How and why we create threat intelligence for Small and Medium sized Businesses (SMBs)
- Jul 27
- 5 min read

https://www.blackcatsecure.co.uk/ransomware-prevention-map - please feel free to try the interactive map for yourself.
How We Gather and Curate Threat Intelligence for SMBs
Threat intelligence can sound like something reserved for large organisations with a security operations centre and a wall of dashboards. For small and medium-sized businesses, it should mean something much simpler, knowing which risks deserve attention now, why they matter to your business, and what to do about them.
At Black Cat, we gather signals from across the threat landscape and turn them into practical, prioritised advice. The aim is not to give our customers more alerts. It is to help them make the best decision they can at the time.
The problem is not a lack of information
Every day brings new vulnerability notices, scam reports, ransomware stories and security headlines. Taken individually, they can be difficult to interpret. A high-severity vulnerability may not affect your business at all; a less dramatic issue may deserve urgent action if it affects a system you expose to the internet and attackers are actively looking for it.
That is why raw information is not enough. Good threat intelligence adds context:
What are criminals actively trying to do?
Which technologies, accounts or business processes are involved?
Are organisations like yours likely to use or expose them?
What could an attacker reach if they succeeded?
Which action will reduce the risk most quickly?
The final question is the most important. For an SMB with limited time and budget, intelligence only becomes useful when it leads to a decision.
How we build the picture
We do not rely on one source or a single vulnerability score. We combine several types of evidence to identify where real-world attacker interest and meaningful business exposure overlap.
1. Watching for attacker activity
Our internet-facing network sensors help us see patterns in hostile activity: broad scanning, repeated attempts to reach particular services, requests for known vulnerable paths and exploit-like behaviour.
The public internet is noisy, so one suspicious request does not automatically mean a targeted attack. We look for patterns: activity that is increasing, becoming more specific, or pointing repeatedly at the same technology or weakness. This can provide an early indication that an entry point is attracting attention.
2. Following vulnerability and exploitation intelligence
We track security advisories, vendor updates and credible reporting about vulnerabilities and active exploitation. Severity is part of the assessment, but it is not the whole story. We also consider whether a weakness is easy to exploit, whether a fix or mitigation is available, and whether it affects a commonly deployed product such as a firewall, VPN, remote-access gateway or email platform.
3. Learning from ransomware and incident patterns
Ransomware is rarely a single event. Criminals need an initial way in, then time to expand their access, steal information and interfere with recovery before encryption or extortion becomes visible.
By studying the access routes and control failures that recur in ransomware incidents, we can connect a new technical signal to the business risk behind it. An exposed remote-access service, for example, matters more when it could lead to administrator access, shared systems or backups.
4. Applying the SMB context
The same threat does not carry the same priority for every organisation. We consider practical questions such as whether the affected technology is likely to be in use, whether it is internet-facing, whether multi-factor authentication is in place, what access it provides, and whether a successful compromise could interrupt operations.
This is how we avoid treating every alert as equally urgent. The goal is proportional action: focus first on the issues most likely to create a meaningful route into the business.

We gather information from all the major ransomware leak sites using https://www.ransomware.live/ we then enrich this with company information, sector and size to make sure we provide the most relevant information to SMBs as we can.
From signals to a useful recommendation
Before we elevate an issue, we ask whether the evidence supports a clear action. In practical terms, a useful alert should answer four things:
Question | What it means for the business |
What is happening? | Attackers are scanning for, exploiting or otherwise showing interest in a particular weakness or route of access. |
Why does it matter? | The affected system may provide access to email, remote working, administrator functions or other important services. |
Who needs to check? | The internal IT team, MSP, system owner or business process owner responsible for the technology. |
What should happen next? | Confirm exposure, patch or mitigate, reduce unnecessary access, review relevant logs and escalate if suspicious activity is found. |
That approach keeps the message focused. It avoids sending someone a long technical report when what they need is a short list of checks and a sensible order in which to make them.
What this looks like for an SMB
Depending on the risk, the immediate action may be to:
confirm whether an affected product or service is in use
check whether it is exposed to the internet
install the vendor update or apply the recommended mitigation
remove unnecessary public access or restrict it to authorised users
ensure multi-factor authentication protects remote and privileged access
review logs for unexpected sign-ins, configuration changes or new accounts
confirm that backups are separated from normal user access and can be restored
These are often straightforward actions, but timing matters. A good intelligence process helps bring the right one forward before an attacker turns an exposed weakness into an incident. On the occasions that we think it necessary we also provide SMS alerts if it can't wait for the next weekly report.
The fundamentals are still the strongest defence
Threat intelligence helps set priorities; it does not replace the basics. The controls that repeatedly make ransomware and other attacks harder include prompt patching of exposed systems, strong multi-factor authentication, well-managed administrator accounts, limited public exposure, monitored logs and tested, isolated backups.
For a more detailed view of how these controls fit together across a ransomware attack path, explore our Ransomware Prevention Map. It is an optional deeper-dive resource for cyber security enthusiasts, IT teams and practitioners. Most business leaders do not need to work through every technique or control on the map; the important point is that ransomware is a chain of opportunities, and breaking any link in that chain reduces risk.
Intelligence should make the next step clearer
The purpose of threat intelligence is not to make the threat landscape feel more complicated. It is to cut through the noise.
By combining attacker activity, vulnerability intelligence, ransomware research and the realities of SMB technology, we can focus attention on the risks most worth checking, fixing or escalating. For customers, the outcome should be simple: a clear understanding of what matters, what to do, and who needs to do it.
That is the kind of threat intelligence that helps an SMB stay resilient.
This article is general information and should be applied alongside your organisation's own systems, risk assessment and incident-response arrangements.



Comments