Dataminr BLOG

The Threat That Gets You Is in the Source You’re Not Watching

The Threat That Gets You Is in the Source You’re Not Watching
DATE October 7, 2026
AUTHOR Dan Cole, VP Product Marketing, Dataminr for Cyber Defense
SHARE

We published an ebook called Mending the Broken Cyber Defense Chain, and the argument in it is that a cyber defense program is really three links that mostly don’t connect: what’s coming at you, how exposed your attack surface actually is, and what it costs the business if it lands.

People who read it tend to agree about the diagnosis. Then they tell me which link they think is easiest to mend, and it’s always the same one.

The threat side, right? That’s a procurement problem. Just buy more feeds.

I understand the instinct. Next to untangling your asset inventory or getting your control data to agree with itself, buying intelligence feels tractable. Feeds are real infrastructure, good ones earn their keep, and ingesting them well is part of what we built our platform to do. But “add a source” treats coverage like a subscription you top up, and coverage is actually the hardest of the three to get right. The Galactic Empire knew this, and excelled at addressing it. But they missed one important part.

A Quick Refresher, In Case It’s Been a While (The Empire’s Intelligence-Gathering Problem)

The Empire Strikes Back opens with a search. The Rebels have gone to ground somewhere in a very large galaxy and the Empire has no idea where — no shortlist, no lead, nothing to aim at. So they don’t aim. They load thousands of probe droids into launch tubes and fire them off in every direction at once, on the theory that if you can’t point at the thing you’re hunting, you cover ground instead.

One droid lands on an ice planet called Hoth and starts transmitting.

The most consequential decision in the movie is an intelligence sourcing strategy.

Hold that image. The Empire is about to get two things right and one thing very wrong, and security teams tend to do the same three things in the same order.

What the Empire Got Right: Volume Is the Strategy (Threat Intelligence Coverage)

Nobody at Imperial Command wanted thousands of droids because thousands sounded impressive. They wanted thousands because the Rebel base was a known unknown — certain to exist, impossible to locate — and the only thing that moves the odds on a known unknown is looking in more places.

Our own industry undersells this constantly. Breadth gets talked about like a vanity metric — a number on a slide, something you put in a comparison table. It isn’t. When you genuinely don’t know where a threat will surface, breadth is the mechanism. More sources means a higher chance the signal crosses your field of view at all, and it usually means you see it sooner, because the first place a threat appears is rarely the place that eventually writes it up.

That’s why threat coverage is the foundation of good cyber threat intelligence, and why Dataminr collects across 1.3 million sources, and why we have a team that spends its days finding and standing up more. What that buys:

  • Fortinet FortiWeb: a zero-day detected 38 days before CISA catalogued it.
  • Johnson Controls: 27TB of exfiltrated data identified from images posted on threat forums. Screenshots. File listings. Not a word of text, and it landed before the victim organization had confirmed anything.
  • MOVEit: 23 additional Fortune 500 companies identified as impacted inside a four-hour window, because one event could be read against everything else in view at the same time.

We would not have found any of those if we weren’t watching that many places. Not one of them surfaced somewhere obvious, and none of them would have turned up with a handful of sources and good intentions. You find the base because you have 1.3 million probe droids searching the galaxy.

What the Empire Also Got Right: Somebody Has to Read It (Threat Analysis & Analyst Experience)

The droid’s report comes in, and the Empire almost throws it away. Watch how fast it happens.

  • Piett: Sir, I think we’ve got something. The report is only a fragment from a probe droid in the Hoth system, but it’s the best lead we’ve had.
  • Ozzel: We have thousands of probe droids searching the galaxy. I want proof, not leads!
  • Piett: The visuals indicate life readings.
  • Ozzel: It could mean anything. If we followed every lead…
  • Vader: That’s it. The Rebels are there.

Ozzel is not an idiot (don’t @ me, Lord Vader). He’s running a triage queue with thousands of inputs and applying a rule every analyst has applied: don’t chase fragments. Defensible. Also about to lose him the search, because volume without interpretation is just a bigger pile.

Vader gets there in three seconds, and — this is the part I think gets misread — not because of the Force. He’s been hunting these people for years. He knows how they move, what they choose, what an uncharted settlement with life readings means when that’s who you’re looking for. Same fragment, same room, same three seconds — the only difference is how much history each of them has to read it against.

You can buy the droids. You can’t buy the years.

Dataminr has twelve-plus years of labeled security events, every label a decision somebody made about what counted and what turned out to matter. Our first foundation model went into production in 2020, and there are 100+ specialized models running on that history now. That’s how we find the signal in the noise — all of that experience, and years of investment in building it. Much the same way Vader knows how the Rebels work.

What the Empire Missed (The Gap Between Threat Detection and Relevance)

So the Empire finds the base. Vader reads the fragment correctly, the fleet arrives, Veers lands the walkers, and the ground assault works. Echo Base falls. By any reasonable measure, the intelligence operation succeeded.

And they still lose AT-ATs to a rope.

A rope.

Wedge Antilles’ snowspeeder wraps a tow cable around a walker’s legs and drops it. Luke cuts into the belly of another one with a lightsaber. Both are known weaknesses in a specific Imperial asset, exploited by a known adversary using known equipment.

Somewhere in Imperial intelligence was a file on Rebel snowspeeder tactics. Somewhere else was a schematic of an AT-AT. Both accurate. Never once compared.

That’s the gap, and it’s where most security programs sit right now. You can have real coverage and genuinely experienced interpretation and still be surprised, because knowing a threat exists is a different question from knowing it’s yours. Teams answer the first one in minutes and routinely take days on the second — pulling asset lists, checking versions, asking around about whether anybody still runs that thing in a regional office. All of that work is comparing two files by hand.

Two Files, One System (Client-Tailored Threat Intelligence)

Coverage finds the threat. Experience tells you it’s real. Neither one tells you it’s about you, and that last part is the reason the first two matter at all.

Closing it is what Client-Tailored Threat Intelligence is for: external signal arriving already matched against your environment, so an alert that fires already knows which of your assets it touches. The Empire’s problem was never collection, and it was never analysis. Nobody ever put the two files side by side.

If you want the longer version — how threat, exposure, and business impact come apart, and what it takes to reconnect them — that’s the whole subject of Mending the Broken Cyber Defense Chain.

And if you’d rather test the idea than read about it: take the last three incidents that hit your industry, and ask whoever supplies your intelligence two questions. When did you first see it, and how long did it take you to tell me whether it applied to us?

The first answer tells you about their coverage. The second one is the whole ballgame.

Oct 7, 2026

SHARE
  • Cyber Risk
  • Blog