Internal versus external teams
Now that an organization has decided that it is in their best interest to conduct threat hunts, the question to answer is whether they need their own team or whether it would be in their best interest to contract a third party to act as an external team. The answer to that is: well, it depends. The selection of the team will need to be based upon the business decisions that are driven by identified risks, long-term strategy, and regulatory or legal requirements. For some organizations, it is a cost-effective solution to stand up a dedicated internal threat hunt team that only focuses on organizational areas in a systematic fashion. For other organizations, they might want to bring in a team once or twice a year to satisfy a few niche business needs in critical areas only. Neither is a wrong decision. The pros and cons of each type of hunt, the requirements to perform a successful hunt, and the type of hunt that could be conducted will need to be considered...