Defending at machine speed.
WHY IT IS NECESSARY
Attacks are automated, and manual response cannot match their speed or volume.
WHAT TO AUTOMATE FIRST
Collection and correlation of signals
Enrichment: adding context to an alert
Triage: classifying and prioritising
Containment of clearly malicious activity
WHY ENRICHMENT MATTERS MOST
Analysts spend most of their time gathering context, and automating that multiplies their capacity.
WHAT ORCHESTRATION PROVIDES
Defined response workflows, executed automatically or with approval.
WHAT TO AUTOMATE CAUTIOUSLY
Anything disruptive: isolating machines, disabling accounts, blocking addresses.
WHY
A false positive automatically isolating production causes the outage the attacker wanted.
WHAT TO REQUIRE FOR THOSE
Approval, or very high confidence.
WHAT TO MEASURE
Time to detect Time to contain Proportion of alerts handled automatically False positive rate
WHAT ALERT FATIGUE CAUSES
Genuine incidents missed among noise.
WHAT REDUCES IT
Better correlation, suppression of known-benign patterns, and tuning.
WHAT TO NEVER AUTOMATE
Decisions with serious consequences and low confidence.
WHAT TO DOCUMENT
Every automated action, and who could override it.