The Hourglass: How the Threat Intelligence Market Restructures by 2031
Signal vs Noise15 min
The Hourglass: How the Threat Intelligence Market Restructures by 2031
CT
Crowd Threat
Intelligence Platform

Every company is a bet on how the future unfolds. AI isn't just a trend inside the threat intelligence industry — it's dissolving the profitable middle of it, leaving verified data and its certification as the only two durable assets by 2031.

Every company is a bet on how the future unfolds. The founders place it, the pitch deck portrays it, and investors have to decide whether to trust that the people in front of them have read the future correctly. Most of the time that bet is placed against a fairly stable backdrop: markets evolve, but the ground rules hold long enough for a thesis to play out.

I sometimes wonder how many companies in this sector actually do this thinking. Because if you have not worked through where the market itself is heading, you do not really have a strategy. You have a sales motion. You are chasing logos and market share in a sector that may pull the ground from under your feet while you are busy celebrating the latest win. Growth inside a structure that is about to be rearranged is not progress; it can be the opposite, because every pound of revenue built on an assumption that is about to break is a pound that will need rebuilding somewhere else.

This is not one of those times when the backdrop can be taken for granted. AI is not a trend inside this industry; it is rewriting the assumptions underneath every industry simultaneously, and the bets being placed across the threat intelligence sector right now diverge more sharply than at any point in its history. Some companies are betting that scale of ingestion still wins. Some are betting on owning the customer's workflow. Some are betting on government money, some on human judgement, some on the idea that in a world of infinite synthetic content, the only thing left worth paying for is proof.

They cannot all be right. The physical threat intelligence market has been described as fragmented, crowded and ripe for disruption so many times that the words have stopped meaning anything. But the last eighteen months of contracts, acquisitions and partnerships tell a very clear story if you read them together rather than one press release at a time. This piece is an attempt to do that: to map the bets on the table, the forces that will settle them, and where the sector lands by 2031.

The state of play

The market today spans a wide spectrum of players operating at different points in the intelligence cycle.

At the top end, Dataminr remains the reference point for real-time alerting from public data, recently reinforced by a five-year, $318 million contract covering the entire US Department of War enterprise and by its $290 million acquisition of ThreatConnect, which extends it from external signal into internal client context. Crisis24, inside GardaWorld, has taken the roll-up route, absorbing WorldAware, Topo.ai and OnSolve to assemble intelligence, critical event management, mass notification and response services under one roof. Seerist, formed from the combination of Control Risks' CORE platform and Geospark Analytics' Hyperion engine, pairs machine-scale monitoring with a large human analyst bench, and has been striking distribution partnerships at pace: into Ontic's Connected Intelligence Platform, Authentic8's Silo Marketplace, DataExpert in Europe and beyond.

Ontic itself, backed by a $230 million KKR-led round, is pursuing a different prize: becoming the system of record for corporate security, the single screen through which every other provider's intelligence flows. Everbridge, under Thoma Bravo ownership, plays a similar consolidating role in critical event management.

A fourth pattern comes from the opposite direction entirely: the guarding and protective-services incumbents integrating intelligence software rather than intelligence vendors integrating response capability. Securitas, whose portfolio includes Pinkerton, completed its acquisition of Liferaft in 2026 after five years as a partner, bringing OSINT monitoring technology in-house to sit alongside its own analyst teams.

Alongside them sits a layer of specialist providers, and within it two companies are pursuing what is recognisably the same thesis at different scales: that in an era of degrading open sources, the durable asset is verified human observation. Factal has taken the journalist route, combining AI detection with a professional editorial team that verifies, corroborates and geolocates incidents to newsroom standards, distributing through partners such as Esri and Vismo. Crowd Threat has taken the network route, building a vetted global crowd of local reporters who submit verified incidents from the communities where they live, on the logic that the world is too large and too fast for any centralised team to cover, and that the person best placed to report an event is the one already standing there. One model optimises for editorial rigour with a smaller trusted core; the other optimises for reach and speed with verification layered over a distributed crowd. Both are bets on the same future, and how each scales its verification will determine how far each can go.

