This talk will provide a look at intelligence-driven defensive operations. The Cyber Kill Chain as a model to dissect the stages of increasingly advanced cyber intrusions will be touched on. Then will elaborate the detective and preventive measures taken to ensure that an adversary is unable to set up residence in the environment. It will discuss about changing the mindset from “incident response” to “continuous detection and response”, and the drivers behind this transformation and what you need to know to enable proactive defense at your organization. It will also walk through the F3EAD process to show how threat intelligence can be included into the incident response procedure.