Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The Journey to Security Automation

by The Gurus
June 1, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

The complexity and breadth of the threat landscape is evolving at a tremendous rate, such that the security industry cannot keep up with the skills demands this is creating, leaving organisations vulnerable to a widening skills shortage. It’s time to start thinking about the solution. Automation and intent-based security are becoming more timely discussions when considering the future and how to get there. The term ‘Intent-based security’ refers to the process of applying analytics to the information generated by security devices on a network. Individual security solutions are already able to deliver vast amounts of independent, unrelated data. We can begin to bring this generated information together as we build out homogenous, interconnected security frameworks. This integration is the trick to achieving intent-based security as security teams are able to reduce these informatics into manageable amounts. This in turn allows us to automatically refine security in real-time as our network and threat landscapes change. But why is automation so important for cybersecurity and the wider business? And how can we get to where we need to be in order to reap the benefits?
From the perspective of the business owner or the person responsible for security policy, it’s important to be able to simply define or update business intent. The security policy and related infrastructure needs to understand that information and implement a reasonable and appropriate response. Security policies should automatically limit systems to just the information and services that they should have access to. This will require more exact network designs in order to reduce the challenge this poses.
Another perspective when it comes to intent-based security involves rethinking how we solve the security problem.  A key factor in creating a joined up and responsive security framework is to implement security tools that can automatically evaluate and determine if a system is performing activities that are normal or intended. This is why there’s an emerging set of security practices referred to as intent-based. Again, a simplified description of an approach like this is that it is able to report and automatically respond to whether or not the system is doing things that are intended by that user on that system or not.
An intent-based system in the context of automation
The main motivation for organisations to embrace automation and intent-based security is to reduce costs, complexity, and errors. For businesses, the Lean movement is all about maximising customer value while minimising waste. For IT, the motivation is to reduce operational expenses and allow them to faster respond to threats and actual breaches.
Automation empowers IT teams to implement proactive actions which enable the network to adapt to demands instantaneously. This enables a form of self-service for both the end user and IT teams. Automation can then become the foundation for the next step, which is an intent-based system which can learn from reflexive actions and can minimise the need for human intervention.
Goals for automation
Automation is a building block. Much like training a guard dog, the system needs to understand what is normal, interpret when something unexpected happens, and then decide on the best course of action.
The next step is to use data to inform this process. By feeding in data based on what we know about the outside world, how our networks should operate, and what has taken place before that is vital. This set of constantly updated data will drive which decisions are made, which brings ‘intelligence’ into automation.
Without the standardisation of the interactions between technologies the system won’t function.  By implementing an integrated security framework, which is an architectural framework built around open APIs, organisations can cover off many of the touchpoints which need to be standardised.
What will it take to get where we need to be?

  1. Logging–  Data collection needs to be fixed to a standard that allows everyone to collect and analyse data efficiently. This should include features that allow the application of extensions in a simple, self-documenting and self-supporting manner.
  2. Threat-Intelligence– This doesn’t relate to just the data that we are producing ourselves, but also the data about the wider world around us. For a system to become self-aware, it’s vital to be able to differentiate between itself and other. This is where threat intelligence comes in. This intelligence must be provided in a standardised format, allowing it to be correlated, processed and acted on.
  3. Open Development– Standardised APIs need to be adopted and expanded into everything, not just the many types of interactions between data and devices, but also the interactions between architectures. If a security system is capable of firewalling, how can it be interacted with in order to empower, restrict, or enhance its behaviour based on real time events and data?  Abstraction can always be used to bring about this kind of standardisation, much like with DevOps.
  4. Authentication– Open architectures must have the ability to identify themselves and others, identify and share critical information, and catalogue things properly in order to safeguard them. This is essential for both nomenclature and taxonomy.  For different technologies to work together, it’s imperative that they speak the same language.

By Shane Grennan, Director, UK&I, Fortinet

Tags: automationcomplexityCybersecurityTechnology
ShareTweet
Previous Post

Cylance Delivers First AI-driven Endpoint Detection and Response Solution with Introduction of CylanceOPTICS

Next Post

Boards still not grasping cyber threats, say IT decision makers

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol