Introducing threat intelligence
The Cost of Malware Containment report from the Ponemon Institute (available at www.ponemon.org/news-updates/blog/security/the-cost-of-malware-containment.html) states that the average organization has to look through 17,000 malware alerts each week. Therefore, having a threat intel feed that can notify you of what is happening around you can be very useful!
Put simply, the faster you escalate alerts, the better chance you have of minimizing the attack: having delays to triage can lead to a domino effect, whereby failing in the triage means also failing in the entire operation, which means the IR team has to step in and "recover" assets. By using threat intelligence as your defense system, you will have the ability to scope data based on the adversary. For example, if you are responsible for the defense of a financial institution, focusing on threat intelligence on adversaries that are actively attacking the financial industry will be...