Although there are many modes of attacks, attacks should be categorized and divided into groups. Hackers generally look for vulnerabilities and weaknesses 24/7. Although most hackers are enthusiast wanting to adventure out on the net and find weaknesses and to 'see' what they can do, their intentions are not always malicious. These individuals can post the 'how they' broke in to a database or company for bragging rights and not realize malicious individuals are gaining valuable knowledge on 'how to' break in to the same corporation.
Given this information, security analyst and network administrators should research the 'web' as a whole scouring the web for any information that may be posted about their company. Part of the IT department's training should be a treasure hunt of looking for their company and the company's IP address range out on the net. Training should include IRC and other chat rooms / areas on the internet.
The United States often listens for 'static' through multiple communication channels trying to find terrorists. This same methodology should be used to gain intelligence on weaknesses and potential hackers that are targeting / or who have targeted their company. This intelligence should be gathered and analyzed to see what can be done to protect their assets.
When the aforesaid information technology professionals 'think' they have gotten all vulnerabilities fixed or patched, there are ALWAYS individuals out on the web who can out think and find items that have been overlooked. These analysts should think 'outside of the box' in order to protect their information.