Why iSight assembled a team of top cybersecurity experts to prioritize preemptive threat intelligence over reactionary alerts
Nicole Perlroth / New York Times :
Context & Ripple Effects
In 2015, iSight made a hiring-first bet: instead of selling firehose alerts after intrusions, staff up with elite analysts who can identify attacker infrastructure and intent before a breach lands. The New Yorker's later reporting on the 0-day market fed by the NSA's offensive priorities explains the supply side of what iSight's team was built to track — nation-state tooling circulating before defenders see it.
The payoff case arrived two years on, when IDT Corporation's CIO surfaced NSA-linked DoublePulsar in his own network, showing exactly what reactionary alerting misses and preemptive hunting finds. The model iSight pioneered then became institutional: Microsoft's Threat Intelligence Center, staffed largely by ex-intelligence and military personnel, is the same playbook absorbed into a hyperscaler.
First-order effects
- Corporate security buyers face a fork: keep paying per-alert vendors or shift budget toward subscription intelligence teams that name adversaries before compromise, pressuring alert-centric rivals' pricing.
- A talent market tightens around ex-intelligence and military analysts, as specialist firms like iSight and large platforms bid for the same small pool of people who can read attacker behavior.
Second-order effects
- Large platform companies respond by building the capability in-house — Microsoft's ex-intelligence-staffed threat center turns boutique intelligence into a bundled feature, squeezing standalone firms on distribution rather than expertise.
- When stockpiled offensive tools leak into the wild, as DoublePulsar did at IDT, demand for preemptive intelligence spikes across every downstream customer of the affected software.
Third-order effects
- If the pattern holds, the industry restructures from alert queues to anticipatory defense, ending in agentic systems like Microsoft's MAI-Cyber-1-Flash and its Perception patching system that automate what iSight's analysts once did by hand.
- The offensive-defensive imbalance documented in the cyberweapons arms race keeps preemptive intelligence a permanent line item rather than a premium add-on, shaping procurement norms across governments and enterprises alike.
The trend: Cybersecurity is consolidating around preemptive threat intelligence — first via expert teams like iSight, then institutional centers, now agentic AI — displacing the reactionary-alert model that dominated the last decade.