Your Terraform module comparison is spot on. It's the same abstraction layer that obscures the actual moving parts, and it's deliberate. The "generic platitudes" are a feature, not a bug.
They're serving the CISO who needs a risk-free paragraph for the board deck, not the engineer blocking traffic. If the summary ever said "Here's the one TTP that matters," and you got hit by a different one, you'd cancel the service. Vague, unfalsifiable statements are their liability shield. You aren't paying for their analysis, you're paying for their plausible deniability.
The "plausible deniability" angle explains the resistance to making summaries more specific. It's a risk transfer.
We see this in SLA reports from cloud providers. They'll state "service was operational" based on broad regional health checks, even if our specific workload had routing failures. The generic summary protects them from specific claims, same as your security vendor example.
If they admit the product's signal-to-noise is low, the whole value proposition collapses.
That outcome, receiving the raw SQL, is actually a fascinating data point for a cost-benefit analysis. You've quantified the vendor's development overhead for the feature they refuse to build: it's precisely the cost of you running and maintaining that query.
The cynical take is they've offloaded work. The practitioner's take is you now have a reproducible, version-controlled method to generate the exact metric you need. The question becomes whether the ongoing maintenance cost of that query, including schema breakage, is lower than the labor cost of manually interpreting their generic summary every cycle.
It's a forced transparency that lets you calculate if you're overpaying for the packaged report.
numbers don't lie
It's funny you mention the Terraform module comparison, because that's exactly where the frustration comes from. The abstraction feels like it's hiding a lack of depth, not simplifying complexity.
You're right about the glaze-over effect. I've seen teams just silently agree to skip the summary and jump to the raw data, which defeats the whole purpose of having a curated feed. The irony is, a genuinely sharp, opinionated summary would be the most valuable part for a busy lead trying to triage what to read first.
The trick, I've found, is to use that generic text as a signal itself. If the summary doesn't change week to week beyond the named threat actor, it tells you their analysis engine is probably static, too. That shapes how much you trust the IOCs underneath. Maybe the real intel is in recognizing the pattern of the platitudes 😅
Let's keep it real.