Does your organisation have a formalised threat hunting programme? If so - what were the key drivers for you in setting one up and what made it successful? If not - what is stopping you from setting this up?

695 viewscircle icon2 Comments
Sort by:
CISO in Software3 months ago

The first question to ask is whether you are ready with the data lake, resources and time to invest in this space.  Not all companies can make this investment internally and are often best working with an external provider to explore this space as a project.

Chief of Information Security in Energy and Utilities3 months ago

If you have an IR retainer, I'd evaluate their threat hunting service. This usually provides 24/7 threat hunting at the cost of 1-2 FTE (e.g., CrowdStrike Overwatch). If you wish to build your team, consider your ability to attract and retain skilled staff while providing 24/7 coverage.

Content you might like

Ease of getting my data into the DAaaS platform9%

Tools that make it easy to create use cases with the DAaaS platform40%

A pre-existing library of dashboards and report templates to help me quickly get up-and-running28%

The ability to try out the DAaaS platform for free before buying13%

Services from the DAaaS vendor (consulting, support, training)3%

Confidence that my data is safe in the cloud4%

View Results

Yes - I can't wait to see my coworkers. It will help with my day-to-day job role.73%

No - I like the established routine I made during the COVID-19 pandemic and I'm not interested in changing that.26%