Samdesk focuses on speed of disruption detection. And a newer generation of companies and products are emerging that focuses on specific stages of the intelligence cycle: firms concentrating on the direction phase, understanding the client deeply before any collection begins, and platforms embedding formal intelligence doctrine into AI so that analytical reasoning is transparent and auditable rather than a black box. Definitely check out Foresight Report's Nexus tool, the best I have seen. https://foresightreports.com/

Finally, AI itself has lowered the barrier to entry. Small teams, even individuals, can now build monitoring, analysis and dissemination tools that would have required a full engineering and analyst bench five years ago. A wave of AI-native micro-vendors is entering the market on exactly this basis, offering capable products at prices the incumbents cannot match. Where they fit in the sector's future is addressed below, because their fate is one of the clearer predictions this analysis makes.

Three forces, one outcome

The shape of this sector in 2031 will not be decided by any one competitor's strategy. It will be decided by the interaction of three forces already in motion.

The first force is capital structure. Dataminr has raised around $1.45 billion, yet secondary market pricing values it roughly 75 per cent below its 2021 round. Ontic's growth capital came from KKR in 2025. Everbridge is private-equity owned. Crisis24 sits inside a privately held group. Seerist is majority-controlled by Control Risks. Nearly every significant player has an owner with a natural liquidity horizon falling between 2029 and 2032. Fund lifecycles and preference stacks do not negotiate. A wave of exits and combinations in that window is not a possibility to be debated; it is implied by the cap tables themselves.

The second force is the collapsing cost of analysis. Every part of the intelligence cycle that consists of reading, synthesising and writing is being absorbed by general-purpose AI. This is usually framed as a threat to boutique consultancies, and it is. But it cuts upward too: the analyst benches that differentiated the larger providers from one another were funded by margin that is disappearing. The written assessment, as a paid product, is unlikely to survive the decade. The most forward-looking responses in the market reflect this, whether through transparent, doctrine-shaped AI reasoning, or through deeper investment in the direction phase of the cycle. These are retreats to the parts of the cycle machines cannot replicate: knowing the client, and knowing the ground.

The third force is signal pollution. Since 2009 the winning strategy in this market has been more sources, faster ingestion, better classifiers. That strategy assumed the open web was mostly written by humans reporting things that happened. That assumption is eroding. As synthetic content spreads through open sources, ingesting more of a polluted corpus does not make a platform more right; it makes it more confidently wrong. For the first time in the industry's history, breadth of collection risks producing negative returns to scale. The premium shifts from how much can be ingested to whether the origin of a piece of information can be proven.

The sequence

Put the three forces together and the next five years run in a fairly predictable order.

2026 to 2028: the partnership lattice hardens into a supply chain. The steady stream of integration announcements, verified intelligence feeding workflow platforms, incident data embedded in mapping and crisis tools, is not random. It is the market self-organising into tiers before M&A formalises them: collection suppliers feeding contextualisation platforms feeding response services. A partnership is a cheap option on a future acquisition, and every owner wants optionality before the exit window opens.

2028 to 2030: the consolidation cascade. One large transaction triggers the rest, because acquirers completing a stack will bid in every subsequent process. By the end of this window the commercial market likely consolidates to three or four full-stack owners. In parallel, contracts of the scale Dataminr has now secured create their own gravity: government and defence budgets dwarf what enterprise security deals produce, authorisation requirements such as FedRAMP or IL5, clearances and government-specific hosting are not partial commitments, and the compliance apparatus they demand only pays for itself by taking on more government work. A cleared, authorised product cannot be sold commercially without carrying overhead a corporate buyer will not pay for, and a commercially-optimised product cannot clear defence procurement at all, so the outcome is two genuinely separate stacks under one brand. This fork is only available to the handful of incumbents large enough to win contracts at that scale in the first place, which is what would split the market into tiers rather than shift it uniformly: a small number of primes forking into government-plus-commercial, the rest remaining commercial by default. It is currently a reasonable extrapolation from one strong data point, Dataminr's trajectory, rather than a pattern yet visible across multiple vendors.

