Threat Intelligence is a subsection of cybersecurity. It can help organizations to understand threats, protect the systems or even respond faster to new threats. Threat Intelligence can become a precious solutions for many operational activities.
For a SOC team, valuable threat intelligence feeds allow to place relevant filters or rules to detect attacks and protect IT.
For an analyst team, a TIP (Threat Intelligence Portal) allows to investigate around attacker modus operandi and make sure the internal tactics can deal with that.
For Incident Response Teams, the ability to transform incident into indicators and share associated events to a constituency is a key value for information sharing at the company level.
For a risk manager, the association between attackers and target sector is a new way to include technological risks into a larger risk management system.
For a security manager, a threat intelligence program with dedicated tools is a way to optimize the priorities and the budget allocation where it's really useful.
With it's ability to handle from technical to strategic aspects, threat intelligence is a real join-the-dots tool for an organization. CyberSecurity does not make really sense if it does not integrate threat intelligence inputs.