There's value here in detection of a breach that's already been monetized, but this isn't in the kill chain; it's long-after, so it appears reactive-only. Why should a non-massive company implement this rather than boosting and refining centralized logging and monitoring which can, if done right, provide far more immediate (even real time) notification of a breach? Your Wells Fargos of the world might do it because t…
In terms of why a mid-sized SaaS should go this route - I would like to think that Breach Insider is a slightly more cost-effective option. To do detection and correlation properly, you’re looking at a SIEM with the right logs and hopefully some well formed rules. However at this stage, I’d argue that to get the absolute most out of this, you’re looking at supporting & monitoring this with at least one dedicated employee, else all those logs will be wasted.