In sports, a great defense must understand the offense. It is no different in security operations. It is not enough to just know threat intelligence—it needs to be acted on. Forrester recognizes ReliaQuest in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026, where ReliaQuest was named a Strong Performer.
At ReliaQuest, we believe that threat intelligence delivers the most value when it provides holistic context that drives action across security operations. In 2025, the fastest data exfiltration time we observed was just six minutes, down from over four hours the previous year. To keep up, security leaders must go beyond just collecting intelligence and use it to power automated action across detection, containment, investigation, and response.
Over the past two decades, we’ve built GreyMatter with the future of security operations in mind. By unifying threat intelligence into a single, actionable view, teams can take faster defensive action before adversaries complete their objective.
Threat Intelligence Must Drive Action
When threat intelligence is used as an operational tool, it becomes an active input into how security operations run.
Proactive security operations are rooted in threat intelligence. Without it, detection rules fall behind, investigations miss context, and response actions stay generic. With it, security teams can move from reacting to alerts toward proactive, Agentic Defense, where intelligence continuously gives the team the insight and action to outpace adversary speed.
When attackers are moving faster than ever, intelligence becomes the signal that helps every part of the defense move faster and with more precision.
GreyMatter Turns Intelligence into Agentic Defense
For us, threat intelligence is one discipline that strengthens agentic defense. GreyMatter makes defense agentic by running threat intelligence across your connected tech stack in plain language. This allows analysts to move from intelligence discovery to investigation to response in one place.
It continuously collects threat intelligence from more than 50 feeds across deep, dark, and open web sources, combined with proprietary collection systems and human-led research. It correlates intelligence with assets, identities, vulnerabilities, and IOCs in a unified model, giving teams the context needed to take defensive action.
From there, GreyMatter turns intelligence into operational action. It runs detection logic, enrichment, and response natively across existing security tools, without forcing teams to pivot between systems or rewrite workflows. It also builds and tunes detections continuously, removing the need for manual rule-writing and helping coverage stay current as threats change.
When intelligence serves as the connective tissue across the platform, teams can shift away from a reactive SOC, and towards a proactive and predictive security operation.
What Forrester’s Evaluation Found About ReliaQuest
Forrester’s evaluation reflected the following findings regarding ReliaQuest’s External Threat Intelligence Services:
1. Threat intelligence as the nervous system of the agentic SOC
Forrester’s report noted "ReliaQuest’s vision positions threat intelligence as the nervous system of the agentic SOC, reflecting where security operations is headed, rather than threat intelligence.” This aligns with our belief that intelligence should not sit apart from security operations, but help drive detection, containment, investigation, and response.
2. Data normalization and correlation at scale
Forrester’s evaluation found that “ReliaQuest’s SecOps-centric platform excels at normalizing and correlating security data at scale through its Universal Translator and adoption of the Open Cybersecurity Schema Framework." We believe this gives teams a unified view across connected technologies without forcing them to centralize all data first.
3. Practical AI agents with appropriate validation controls
Forrester’s assessment noted that ReliaQuest “offers a range of practical AI agents built on robust architectures with appropriate testing and validation controls.” ReliaQuest also scored a 5 out of 5 in criteria including AI agent maturity, product security, and roadmap in the Forrester Wave™: External Threat Intelligence Service Providers. These capabilities are core to how GreyMatter delivers Agentic Defense across security operations: breaking work into focused tasks, so teams can act at the speed and accuracy of attackers.
4. A “forward-looking roadmap” aligned to its ambition
Forrester’s report also recognized ReliaQuest’s “forward-looking roadmap”, which “addresses multiple threat intelligence use cases and evolving customer needs.” To us, that direction reflects how we are building GreyMatter to not only support threat intelligence, but to operationalize it as part of Agentic Defense.
5. A strong fit for enterprise customers with limited security personnel
Forrester’s take is that ReliaQuest is “a strong fit for enterprise customers with limited security personnel, particularly those seeking a consolidated security operations platform as an alternative to traditional SIEM-centric deployments.”
In The Forrester Wave: External Threat Intelligence Service Providers, Q3 2026, ReliaQuest was named a Strong Performer. For us, this recognition reflects the role threat intelligence plays within GreyMatter: a platform where threat intelligence functions as the connective tissue between detection engineering, alert triage, and response orchestration. GreyMatter Agentic Teammates autonomously investigate and respond to 100% of alerts across 300+ technologies with 99.4% accuracy—more than 74 million times a year—while GreyMatter customers contain threats in under 5 minutes.
For us, our placement reflects our belief that the future of security operations depends on threat intelligence being operationalized across the entire lifecycle—from detection engineering to investigation and response.
Today, GreyMatter customers use this model: a platform where threat intelligence is imbedded into how the security operations runs, so every detection, investigation, and response action is backed by context, executed at speed, and scaled across the enterprise. That operational reality is what we'll continue to build on.
Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here.

