How can security leaders in smaller organizations stay informed about emerging threats if they don’t have access to formal threat intelligence feeds?

1.9k viewscircle icon8 Comments
Sort by:
Director of Information Security7 hours ago

As others have mentioned - reports from CISA (or your local equivalent) are free and useful. Join an industry forum so that you can share information and observations.

Have a Threat Profile prepared for your organisation and updated periodically.

I also want to point out, don't lose sight of the fundamentals. Inventories, Patching (particularly the edge) and hardening, Monitoring, ability to Respond & Recover. The majority of cyber threats are still hindered by getting the basics covered.

CISO2 months ago

Most strategic threat intelligence relevant to planning is published for free by most threat intelligence shops, you don't need feeds for this. You might want to ask someone to compile you relevant things once a quartner/annually.

Head, Software Engineering, Cloud and Digital Transformation2 months ago

One way is to subscribe to some of newsfeed such as:
https://www.infosecurity-magazine.com/
https://www.bleepingcomputer.com/
https://www.cisa.gov/news-events/cybersecurity-advisories

Microsoft has good blog site as well at https://www.microsoft.com/en-us/security/blog/ which has a section on Threat Intelligence and Security Insider.

Attend Black Hat conference if possible. Hope this helps.

Chief Information Security Officer2 months ago

There is an easy way to answer this question: Subscribe to CISA's threat advisory service (for free). Their threat analysis is world class and yet, remarkably easy to interpret. Link here: https://www.cisa.gov/news-events/cybersecurity-advisories?f%5B0%5D=advisory_type%3A94

Lightbulb on1
Chief Information Security Officer3 months ago

When you run a startup, creativity is essential. AI is great for that. With the right prompt, it’s amazing how it can process information and deliver exactly what you need.

Content you might like

Key management system or certificate life cycle management 10%

Network security appliance 50%

Custom/proprietary solution 20%

App security posture management (ASPM) tool 50%

Cryptographic posture management tool 10%

Something else

N/A

View Results

Very confident14%

Confident – there could be some shadow AI but I doubt it49%

Sort of confident – some shadow AI, but aware of the important stuff28%

Not confident – still trying to determine extent of GenAI use8%

View Results
How can security leaders in smaller organizations stay informed about emerging threats if they don’t have access to formal threat intelligence feeds? | Gartner Peer Community