Our View on What It Takes To Be Named an Industry-Recognized Threat Intelligence Leader

Recorded Future was just named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026.

We’re incredibly proud of this acknowledgment, just as we are of every recognition we’ve received over the years. Behind every one of these industry evaluations is a lot of work that readers never see — including product demonstrations, customer reference calls, briefing presentations, and formal questionnaire submissions — all of it condensed into a single final report. But the most interesting part of any industry recognition is all the details and information that resides in the demos, decks, and responses, so we wanted to share some additional context on the factors that we believe contributed to our ranking this year.

Use this blog post as a companion guide when reading your complimentary copy of the Forrester Wave™ report, which you’ll find in the link below.

Get the report.

Superior support for Priority Intelligence Requirements

Priority Intelligence Requirements (PIRs) are foundational in helping security teams achieve meaningful outcomes, because they help shape data collection strategy and support the effective decision-making that enables machine-speed defense.

Recorded Future received the highest possible score in the PIR criterion. Forrester’s evaluation describes this score as for vendors that offer “superior support for features such as mechanisms to translate external PIRs meaningfully, advanced querying for building/optimizing PIRs, and structured management of General Intelligence Requirements.”

We’ve made PIRs a particular focus in the Recorded Future Platform, adding prebuilt PIRs and enabling customers to use them or define their own in our Impact and Metrics Dashboard. The dashboard surfaces metrics based on those requirements, so teams can more easily measure and better report on how successfully their programs are answering the key questions business leadership wants answered.

Extensive intelligence collection sources and deep and dark web monitoring

Intelligence is at the core of the modern security stack, and good intelligence is often what separates reactive security teams from proactive ones that can defend themselves pre-attack, at the first sign of threat.

To us, Forrester’s evaluation criteria show how important comprehensive intelligence collection is in providing security teams with full visibility across the threat landscape. Here are the different types of data sources we primarily index and analyze and how these data sources can be used for a multitude of use cases:

  1. Technical intelligence — network traffic analysis across billions of daily data points from over 200 points of presence, internet-wide scanning and infrastructure monitoring, malware detonation and behavioral analysis, and vulnerability exploitation tracking
  2. Underground intelligence — data gathered from criminal forums, marketplaces, and adversaries that can help identify stolen data and credentials, emerging attack techniques, threat actor intent, and ransomware victimology
  3. Community intelligence — aggregated detections across customers that reveal patterns and campaign-level activity no single organization would usually catch on its own
  4. Open-source intelligence — broader context from data leakage detection, code repository monitoring, social media monitoring, and web/HTML/DOM analysis to help catch brand abuse, impersonation, and exposed data

Threat hunting, vulnerability intelligence, third-party risk management, and more
We believe that receiving the highest possible scores in the Forrester Wave in criteria around multiple cybersecurity disciplines — including brand protection, third-party and supply chain intelligence, fraud intelligence, and threat hunting and vulnerability intelligence — demonstrate our commitment to providing powerful threat intelligence and defensive capabilities across the entire attack surface.

Figure 1: Unified threat intelligence visibility across the critical attack surfaces

Just to highlight a few of our unique capabilities:

New pricing packages designed for the modern threat landscape

In addition to evolving our technology solutions to better meet customers’ needs, we’ve recently revealed our pricing and packaging, moving away from modules. We made the change in response to a threat landscape that’s moving faster and growing more interconnected — and to customer requests for complete, domain-aligned capabilities plus easier access across teams and more predictable pricing.

This includes having Platform Packages (Core, Professional, and Elite) for organizations who want multiple Cyber threat intelligence use cases covered and need broader, cross-attack surface visibility and capabilities. We also have individual Solution Packages (Cyber Operations, DRP, Third-Party Risk, and Payment Fraud) for organizations that are focusing on single use cases.

Our new pricing packages will continue to evolve to address different organization types, use cases, and how organizations want to license CTI. You can learn more about the new pricing on our pricing page.

A Leader for the future


The capabilities highlighted above are just a few of the many ways we empower organizations to defend at machine speed. There’s lots more to the report and what goes into being a leader. To learn more, book a demo or join us for our upcoming product roadmap webinar.

Get the Forrester Wave™ report.

Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here.