Threat Landscape
Updated July 21, 2026
The full picture of external risks and competitive forces acting on a business.
Also known as: competitive threat landscape
The threat landscape is the set of external risks and competitive forces that could erode a company's position if left unaddressed. It is the catalog of what might go wrong on the outside, regardless of how well the inside is run. Unlike a competitor list, it is concerned with categories of pressure: who might enter, what might substitute, where adjacent platforms might absorb the category, which regulatory or pricing-model shifts change the rules, and how talent flows redistribute capability. Strategists and competitive intelligence teams use it as the input layer for scenario planning, early-warning work, and defensive investment decisions, the picture that tells leadership which threats are worth hedging against before they show up as quarterly misses.
The term originated in cybersecurity and remains well-established there. NIST defines a threat as any circumstance or event with the potential to adversely impact organizational operations, assets, or individuals, and agencies such as ENISA publish recurring Threat Landscape reports that enumerate and rank active threat categories year over year. The competitive-intelligence usage borrows the metaphor without claiming a parallel analytical tradition: a competitive threat landscape describes which external forces are pressing on the business, in the same shape that a cyber threat landscape describes which adversary behaviors are pressing on a network. The borrowing is honest about being a borrowing: there is no equivalent ISO standard or consulting-authored origin for the business sense.
Today the term is used by product marketers, strategy teams, and CI practitioners to frame what they monitor for. A B2B SaaS threat landscape typically tracks emerging entrants, adjacent platform risk (the big-platform absorption scenario), substitutes, regulatory shifts, macro pricing-model shifts, talent flow patterns, and AI-driven platform substitution. The discipline is what separates watching named competitors from watching everything that could make those competitors a footnote.
Threat landscape versus competitive landscape
The competitive landscape is the set of rivals: who they are, what they sell, and where they are positioned. The threat landscape is the set of risks: forces that could displace the company regardless of how any single competitor performs. A competitive landscape listing might identify five named vendors and their market share; a threat landscape listing might include an adjacent platform preparing to bundle into the category for free, a regulatory change that invalidates one pricing model, and two engineers whose departure from a rival to a hyperscaler could shift that rival's roadmap.
The two overlap but answer different questions. The competitive landscape asks who the company competes with today; the threat landscape asks what could hurt the company that it is not yet framing as competition. Mapping one without the other leaves a gap: strong rivals with no broader pressure behind them are a different problem than weak rivals with structural pressure behind them.
The dimensions a B2B SaaS threat landscape tracks
For a B2B SaaS business, the threat landscape is rarely just named competitors. Practical dimensions include emerging entrants (newly funded vendors entering the category), adjacent platform risk (a hyperscaler or platform incumbent absorbing the category into a bundled offering), substitutes (different product forms that solve the same job), regulatory shifts (data residency, AI disclosure, or licensing rules that change cost structure), macro pricing-model shifts (per-seat to usage-based, or one-time to subscription), talent flow patterns (where category expertise is migrating), and AI platform substitution (a foundation-model capability that collapses a wedge feature into a commodity).
Each dimension is monitored differently. Some show up in funding and product announcements, some in regulatory filings, some in job posting patterns, some in competitor pricing page changes. The point of the landscape is to make those dimensions explicit so each is owned, rather than left to whoever happens to notice.
How CI teams operationalize the landscape
A CI team turns the landscape into deliberate monitoring by assigning each dimension an indicator set (competitor pricing pages, new-entrant press releases, regulatory filings, executive moves, hiring velocity) and a refresh cadence. Outputs typically feed three downstream artifacts: an early-warning register of weak signals that have not yet crossed into confirmed trend, a quarterly landscape briefing for leadership, and ad-hoc flags when an indicator crosses a threshold, such as a Tier-1 rival launching a usage-based tier or a hyperscaler hiring three of a competitor's category leads.
The landscape also disciplines prioritization. When every dimension has an owner and a recent reading, leadership can argue from evidence rather than from anecdotes about the most recent sales loss. It also gives monitoring a stopping rule: signals outside the agreed dimensions are deferred, which keeps the team from chasing noise.
Common mistakes and limitations
The most common mistake is conflating the threat landscape with a competitor list, and therefore filling it with named rivals rather than categories of pressure. A landscape populated entirely with logos misses platform absorption, regulation, and pricing-model substitution, exactly the forces that have historically displaced SaaS categories. The second mistake is overconfidence in scoring: assigning high, medium, or low to each dimension without agreeing on the indicators lets the exercise collapse back into opinion.
A third mistake is treating the landscape as static. The cyber threat landscape is refreshed annually for good reason, and competitive threat landscapes in most SaaS categories move faster than that. The metaphor also has limits: unlike in cybersecurity, there is no shared methodology equivalent to ENISA's and no published taxonomy of threat actor behaviors, so each team defines its own dimensions. The cross-language with cyber is borrowed, not standardized.
Stop looking terms up. Start tracking them.
meertrack watches your competitors' websites, pricing, and hiring, then alerts you when something meaningful changes.
Frequently Asked Questions
What is a threat landscape?
It covers the external risks and competitive pressures that could weaken a company's standing over time. For a B2B SaaS business, those typically span emerging entrants, platform absorption by an adjacent incumbent, substitutes, regulatory and pricing-model shifts, talent movement, and AI-driven platform substitution. Unlike a competitor list, it is organized by category of pressure rather than by named rival.
Threat landscape vs. competitive landscape: what is the difference?
A competitive landscape enumerates the rivals a company faces today: who they are, what they sell, and where they are positioned. A threat landscape enumerates the categories of pressure that could hurt the business, including ones that are not yet rivals, such as platform absorption, regulatory shifts, pricing-model change, and substitutes. The first answers who the company competes with; the second answers what could displace it.
Where did the term threat landscape come from?
The phrase comes from cybersecurity, where it is well-established. NIST characterizes a threat as any event or circumstance that could adversely affect operations, assets, or people, and ENISA publishes recurring Threat Landscape reports that rank active cyber threat categories. Competitive intelligence borrowed the metaphor without an equivalent standardized methodology behind the business sense.
How is the threat landscape different from the attack surface?
The attack surface is the company's own exposure: the points where an adversary could act. The threat landscape is the external environment: the adversaries, pressures, and forces that exist regardless of the company's defenses. The same distinction holds in competitive intelligence: the attack surface is what the company exposes; the threat landscape is what is out there.
Who uses a threat landscape?
Strategy teams, product marketers, and competitive intelligence practitioners use it to frame monitoring and prioritization. Leadership uses the resulting briefing to decide where to hedge, such as investing against platform absorption or adjusting pricing before a model shift lands. Sales and customer success teams use downstream flags to defend renewals against emerging pressure.
Related terms
In CI context, the market segments, customer bases, or product areas where a competitor could threaten your business.
Threat Actor ProfilingBuilding a behavioral model of a specific competitor (their patterns, decision cadence, resource allocation) to predict future moves.
Competitive LandscapeA structured overview of all relevant competitors in a market, their relative positions, strengths, weaknesses, and strategic trajectories.
Weak SignalAn early, ambiguous indicator of a potentially significant future change. Requires pattern recognition across multiple data points.
Strategic Early Warning (SEW)A methodology for detecting weak signals that indicate emerging competitive threats or market shifts before they become obvious. The proactive, forward-looking edge of CI.
Switching Cost AnalysisEvaluating how difficult it is for customers to move between competitors, considering data portability, integrations, training, and contracts.
Time-Series AnalysisTracking a metric (pricing, headcount, rankings) over time to identify trends, seasonality, and inflection points.
AttributionConnecting an observed competitive action back to its strategic intent or root cause.