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 Analysis of 4,875 incidents; AI-themed lures, trojanised packages, AI supply-chain risks and the misuse of LLMs.
[5] World Economic Forum, in collaboration with Accenture. Global Cybersecurity Outlook 2026. 2026. Source: https://www.weforum.org/publications/global-cybersecurity-outlook-2026/ Cyber skills gaps, AI adoption and disparities in cyber resilience between small and large organisations.
[6] ECCC. European Cybersecurity Competence Centre and Network / National Coordination Centres. 2026. Source: https://cybersecurity-centre.europa.eu/nccs-0_en The mandate of the ECCC/NCC network includes strengthening capabilities, industry, research, and the participation of SMEs and start-ups.
[7] OECD. OECD Digital Education Outlook 2026: Exploring Effective Uses of Generative AI in Education. 2026. Source: https://doi.org/10.1787/062a7394-en Review of research on GenAI, performance, actual learning outcomes and the risks of cognitive offloading.
[8] National Institute of Standards and Technology (NIST). SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems. 2021. Source: https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final Cyber resiliency: anticipate, withstand, recover, adapt.
[9] European Commission. EU Action Plan on Cybersecurity and Artificial Intelligence. 2026. Source: https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence Published on 7 July 2026; connects AI and cyber security with the EU’s existing regulatory and strategic framework.
[10] ENISA. NIS Investments 2025. 2025. Source: https://www.enisa.europa.eu/publications/nis-investments-2025 Survey of 1,080 professionals across the EU covering investment, resources, skills, patching and supply-chain practices.
Methodological note: Statistical claims made throughout this article are based on the sources listed above. The interpretations concerning the strategic role of Threat Intelligence and the relationship between cyber security and cyber resilience represent the author’s analysis derived from those findings.
Originally published by Advanced Cyber Security on 8 September 2026. Read this article on LinkedIn ↗.




