A note on sourcing. This guide is not a measurement of ours. Where it describes an incident, it describes what named organisations publicly reported, and says who reported it. That distinction matters more here than anywhere else in this series, because prevention claims are the least verifiable statements in security.

Threat intelligence is sold on the promise of early warning: know sooner, and the attack won't land. It's a reasonable pitch, but nearly impossible to audit. The evidence for a prevented attack is an absence, and an absence can be explained in many ways.

The measurement problem, stated plainly

If an organisation acts on a warning and is not subsequently breached, at least four things could be true:

  • The warning was accurate, the action was effective, and an attack was stopped
  • The warning was accurate, but nobody attacked them anyway
  • An attack occurred, succeeded, and has not been detected
  • The action was irrelevant and something else prevented the outcome

From the inside, all four look identical. "We prevented an attack" is therefore among the hardest claims in the field to substantiate — and among the easiest to make, which is why it appears in so much marketing. A security programme with no incidents may be excellent or may be blind, and the organisation itself often cannot tell.

This is not an argument against early warning. It is an argument for reading prevention claims structurally: who is asserting it, what would they have observed, and what would the world look like if they were wrong?

What early warning has demonstrably done

The strongest cases for prevention share a feature: enough time passes between the warning and the attack for a causal chain to appear in the public record.

MS17-010 and WannaCry, 2017. Microsoft published a patch for the SMB vulnerability in March 2017. WannaCry propagated using that vulnerability in May 2017, roughly two months later, and the difference between organisations that were disrupted and those that were not corresponded closely to whether the patch had been applied. This is about as clean as the public record gets, and the warning was not intelligence in any exotic sense — it was a vendor patch, published openly, with two months of lead time.

Log4Shell, December 2021. The vulnerability in Log4j was disclosed publicly and added to CISA's confirmed-exploited catalogue almost immediately, triggering one of the largest coordinated patching efforts on record. What makes it instructive is not that the response was fast but that the warning was universal — every organisation received it at the same moment, which turned the outcome into a test of capacity to act rather than access to information.

Industroyer2, April 2022. ESET and Ukraine's CERT-UA jointly reported that they had identified and disrupted malware targeting Ukrainian electrical substations before it executed its intended function. This is the closest thing the public record has to a documented case of intelligence-driven prevention in a conflict setting — and it should be read as what those two organisations reported, because independent verification of an averted outcome is, by the logic above, not available.

Advisory campaigns. CISA's "Shields Up" campaign in early 2022 raised readiness across US critical infrastructure around the invasion of Ukraine. Its effect is unmeasurable in the sense described above. It is included here as an example of the category, not as a claim about outcomes.

The measured part: warning is rarely what was missing

Here is where our own measurement bears on the question. Of the vulnerabilities CISA has confirmed as exploited in the wild, 54.6% are five years old or more.

Sit with that. In the substantial majority of cases where a vulnerability is being actively used against real organisations, the vulnerability — and its patch — had been public for over half a decade.

The warning was not late. The warning was years early, freely available, and machine-readable. What was missing was action: an inventory to match it against, a maintenance window, an owner, a budget line, or an organisation that could tolerate the downtime of patching.

This is an inconvenient fact for anyone selling early warning. For most organisations, most of the time, the constraint is not knowing sooner. It is doing anything at all with what is already known.

How to read a prevention claim

To separate a substantiated account from a press release, ask four questions.

  • Is there a described artefact? Malware identified, infrastructure named, a technique documented. A claim with no observable is not a finding.
  • Who observed it, and what could they see? A vendor sees its own telemetry; a national CERT sees what constituents report. Both are partial in known ways.
  • Is prevention being claimed, or interruption? "We found and removed this before it ran" is a much stronger and more checkable statement than "we prevented an attack".
  • Would the claimant know if they were wrong? If an undetected success and a prevention look the same from where they sit, the claim rests on their detection quality, not on the outcome.

The 54.6% also reframes the market. Who sells threat intelligence maps the categories of provider, and the sequence it recommends starts with an inventory rather than a subscription for precisely this reason.

What this means for the "cyberwarfare" framing

The phrase does real damage to clear thinking, because it implies discrete engagements with winners. What the public record supports is quieter and less satisfying: sustained, continuous intrusion attempts against infrastructure across many countries, occasionally surfacing as a publicly reported incident, mostly not surfacing at all.

In that setting, "stopped" is the wrong unit of analysis. Attacks are not won or lost so much as made more expensive, slower, and more likely to be noticed. Early warning can contribute to all three, but it doesn't produce a countable number of prevented catastrophes.

The organisations that seem to do best have the capacity to act on ordinary intelligence quickly, not access to the most exotic intelligence. This brings the answer back to the 54.6% and the unglamorous work of knowing what you run and being able to change it.

What we are not claiming

We have not independently verified any incident described above; each is attributed to the organisations that reported it, and the public record on contested intrusions is frequently revised. Attribution of state-sponsored activity in particular is a judgement made by parties with partial visibility and, sometimes, political interests — the distance between "this matches a documented pattern" and "country X did this" is covered in what a threat actor name buys you.

The 54.6% figure is ours, measured from CISA's published catalogue on 19 August 2026, and the script is in our repository. It is the only number in this guide we can stand behind directly, which is itself the point.