2030 onward: the provenance regime. With consolidation complete, the surviving platforms compete primarily on data quality, and by then signal pollution has made verified primary collection the constrained input. The economics begin to resemble commodities more than software: platforms as refiners, verified collection networks as producers, and the scarce input commanding a premium because it cannot be created quickly with capital alone. Trust in a human network, whether a professional editorial team or a distributed global crowd, accretes over years; it cannot be bought into existence.

The hourglass

The end state is an hourglass. At the top, a small number of consolidated platforms owning the workflow and the customer relationship. At the bottom, a small number of verified primary collection networks. In the neck, very little: analysis, aggregation and dissemination, the comfortable middle where much of this industry has historically made its living, largely automated away.

The AI-native micro-vendors deserve a specific word here, because they occupy that neck and their trajectory is instructive. They are genuinely valuable to their users today, and their effect on the market is real: by driving the price of monitoring, analysis and dissemination toward zero, they collapse the margin of the middle layer faster than the incumbents would have collapsed it themselves. But they own no proprietary data and no system of record, which means they own nothing that compounds. Their end is absorption, though mostly not acquisition: the consolidated platforms have little reason to buy a tool they can rebuild in a quarter on the same foundation models, so most will be feature-absorbed, a few acqui-hired, and very few will become enduring companies. The middle is also being eaten from a second direction that receives less attention: the same tools let end customers build internal capabilities they would previously have bought as software, so part of the middle is swallowed not by the big players but by the buyers themselves. One consequence of all this cheap tooling, though, runs the other way: as the cost of building a presentation layer collapses, collection networks no longer depend on platform partners to package and deliver their data, which modestly loosens the top of the hourglass's grip on distribution.

The two ends will interact through a familiar progression: licensing arrangements first, as platforms take verified feeds under OEM deals; competition for differentiated data next, as open-source reliability degrades and exclusive access to trusted collection becomes a way for otherwise similar platforms to stand apart; attempts at vertical integration, as the larger players explore building collection networks of their own; and eventually a standards conversation, driven less by the vendors than by their most demanding customers.

That last point deserves emphasis, because it is the least discussed, and it may reshape the hourglass itself. It is tempting to treat verification as an attribute of the collector, something each network does to its own data. But there is a strong historical pattern suggesting it becomes a layer in its own right. Shipping produced classification societies, credit produced rating agencies, electronics produced independent testing laboratories: in each case the market concluded that self-certification was not credible, and an independent party captured the trust function, often with the best economics in the value chain despite owning none of the underlying assets.

The same logic applies here, with one important constraint. Incident-level verification cannot fully decouple from collection, because the product is measured in minutes and routing every raw report through a third party consumes the very edge being sold. It also requires deep access to the network itself: reporter identities, trust histories, corroboration channels. What can decouple, and likely will, is certification of the process. An independent body that audits a network's verification methodology, reporter vetting, trust scoring and chain of custody, and certifies it the way a classification society certifies a vessel, resolves the conflict of interest without paying the latency cost. The collector verifies each incident; the certifier verifies the verifier.

If that structure emerges, the hourglass gains a third node, and a powerful one. Certification bodies tend toward natural monopoly or duopoly, and the first credible one in this space will be difficult to displace. How it is funded will matter enormously: a model in which collectors pay for their own certification recreates the issuer-pays structure that undermined credit ratings in 2008, whereas a model funded by the insurers, governments and platforms who rely on the certification is structurally sound. Insurers writing parametric political risk products need an objective, contestable trigger; governments procuring intelligence need accountable sourcing. Both have every incentive to convene exactly this body, and the emergence of that standard, and who shapes it, may matter more to the sector's final structure than any single acquisition.

Three complications

Three further dynamics deserve a place in this analysis.

The first is the economy. Security budgets are no longer insulated from macro conditions: growth has slowed to its lowest rate in five years, and security leaders are being asked to do more with less. Physical security intelligence is more exposed to this than cyber, because cyber increasingly has regulatory spending floors and physical largely does not. Constrained buyers behave predictably: they consolidate vendors, which accelerates the hourglass because one platform replacing three line items beats three point solutions; and they favour anything that replaces headcount, which turns AI-driven products from a capability sale into a cost-reduction sale. A difficult economy does not slow the restructuring described here. It speeds it up, and it selects for survivors attached to non-discretionary money: defence, insurance and duty-of-care compliance.

