Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

Risk Intelligence

Risk intelligence is the practice of mapping global threats against a specific organization's ecosystem to produce actionable, contextualized findings, as distinct from broad threat intelligence, which describes the threat landscape in general terms. It answers the question: does this global threat affect my vendors, and if so, how? Black Kite's risk intelligence outputs include FocusTags®, the Vulnerability Intelligence Brief (VIB), the Ransomware Susceptibility Index® (RSI™), the Adversary Susceptibility Index™ (ASI™), and Financial Impact Ratings.

Risk Intelligence is the practice of mapping global threats and vulnerabilities against a specific organization’s own vendor ecosystem, turning broad threat data into findings that are directly actionable for that organization. General threat feeds describe what’s happening in the world. Risk intelligence narrows that down to which vendors are actually exposed, and what it means for them.

Black Kite’s risk intelligence outputs include FocusTags®, the Vulnerability Intelligence Brief (VIB), the Ransomware Susceptibility Index® (RSI™), and the Adversary Susceptibility Index™ (ASI™), each mapping a different category of global threat data onto a specific vendor portfolio. The need for this layer exists because raw signal has outpaced any team’s ability to review it manually. Tens of thousands of vulnerabilities are disclosed every year, and only a small fraction of them ever get weaponized against a real target.

What Turns Raw Threat Data Into Risk Intelligence?

Three things turn raw threat data into risk intelligence: correlation against a known asset inventory, prioritization by real-world exploitability, and delivery to the team that owns the relationship.

  • Correlation: matching a disclosed vulnerability, breach, or threat actor campaign against an actual inventory of vendors and assets, not a generic industry list.
  • Prioritization: ranking what’s left by real-world exploitability, not just a severity score assigned at disclosure.
  • Delivery: routing the finding to whoever owns that vendor relationship, with enough evidence to act without further research.

Without all three steps, the exercise stays threat intelligence. It might be broad and current, but it’s largely irrelevant to any one organization’s actual risk. Filtering that noise down to a workable queue is also the argument behind AI for TPRM: Filter the Noise in 24/7 Risk Monitoring, which walks through the same problem from the monitoring side.

How Is Risk Intelligence Different From Threat Intelligence?

Threat intelligence describes what’s happening across the global threat picture. Risk intelligence maps that same activity onto a specific organization’s vendor ecosystem to show what it actually means for that organization.

That distinction, the difference between information about the world and information about your world, is significant enough that it gets its own dedicated comparison: Risk Intelligence vs. Threat Intelligence.

Why Does CVE Volume Make Risk Intelligence Necessary?

The volume of published vulnerabilities has grown past the point where manual triage works, and only a sliver of what’s disclosed ever gets exploited.

The Long Tail of Exploited CVEs

More than 48,000 CVEs were published in a single recent year, and Black Kite’s 2026 Supply Chain Vulnerability Report found that roughly 800 of them, roughly 1.7%, were ever exploited in the wild. The other 47,000-plus disclosures are noise relative to any specific portfolio, but a security team has no way to know which 800 apply to them without a mapping step in between.

Exposure Concentrates Outside the Headlines

That mapping step gets harder as vendor portfolios grow, because exposure doesn’t distribute evenly. The same report found that 82% of all company-to-CVE matches identified fell in the long tail, outside the 20 most-discussed vulnerabilities of the year. Most of what actually touches an organization’s ecosystem never shows up on a top-ten list or a vendor’s own security bulletin. Risk intelligence exists specifically to surface that long tail, not just the headline CVEs everyone already knows about.

What Data Feeds Risk Intelligence in a Vendor Ecosystem?

Risk intelligence typically draws on three categories of signal: vulnerability and exploit data, breach and threat-actor activity, and geopolitical or concentration exposure.

  • Vulnerability and exploit data: newly disclosed CVEs, exploit code availability, and whether a flaw has been added to the known-exploited vulnerabilities catalog.
  • Breach and threat-actor activity: confirmed incidents, ransomware group targeting patterns, and leaked-credential exposure tied to a specific vendor.
  • Geopolitical and concentration signals: sanctions, regional instability, and concentration on a single provider or region across a portfolio.

None of these signals is useful in isolation. A CVE with no exploit code, a threat actor with no history in an organization’s industry, or a geopolitical event with no vendor footprint nearby is background noise until it’s checked against who’s actually in the ecosystem. That checking step is why a standalone vulnerability assessment of one vendor and a portfolio-wide risk intelligence program answer different questions, even when they start from the same CVE.

How Is Risk Intelligence Applied in Practice?

Running that correlation continuously across an entire vendor portfolio, rather than one vendor at a time, is what separates risk intelligence as a program from risk intelligence as a one-off exercise.

Black Kite built its risk intelligence capability around exactly that gap, and it’s a large part of why the company is positioned as the leader in third-party cyber risk intelligence rather than a general threat feed. FocusTags® flag which vendors in a monitored portfolio are exposed to a specific breach, ransomware campaign, or newly disclosed CVE. In 2025, 95.2% of those tags were applied before the underlying CVE reached the CISA KEV catalog, or within 24 hours of it.The Vulnerability Intelligence Brief™ breaks down why a given flaw does or doesn’t apply to a specific vendor’s environment, backed by continuous monitoring that keeps the underlying signal current. For a third-party risk management team covering hundreds of vendors, that’s the difference between chasing every headline CVE and working a queue that’s already been filtered down to what’s actually exposed.

The full stack of outputs, and how they fit together, is covered in more depth in the Cyber Risk Intelligence Knowledge Center.

What Are the Limits of Risk Intelligence?

Risk intelligence is only as good as the inventory and data feeds behind it, and it can still generate false positives that cost a team credibility if they aren’t triaged carefully.

Coverage Gaps in the Inventory

A vendor that never appears in an organization’s tracked inventory can’t be flagged, no matter how good the underlying threat data is. Shadow IT, informal fourth-party relationships, and newly onboarded vendors are common blind spots, and risk intelligence can only correlate against what it can see.

False Positives Erode Trust

A tool that flags too aggressively trains its own users to ignore it. Matching a CVE to a vendor by product name alone, without confirming the vendor actually runs the affected version, produces exactly this kind of noise, and it’s one of the more common failure modes in less mature risk intelligence programs.

See also: Stop Drowning in CVEs: Prioritize Supply Chain