Quick answer: MSP threat sharing breaks down because intelligence is scattered across too many sources, too noisy to act on and rarely shared back with peers. The GTIA Information Sharing & Analysis Organization (ISAO) fixes this. It gives GTIA members curated, channel-specific threat intelligence, a trusted peer community and action-ready threat reports. The ISAO is valued at $7,200 a year and is included with every GTIA membership.
Cybersecurity Awareness Month starts today. The IT channel faces a clear challenge: Attackers already share tooling, tactics and lessons learned, while most MSPs still defend alone.
At ChannelCon 2026 in San Diego, a panel of channel security leaders explained why threat sharing falls short and how to fix it. The panel included Jack Skinner, CTO at Oversee My IT and GTIA Cybersecurity ISAO Advisory Group member; Jason Slagle, president at CNWR, Inc. and Chair of the GTIA ISAO; Oli Thordarson, founder and CEO at Alvaka; and Ann Westerheim, president at Ekaru and GTIA Cybersecurity ISAO Advisory Group member. Their message was simple: The channel is a community too, and it's time to defend like one.
What Is the Current State of Threat Intelligence for MSPs?
When the panel asked the room how often attendees use threat intelligence on a scale of 1 to 5, answers were evenly split, averaging 3.2. Attendees named many sources, including the GTIA ISAO, Reddit, LinkedIn and government cyber portals such as CISA.
Slagle said that range of sources is part of the problem. "MSPs have it pretty hard. On top of trying to take care of our things, we have to take care of all of the things our clients have. And every day the attackers get smarter. We are a tool-heavy industry. I have 46 tools my techs can log into to service my clients. It's insane."
The volume of information makes it harder. "We all try to follow best practices," Slagle said. "But it's hard because information comes from a lot of places. It's very noisy. Every single day there are multiple alerts about multiple software packages." He added: "On top of your day job you have to ingest and deal with this information coming at you. You could spend 10 hours a day trying to keep on top of it."
Meanwhile, the threat keeps shifting. Thordarson described how attack activity rises and falls. "A little over a year and a half ago, we saw a steady increase in cases related to edge devices… In June/July, case volume in the United States dropped by about 50%. Up until the past week, it seems to have spiked again. There's geopolitical dynamics that power this stuff behind the scenes. There are so many vulnerabilities that are currently exploitable."
The result is too many places to look, and one breach to miss. That's the MSP life.
Why Do MSPs Struggle to Act on Threat Intelligence?
The panel named three common gaps.
1. Assuming it won't happen to them. According to Slagle, 80% of MSP breaches come from credential reuse. "As an MSP you are the aggregate risk and aggregate cost of every client under you," he said. "That's a takeaway you should all keep in mind."
Thordarson warned against complacency. "We tend to deal with the known knowns. We recognize there are some known unknowns. But that lulls us into complacency. It's the unknown unknowns that we need to be paranoid about. The bad guys just have to be right on one thing one time and catch us on a bad day."
Westerheim said the stakes reach beyond any one company. "It's reputation damage to the entire industry. If one MSP isn't up to par, that's reputation damage for every one of us."
2. Skills gaps. "If we can't work together to skill up, the government will come in and solve this for us, and it won't be in a way we like," Slagle said. Skinner agreed: "The world has changed. We as MSPs need to look at the things we used to do and how we have to do them differently to address the current and future threat landscape."
3. Weak standardization. The panel's advice was to pick a lane and be very good at it. The fewer tools and platforms you run, the less threat intelligence you have to consume, and the easier it becomes to act on it.
What Does Effective Threat Sharing Look Like?
Good threat sharing is built on six things:
- Trust
- Speed
- Context
- Safe sharing boundaries
- Actionable guidance
- Feedback loops
"We need trust," Skinner said. That trust grows when intelligence is built for the people using it. GTIA ISAO threat reports follow a consistent structure: A brief summary, why it matters, immediate actions and a bottom line. Every report is written for ITSPs and MSPs. "I get three to six of these a day, and they are super valuable," Thordarson said.
That value is significant. "To join IT-ISAC, it's $2,500 minimum to get the same data that's included in your GTIA membership with the ISAO," Slagle said.
Sharing also works in both directions. "Information sharing can go both ways," Skinner said. "As a community it's helpful when you're seeing something that you say something." When members submit what they see, everyone gets a clearer picture faster.
What 5 Steps Can MSPs Take Next Week to Strengthen Threat Intelligence?
The panel closed with five practical steps you can start right away:
- Name an intel owner. Pick one person. Clear ownership keeps the work consistent.
- Create a communications plan. Keep it simple, cover internal and external communications, and print it.
- Log in to the GTIA ISAO. It's already part of your membership.
- Workshop it internally. Decide what you'll do in an incident, then practice it.
- Understand your risk. Know what risk you own from vendors and what you owe your clients if something goes wrong.
"There's a lot of confusion over what to do and who to trust," Westerheim said. "The answer to these problems is the GTIA ISAO."
How Does Threat Sharing Move MSPs from Reactive to Collaborative?
Today:
- Every MSP investigates along
- Hours spent validating alerts
- The same investigation repeated hundreds of times
- Limited visibility
- Vendors hear complaints one at a time
- Lessons stay inside the MSP
With the GTIA ISAO:
- Shared intelligence across trusted peers
- Faster signal with community context
- One investigation benefits everyone
- Broader attack patterns emerge
- Vendors receive coordinated evidence
- The whole community learns together
How Does the GTIA ISAO Help MSPs?
The GTIA ISAO builds trusted sharing, speeds up learning, adds community context, improves shared visibility and coordinates intelligence across the channel. It works best as a force multiplier for the security program you already run. Your SOC, your analysts' judgment and your team's active participation turn shared intelligence into real protection. The more members contribute, the stronger everyone's defense becomes.
The GTIA ISAO includes real-time threat intelligence, a predictive Cyber Risk Rating, vendor risk insights, attack surface monitoring and a peer community. Together, that package is valued at $7,200 a year. Learn more about the $7,200 membership benefit most members don't know they have.
The panel's conclusion: Threat actors aren't the only ones with a community. When the channel comes together and participates in the ISAO, everyone gets better.
Frequently Asked Questions
What is the GTIA ISAO?
The GTIA ISAO is an Information Sharing and Analysis Organization built specifically for the IT channel. It delivers curated threat intelligence, action-focused threat reports and a trusted community for peer-to-peer threat sharing.
Is the GTIA ISAO included with GTIA membership?
Yes. The ISAO is included with every GTIA membership at no additional cost and is valued at $7,200 a year.
What should an MSP do first to improve threat intelligence?
Name one person to own threat intelligence, then sign up for the GTIA ISAO so that person has a single, trusted, channel-specific source to work from.