When it comes to the effective use of intelligence, national CSIRTs have unique challenges. Leaving advanced targeted attacks aside, we are left with the task of protecting millions of users and companies facing a variety of threats to their data and money. Obviously threat intelligence plays an important role here but what impact can it make in practice?Over the years we tried multiple approaches to collect relevant intelligence and to make it actionable. Looking back, we will try to identify some things that worked and ones that did not bring substantial results. The main topics will be automated monitoring, practical aspects of information exchange and situational awareness on a country level.