Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 23 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The role of automation in incident response

by The Gurus
December 10, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

The role of automation in incident response
John Bruce, CEO & co-founder, Resilient Systems
Faster response can make the all the difference when faced with a cyber threat.  Getting there is an emerging priority for cybersecurity professionals, and organisations are still working to develop an expertise and develop best practices. Automation is becoming a trend as organisations see it as a way to become faster – but there are limits on using automation in IR.
One reason organisations struggle with IR is that it differs greatly from prevention and detection – two technology-based processes. With prevention and detection, organisations buy world-class tools to in many instances replace employees from security process as much as possible.
Incident response is a different story.
A key difference in IR is that automation is not the goal – but an accelerator to rapidly achieve the goal of responding intelligently in record time.  Human involvement is critical. The complexity of IR demands human decision-making: once a breach has taken place, the implications move beyond the network into legal ramifications, customer relations, marketing, and even board-level decisions.
Ultimately, it’s the same as physical security. Take airports, for example: prevention and detection is largely managed by technology such as metal detectors – but if there is an incident, emergency response is always coordinated and controlled by people, with technology playing a complementary role.
When creating IR procedures, automation is a tool. It needs to be deployed thoughtfully and carefully to speed and enrich the human response – not replace it. There are four components of incident response – preparation, assessment, management, and mitigation – and, when used appropriately, automation can play a critical role in each phase.
Preparation
Effective response requires provisioning for and preparing IR processes long before an incident occurs. Businesses should build out and document IR processes (playbooks), practice response, and orchestrate the process to measure and improve response performance.
It’s also the time to build out – and, over time, increase – automation capabilities. Organisations should start simply by automating incident creation or data collection, and test these functions over and over until they’re sure the automated systems will work as desired every time. Look at the data you’re collecting. Can you do it faster or smarter?
Assessment
Context is key in incident response. But for many, gathering insight about an incident involves logging into countless individual systems – a SIEM, networking monitor, or other source – extrapolating data in multiple formats, and compiling it into one report. It’s a tedious and inefficient process – but one that can be automated. Leveraging emerging technologies will empower security teams to integrate and interface with these various tools quickly and compile information on specific incidents can dramatically enhance IR speed and effectiveness.
Management
Incident response stretches across business functions – from IT and security, to legal, HR, marketing, and the C-suite. Ensuring everyone’s in the right place at the right time and knows precisely what to do is critical.
Thankfully, this task management and coordination can also be automated to a certain extent as systems can recognise a familiar threat and automatically launch response workflows. When dealing with substantial threats, the automation process can pass the decision to humans who decide how best to act.
Mitigation
Finally, this is where the human factor is irreplaceable. Automation can be helpful in increasing the speed and effectiveness of response – but it’s still human decision-making that’s most critical. IR teams can automate the process of quarantining infected machines, profiling targets, or blocking malicious IPs (and many mature IR teams do) – but it requires the human mind to put it all in context, grasping the environment, complex controls, and extensive testing to ensure that automated processes don’t inadvertently harm your business.
The nature of incident response means that it is not a wholly technological process – the best practice for incident response is to align people, process, and technology. IR teams must work to ensure that automation processes are trust-worthy and enriching human decision-making, not designing them out.

FacebookTweetLinkedIn
ShareTweetShare
Previous Post

Global survey by Gemalto reveals impact of data breaches on customer loyalty

Next Post

Air Canada, San Diego Zoo and easyJet* exposed customers’ credit card details

Recent News

Blue logo, capitalised letters. SPECOPS.

Fortune 500 Company Names Found in Compromised Password Data

March 23, 2023
Ferrari Data Breach: The Industry has its say

Ferrari Data Breach: The Industry has its say

March 22, 2023
security

What Is Observability, And Why Is It Crucial To Your Business?

March 21, 2023
Organisational Cybersecurity.jpg

How Emerging Trends in Virtual Reality Impact Cybersecurity

March 21, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information