Threat Intelligence

    The role of threat intelligence for digital infrastructure in 2026

    Most organisations now have access to more threat data than they can process. The differentiator in 2026 is not volume but whether a signal arrives early enough, with enough context, to change what happens next.

    Sheridan, Wyoming6 min readPublished September 18, 2026

    The problem is no longer data scarcity

    Public and commercial sources cover malware URLs, phishing pages, malicious IP addresses, certificate issuance and domain registrations. A mid-sized company can subscribe to more indicators than its tooling can meaningfully apply.

    The failure mode has shifted accordingly. Teams rarely miss an attack because the indicator did not exist somewhere. They miss it because it arrived without context, arrived after the campaign ended, or arrived in a system that nobody consults during an incident.

    Freshness: the half-life of an indicator

    Phishing infrastructure is often disposable. A domain can be registered, provisioned with a certificate, used for a campaign and abandoned within days. An indicator that describes that domain a week later documents history rather than risk.

    This is why registration-time and certificate-time signals matter more than they once did. Certificate transparency logs are public, continuous and usually reflect a domain before any mail is sent from it. Treating that as an early warning source, rather than as an audit trail, changes the window in which defence is possible.

    Context: who controls the infrastructure

    An indicator without ownership context cannot be acted on. For any malicious domain, the operationally relevant facts are:

    • The hosting provider, which can remove content.
    • The registrar, which can suspend the domain.
    • The autonomous system announcing the address, which can null-route the network.
    • The jurisdiction, which determines which CERT or authority is relevant.

    A feed that delivers a URL is data. A record that delivers a URL together with the party able to remove it is the beginning of a response.

    Measurement: provider behaviour is itself intelligence

    Response behaviour varies enormously between providers. Some abuse desks act within hours; others do not answer at all. Recording, per provider, how often a report produces a removal and how long it takes turns anecdote into a planning input: it tells a defender when to wait and when to escalate immediately.

    Blackwall tracks this from its own case history rather than estimating it, and shows the result publicly rather than as a marketing claim. Where there is not yet enough data for a meaningful figure, the platform states that instead of publishing a number.

    What this means for infrastructure operators

    For hosting providers, registrars and network operators, abuse handling is increasingly a visible quality attribute rather than an internal cost centre. Reporting platforms, researchers and customers all now measure it.

    For companies consuming intelligence, the useful question is narrow: for each signal we ingest, what action does it trigger, who performs it, and how do we know it worked? Signals that cannot answer those three questions are overhead.

    Working on a story or facing an active threat?

    Press enquiries and case questions go to contact@blackwall.report. Active phishing, malware or fraud infrastructure can be submitted directly.

    See Blackwall results

    Cookie Notice

    We use cookies to ensure the functionality of our website. Necessary cookies are required for operation. Optional cookies help us improve our services. For more information, see our Privacy Policy.