How can security leaders in smaller organizations stay informed about emerging threats if they don’t have access to formal threat intelligence feeds?

3.4k viewscircle icon10 Comments
Sort by:
CISO in Bankinga month ago

CISA, BleepingComputer.com, Dark Reading, Krebs on Security, join a low-cost information sharing organization specific to your industry.

Director of Operations in Constructiona month ago

Like others have mentioned, smaller organizations can stay informed by leveraging free community threat-intelligence sources, industry forums, and information-sharing groups. With the help of AI platforms and well-crafted prompts, it’s also possible to quickly access the latest insights on the threat landscape.

US-CERT / CISA Alerts – free, high-quality advisories on active threats and vulnerabilities
SANS Internet Storm Center (ISC) – daily threat diaries, honeypot data, and analysis
Public forums such as Reddit communities (r/netsec, r/cybersecurity, r/blueteamsec) that offer active discussions on emerging threats"

Director of Information Securitya month ago

As others have mentioned - reports from CISA (or your local equivalent) are free and useful. Join an industry forum so that you can share information and observations.

Have a Threat Profile prepared for your organisation and updated periodically.

I also want to point out, don't lose sight of the fundamentals. Inventories, Patching (particularly the edge) and hardening, Monitoring, ability to Respond & Recover. The majority of cyber threats are still hindered by getting the basics covered.

CISO4 months ago

Most strategic threat intelligence relevant to planning is published for free by most threat intelligence shops, you don't need feeds for this. You might want to ask someone to compile you relevant things once a quartner/annually.

Head, Software Engineering, Cloud and Digital Transformation4 months ago

One way is to subscribe to some of newsfeed such as:
https://www.infosecurity-magazine.com/
https://www.bleepingcomputer.com/
https://www.cisa.gov/news-events/cybersecurity-advisories

Microsoft has good blog site as well at https://www.microsoft.com/en-us/security/blog/ which has a section on Threat Intelligence and Security Insider.

Attend Black Hat conference if possible. Hope this helps.

Content you might like

Cybersecurity Concerns: Protecting sensitive data and systems from evolving threats.25%

Digital Transformation: Ensuring a smooth transition to a digital-first strategy.41%

Talent Shortage: Finding and retaining top IT talent in a competitive market.27%

Compliance and Regulations: Navigating complex compliance requirements.6%

System Downtime: Minimizing the risk of unplanned outages and disruptions.1%

Something Else - Please elaborate if possible

View Results

Skills development43%

Networking opportunities63%

Research emerging tech35%

Other (list your justification in the comments)2%

View Results