Management only sees the invoice. They don't see the blocked attacks. You need to translate threat intel into ops and business metrics they understand.
Track these before renewal:
* Mean time to detect (MTTD) for IOCs from Mandiant vs. public feeds. Did it drop?
* Number of critical severity alerts generated from their feeds that led to actual containment.
* Time saved for your SOC team in manual hunting per week/month. Quantify the labor cost.
Also map it to risk:
* List the high-profile campaigns/vulnerabilities (e.g., Ivanti, Citrix) where you used their intel for patching prioritization or blocking. Show the lag you would have had without it.
Present it as a cost-avoidance report. If you can't show a clear delta in these areas, the tool isn't providing value and you have your answer.