Tl;dr
The gap between what exists and what appears in public feeds is where attacks get their headstart.
Security teams have never had more data. DNS records, certificate logs, threat feeds, search results, social platforms, app stores and public reporting all produce a steady stream of things to investigate. On a busy day, it can feel less like intelligence and more like weather.
The volume creates a dangerous illusion: If a threat exists, surely it will appear somewhere we already monitor.
Unfortunately, threat actors are not required to publish a complete asset inventory. That would be considerate. It is not their style.
They use redirect chains, geofencing, cloaking, compromised accounts, private messages, malicious ads, SMS, phone numbers and short-lived infrastructure to keep attacks outside the obvious line of sight. The attack is real. The public trail may be faint, delayed or deliberately misleading.
The visibility gap
The gap between what exists and what appears in your feeds is where attacks get their head start.
OSINT is the baseline, not the edge
Open-source intelligence is indispensable. It helps defenders map infrastructure, enrich indicators, follow campaigns and investigate unfamiliar activity. Every serious security program should use it. Netcraft does.
But public data has a built-in ceiling: it is public. Your peers can access it. Your suppliers can access it. Your competitors can access it. Often, the people running the attack can access it too.
That makes OSINT excellent common ground and weak differentiation. If every provider starts from the same feeds, the meaningful questions are what else they can see, how quickly they can verify it and whether the intelligence is strong enough to produce action.
A public feed may show a newly registered domain. It will not necessarily show the phishing email delivered to a closed abuse mailbox, the redirect path visible only from a particular geography, the fake support conversation happening in a private channel or the relationship between a fresh lure and infrastructure used in an earlier campaign.
Those are not exotic edge cases. They are the places attackers go when the well-lit routes become inconvenient.
Two-thirds of the work happens past the public record
The term “proprietary data” can sound like a locked filing cabinet full of secret indicators. The useful version is more operational than that. It is intelligence produced by systems, relationships and communities that improve because they are used.
For Netcraft, that includes cybercrime reports from a global reporting community, spam and abuse reporting ecosystems, large-scale internet telemetry, private intelligence collection, historical classifications, provider feedback and a global proxy infrastructure built to reach threats that do not present the same way to every visitor.
In a 2026 internal analysis, 64% of Netcraft takedowns and disruptions leveraged proprietary data. Almost two-thirds of those actions drew on information that an OSINT-only approach would not have supplied on its own.
It is worth being precise about what that number does and does not say. It does not say public data is useless. In the remaining third, open sources were enough, which is exactly what a working ecosystem should look like. What it says is that most of the time they were not enough, and that a provider operating only from shared feeds would have reached those threats late, or not at all.
That matters because discovery time is exposure time, and exposure is front-loaded. Netcraft's published analysis of phishing victim traffic found that more than 95% of victim visits have already happened within 20 hours of a threat being detected. Against that curve, a takedown standard measured in days is not a slower version of the same outcome. It is a different outcome, arrived at after the harm.
A missed phishing site is not a tidy reporting problem. It is still collecting credentials. A fake social profile is still speaking to customers. A scam phone number is still ringing.
An alert without evidence is mostly a notification
Finding a suspicious asset is only the first engineering problem. The next is proving what it is.
Attackers routinely show different content by location, device, referral path or time of day. They add CAPTCHA gates and redirect chains. They hide the final page behind several disposable domains. A detection system may have the correct URL and still fail to load the attack.
That failure has consequences. If you cannot reproduce the malicious behavior, you may not be able to collect the screenshots, redirects, hosting details and other evidence an infrastructure provider needs before it will act. The alert can be right and still be operationally useless.
The opposite failure carries a cost too. Registrars, hosts and platforms move fast on submissions from reporters they trust, and that trust is built by being right, repeatedly, at volume. Netcraft's published false positive rate is 0.02%. Accuracy is not a quality metric sitting off to one side of the workflow. It is the thing that keeps the queue moving.
This is why visibility and disruption should not be treated as separate product categories. The real chain is continuous: find the threat, reach it, classify it, capture defensible evidence, identify who can act, submit through the right channel, monitor the response and re-engage if the attack returns.
