Skip to content

Threat Intelligence as-a-Service: As good or better than D-I-Y?

February 20, 2024 – Published on Cybersecurity Insiders

There was a time when managed security service providers (MSSPs) were perceived as expensive outsourced options to replace or bolster internal security teams with a one-size-fits-all approach. Fortunately, those days are long gone. Now they offer advanced sets of technologies backed up with in-depth expertise, giving access to sophisticated solutions that customers can’t, or don’t want to, manage themselves. Regarded as trusted, knowledgeable partners, increasingly clients have turned to them for advice to solve emerging security concerns.  Many are already benefiting from a wide range of options including firewalls, vulnerability patching, endpoint security, SIEM and identity management.

More recently MSSPs have started adding advanced detection and response capabilities to their portfolios, as well as threat intelligence as-a-service. Not a moment too soon for those facing a barrage of security alerts and trying to pinpoint which ones pose the greatest risk. According to Gartner, security and risk managers struggle to know what threats constitute genuine concerns for their organisation and lack an accurate view of their own threat landscape.

While threat intelligence holds key indicators to identify and pre-empt attacks, sifting through the bewildering array and volume of data to find them is beyond many security teams, especially in smaller organisations. To make matters worse, the data arrives in all kinds of formats from internal and external feeds, such as reports, articles, emails, pdfs and documents. Attempting to assimilate and turn this information into usable format is a mammoth task in itself.

GuidePoint Security’s senior director of digital forensics and incident response and threat intel, Tony Cook, agrees that managing threat intelligence can overwhelm small and medium-sized security teams, saying it typically requires a level of expertise and complex systems that are only practical for large enterprises with specialised threat intel analysts.

Read More HERE.