Regulatory requirements, legalities, and best practices – where to start…
While threat hunting is one of the best ways to identify malicious activity with a high return on investment for an organization, there are many other reasons to employ this style of cyber defense in an enterprise. One of the biggest drives for an organization to do this is when organizational leadership says we have to. Yes, but why? Has the organization established its own internal standards or policies that state how often and why it would employ this method of cyber defense? If so, then it would be entirely internally driven and an internal business decision on whether or not to continue to follow that policy. All of the external causes for building a threat hunting team require the same thing: due diligence. While standards, laws, or insurance contracts won't directly say that an organization must "stand up a cyber threat hunting team", they will say things such as implement...