The CTI Oligopoly’s Contractual Firewall: Restrictive Licensing as a Structural Barrier to Collective APT Defence

Authors

DOI:

https://doi.org/10.34190/eccws.25.1.4743

Keywords:

CTI, Threat intelligence, AI

Abstract

Cyber threat intelligence (CTI) is widely promoted as indispensable for modern cyber defense, yet collective defense in practice is constrained by market concentration and restrictive licensing imposed by a small number of dominant vendors. This study analyses 34 publicly available documents; licence agreements, terms of service, API documentation, and pricing materials, across 15 major commercial CTI providers. Following a thematic analysis approach, we code restrictions across six dimensions: (1) access pathways and subscription gating, (2) redistribution and collaboration rights, (3) automation interfaces and rate limits, (4) portability and interoperability, (5) pricing transparency and contract flexibility, and (6) geographic and jurisdictional constraints. Findings confirm a highly concentrated oligopolistic market in which the top five to ten vendors control an estimated 50–80% of global revenue and a disproportionate share of APT telemetry. Recent consolidation, including Mastercard’s USD 2.65 billion acquisition of Recorded Future in December 2024, further reinforces this concentration. Licence terms systematically prohibit redistribution to third parties, constrain automation through non-cumulative quotas and unstable APIs, and obscure pricing behind enterprise sales funnels. These patterns constitute what we term a contractual firewall, a structural barrier that prevents threat intelligence from flowing between defenders even where policy frameworks encourage sharing. The contractual firewall creates asymmetries in defensive capability that disproportionately affect SMEs, public-sector entities, and sector consortia. These constraints do in some instances conflict with European collective defense mandates like NIS2, but fundamentally fragment the defender ecosystem, leaving smaller entities vulnerable to sophisticated threat actors. We suggest some procurement-focused recommendations for redistribution carve-outs, export and portability requirements, API stability guarantees, and multi-source resilience strategies. Future work should validate these patterns against negotiated enterprise terms and assess operational impact in incident response environments. We conclude that resource-constrained defenders facing APTs are caught in a systemic double bind: the ’contractual firewall’ restricts the intelligence access necessary for pro-active defense, while regulatory frameworks like NIS2 impose sharing mandates that these commercial restrictions effectively render impossible to fulfill.

Author Biography

Raymond Hagen, Norwegian University of Science and Technology

 

 

Downloads

Published

2026-06-15