Real world conflicts, both geopolitical or smaller events can impact your threat landscape. So don't just focus only on cyber events, but have people in your intel team or through a provider also look at events and conflicts that could impact your country/sector/organisation. Following specific activity groups is the best you can do to focus your defences on current threats. Basic security hygiene stays very important. Without a good basic security, you can't build on top of that and are just playing whack-a-mole.