I have sat through more security budget reviews than I can count, on both sides of the table. The pattern is almost always the same. Every line has a vendor, a renewal date, a cost, and an owner. Almost no line has a sentence describing what it is supposed to stop.

That absence is small enough to miss and large enough to explain why threat intelligence, which everyone agrees is valuable, changes so little.

The 2026 SANS Cyber Threat Intelligence Survey polled 401 practitioners globally between November 2025 and January 2026. It included a dedicated module for 67 CISOs and CSOs. Ninety-one percent of those executives said they value cyber threat intelligence. Only 26 percent said it actually drives their decisions.

The usual reading of that gap is that the intelligence is not good enough, or not delivered well enough, or not translated into business language. All three are plausible. All three are wrong, or at least secondary. The real reason is structural, and it sits in the budget rather than in the intelligence function.

What a security budget actually is

Strip away the procurement language and a security budget is a portfolio of bets. Every control you fund is a wager that a specific adversary behaviour will be attempted against you, and that this control will interrupt it. You are not buying a product. You are placing money on a prediction about how you will be attacked.

Intelligence is the thing that updates the odds on a bet. That is its entire function. It tells you a behaviour you were not expecting is now common, or a behaviour you funded heavily against has fallen out of use, or an assumption underneath a control quietly stopped being true.

Which leads to the point this whole argument turns on. Intelligence can only change a decision that was written down as a bet. If the bets are not named, there is nothing for the intelligence to update. The report arrives, everyone reads it, everyone agrees it is concerning, and the budget does not move. Not because anyone is negligent, but because there is no line item that the report contradicts.

A report with nowhere to land

Consider a mid-market manufacturer with a competent security team and a reasonable budget. An intelligence report arrives describing an access broker selling remote access credentials into their exact sector, with initial access achieved overwhelmingly through valid accounts against remote access gateways that lack phishing-resistant authentication. No malware. No exploit. Just credentials that work.

The CISO forwards it. The team agrees it is relevant. Two people say it is a good reminder. Then the quarter ends and nothing changes.

Look at why. The budget contains a line called network security, funded at $680,000, which covers the VPN concentrator, the firewall estate, a web gateway, and two smaller tools. Nowhere does it say what any of that money is betting against. There is no line reading "we are betting that an attacker holding valid employee credentials cannot reach the ERP environment." So when a report lands saying exactly that bet is losing, there is no line to raise, cut, or kill. The intelligence has no address.

Now give the same organisation named bets. Line fourteen reads "prevents credential replay against remote access. Assumes the attacker must present a password. Does not cover stolen session tokens or help desk social engineering." The same report now collides directly with a written assumption. The decision becomes almost mechanical, and it takes twenty minutes rather than a quarter.

Nothing changed about the intelligence. What changed is that the budget had something to say back.

Why nobody does this

Naming bets is uncomfortable, and the discomfort is the reason it gets deferred rather than any real difficulty. Write a sentence for every budget line and two things surface within an afternoon.

The first is duplication. You will find three products betting against the same adversary behaviour, bought in different years by different people for different reasons, each one justified on its own and indefensible next to the other two.

The second is stranger. You will find spend that cannot be assigned to any adversary behaviour at all. Some of that is genuine waste. Most of it is compliance spend, which is legitimate and necessary, but which has been quietly filed under defence for years. Labelling it accurately does not make it go away. It makes the defence portion of the budget honest, and honest numbers are the only ones you can reason about.

The SANS data hints at the same avoidance from another angle. Fifty-seven percent of threat intelligence programs do not track their own maturity over time, and 49 percent gather no systematic feedback on whether their output was useful. That is not laziness. If nothing downstream depends on the intelligence, there is genuinely nothing to measure. The measurement gap and the decision gap are the same gap.

The strongest objection

Anyone who runs a mature program will already be forming the obvious response. We do this. It is called ATT&CK coverage mapping, and we have a heat map.

That objection deserves a serious answer, because coverage mapping is genuinely valuable and most teams that do it are ahead of most teams that do not. But it answers a different question. Coverage mapping links tools to techniques. It tells you which adversary techniques something in your estate claims to detect. It says nothing about which dollars are attached to which claim, and more importantly, it says nothing about what each control assumes to be false.

A control can show full coverage of a technique on the heat map and still be betting on something that stopped being true eighteen months ago. Coverage says "we can see valid account abuse." The named bet says "we are betting valid account abuse requires a stolen password, and we do not cover token theft." Coverage is a claim about capability. The bet is a claim about the assumption underneath the capability.

Intelligence almost never attacks capabilities. It attacks assumptions. That is why a heat map full of green can sit next to an incident nobody saw coming, and why the 26 percent figure survives in organisations that have done all the mapping work.

Running it in parallel

None of this requires reorganising anything. Take next year's budget draft and run the naming exercise alongside your existing process for one cycle. Do not change a single allocation. Just add one sentence per line naming the adversary behaviour that line is betting against, and one clause naming the assumption it depends on.

The output that matters is not the sentences you write. It is the count of lines where you could not write one. That number is your answer to whether threat intelligence has anywhere to land in your organisation, and it is a far more useful metric than anything on an intelligence vendor's dashboard.

Three questions to put in front of your team on Monday. Pick any three budget lines and name the adversary behaviour each is betting against. For each, state the assumption that must hold true for the bet to pay. For each, name the specific piece of intelligence that would tell you the assumption has failed.

If your team answers all three in under ten minutes, you have named bets already and the 26 percent problem is not yours. If the answers require a call to the vendor, the vendor is holding your threat model and you are not.

What this actually buys you

Not better intelligence. The intelligence you already have is very likely sufficient. What you get is a budget where every line can be defended in one sentence. You get a mechanism by which new information can change an allocation. And you get a defensible answer to the question leadership and the board keep asking.

That question is whether the security spend is right. Today the honest answer in most organisations is that nobody knows, because nobody wrote down what the money was buying against. Named bets make the question answerable, which is worth more than any single control the budget contains.

Worldwide end-user spending on information security reached an estimated $213 billion in 2025 according to Gartner, and it continues to climb. The share of that money placed on bets nobody ever named is not a number anyone publishes. In my experience it is large.

Start with next year's budget. One sentence per line, before the negotiation starts rather than after. It will take a security leader a single afternoon, and it converts every intelligence report you receive for the rest of the year from something interesting into something decidable.

The intelligence is not failing to reach you. It is arriving at a budget that never wrote down what it believed.