Compromise any link and the threat stays online.
More feeds are not the same as more sight
Security buyers are often shown a long list of data sources. Lists are comforting. They look comprehensive. They are also easy to copy.
The better test is whether the intelligence changes the outcome. Did it surface a threat the customer had not reported? Did it expose the full redirect chain rather than only the lure? Did it reveal related infrastructure across domains, social accounts, apps or phone numbers? Did it produce evidence a registrar, host or platform could use? Did it shorten the time people were exposed?
Those questions connect collection to consequence. They also make it harder to hide a monitoring service inside a disruption claim.
At Netcraft, detection and takedown have been built as one system rather than two products joined at the reporting layer, and the internet monitoring underneath them goes back nearly three decades. Publicly documented capabilities include headless browser analysis, proxy network intelligence, redirect-chain tracking, automated evidence collection and provider communication. The current median phishing takedown time is measured in minutes. That speed is not produced by a single feed or a clever model. It is the compound effect of data, classification, evidence, automation and relationships working together.
What security leaders should ask
When evaluating external threat intelligence or digital risk protection, the useful questions are the ones that reveal where a provider's field of view ends and what it expects your team to absorb:
What proportion of confirmed threats comes from sources that are not broadly purchasable or publicly queryable?
How often are threats found before a customer or a victim reports them?
Can the system reach cloaked, geofenced and redirect-heavy attacks from multiple locations and devices?
What evidence is captured automatically, and is it sufficient for a provider to act without avoidable back and forth?
Where does the coverage end, and what is handed back to your team to handle?
None of these asks for perfect visibility. That does not exist, and a provider claiming otherwise is telling you something useful about how it answers harder questions. They ask whether the provider has built a durable advantage in finding threats earlier and turning what it finds into less exposure.
A longer version of these questions, with notes on what a strong answer includes and what should prompt a follow-up, is available as a separate checklist.
The useful map is the one that leads to action
The public internet is a valuable map. It is not the territory.
Defenders need OSINT because shared visibility makes the whole ecosystem stronger. They need proprietary intelligence because attackers operate in the gaps between shared sources. And they need evidence because intelligence that cannot support action is only an interesting observation.
The objective is not to collect the most data or produce the most alerts. It is to see the threats that matter while there is still time to change the outcome, then remove the infrastructure that gives those threats somewhere to operate.
That is the difference between knowing the internet is hostile and making it a less hospitable place to attack your customers.
What is the difference between OSINT and proprietary threat intelligence?
Open-source intelligence (OSINT) comes from publicly available sources such as DNS records, certificate transparency logs, search results, and threat feeds. Proprietary threat intelligence includes intelligence gathered through private reporting networks, internet telemetry, historical threat data, specialized infrastructure, and other sources that are not publicly accessible. Together, they provide broader visibility into emerging cyber threats.
Why isn't OSINT alone enough to detect modern cyber threats?
Many threats operate outside publicly visible channels. Attackers frequently use geofencing, cloaking, redirect chains, private messaging platforms, SMS campaigns, and short-lived infrastructure that may never appear in public datasets. As a result, organizations relying solely on OSINT may discover threats later than attackers intend.
What is the visibility gap in cybersecurity?
The visibility gap is the difference between threats that exist and threats that appear in publicly accessible feeds or monitoring tools. Attackers often exploit this gap to operate undetected before security teams can identify and remove malicious infrastructure.
How do attackers hide phishing websites from security teams?
Cybercriminals may use cloaking, geofencing, CAPTCHA gates, redirect chains, and device-specific content delivery to prevent researchers and automated tools from viewing malicious content. This can make phishing sites difficult to verify and disrupt.
Why is evidence important for phishing takedowns?
Finding a suspicious website is only the first step. Hosting providers, registrars, platforms, and infrastructure operators often require clear evidence of malicious activity before taking action. Screenshots, redirect paths, hosting information, and threat classifications help accelerate remediation.