The second is Palantir. It does not compete in this market, and that is precisely what makes it consequential. Its multi-year strategic partnership with Crisis24, which puts Foundry underneath Crisis24's risk analysis, is best read as a preview: the top of the hourglass itself running as an application on someone else's operating system. Palantir has no need to acquire anyone in this sector; it needs the sector's data flowing through its ontology, and every platform that builds on it trades a measure of sovereignty for capability, because whoever owns the ontology ultimately owns the customer. Notably, Palantir does no primary collection of its own, which makes it a permanent, well-capitalised consumer of verified data rather than a threat to those who produce it.

The same pattern is now visible in defence. Alongside the DoW contract, Dataminr launched an application on the Palantir Foundry Marketplace that fuses its alerting output with government data layers inside Foundry, enabling agentic workflows on top of it. Foundry is already deeply embedded across US defence procurement, so this is less a choice than a recognition that any serious DoD-wide deployment will eventually run through it regardless of which vendor supplies the underlying signal. The likely equilibrium mirrors the commercial one: Dataminr's proprietary alerting engine, built on a data archive Palantir cannot easily replicate, becomes the best input plugged into Foundry, much as Seerist and other feeds are becoming inputs into Ontic. The defence tier does not escape the hourglass so much as reproduce it, with Foundry rather than First Alert positioned to become the actual pane of glass in government, even though the contract headline belongs to Dataminr. This is inference from a single, very recent data point rather than a confirmed trajectory, but it is consistent with the logic playing out commercially.

The third is the way intelligence is starting to be delivered. Buyers increasingly want threat intelligence through APIs and, more recently, through Model Context Protocol servers that plug directly into AI assistants, letting a security team query intelligence conversationally rather than through a dashboard. Vendors across the security industry are shipping MCP servers at pace, and physical risk providers are beginning to follow. The implication is uncomfortable for the top of the hourglass. This analysis assumed the pane of glass was the safe position. But if the buyer's own AI environment becomes the interface, and a client can assemble a bespoke internal platform in days, then workflow ownership migrates to the customer, and the security-specific platform is disintermediated from above at the same moment the middle dissolves beneath it. A platform publishing an MCP endpoint is, in effect, converting itself into the very thing it made of its suppliers: a feed.

The five-year picture in this piece stands. The ten-year picture could be: the top of the hourglass may not be a security platform at all, but the buyer's own AI environment, running on general-purpose infrastructure and consuming certified data over open protocols. In that world, only two assets in this industry are durable. Verified data, and the certification that makes it worth trusting.

The hinge

Everything above turns on a single question: in a world where synthetic content makes open sources progressively less reliable, whose information can still be trusted, and how is that trust demonstrated?

Verification is easy to claim and hard to prove. It will be tested by hostile actors seeding false reports, by lawyers contesting claims, and by the ordinary entropy of any network operating at scale. The providers whose verification survives adversarial scrutiny, rather than marketing scrutiny, will define the bottom of the hourglass. The platforms that secure access to them will define the top. And if an independent certification layer emerges between them, the body that administers it may quietly become the most important institution in the industry.

Consolidation is certain. Automation of the middle is certain. The only genuinely open question in this market is who gets to be believed.

Michael McCabe is the founder and CEO of Crowd Threat, one of the companies discussed above. He previously founded Intelligence Fusion and served in British Military Intelligence. The views here are his own analysis of publicly available information.

Contact
contact@crowdthreat.com
15A Cobalt Business Park
Quick Silver Way
Newcastle Upon Tyne
NE27 0QQ
United Kingdom
SSEA 2026 FINALIST
MARKET DISRUPTOR OF THE YEAR
REGISTERED IN ENGLAND & WALES · CO. NO. 15880372
©2026 Crowd Threat Limited. All rights reserved.
Registered in England & Wales · Company No. 15880372 · VAT No. GB495919525 · Privacy · Terms