How Does Cydarm Improve Incident Response?

TL;DR
Cydarm improves cybersecurity incident response by replacing manual ticket creation, copying, data entry, and report preparation with secure case management, workflow support, integrations, orchestration, and automated reporting. The platform helps security operations teams collaborate, follow NIST recommendations, measure service levels and threats, inform resource decisions, and reduce responders’ cognitive load.
Transcript
I'd like to welcome, from Sidearm, Dr. Vaughn Shanks, CEO and co-founder. Come on up. Come on up. All right. Please. Thank you. Good luck. Good luck. Thank you. Okay. Dr. Shanks, your time begins now. Okay. Well, thanks for the introduction, Hugh. Uh, so our company, Sidearm Technologies, uh, is making cybersecurity incident response better and fas... Read More
Key Insights
- Manual incident response management is often slow because teams rely on generic ticketing systems, office software, copying, and manual data entry. These disconnected practices make alert triage, context gathering, collaboration, record keeping, disclosure decisions, and reporting harder than they need to be.
- Cydarm is a secure case management platform designed specifically for cybersecurity incident response. It combines workflow support, secure collaboration, report generation, and orchestration to help organizations implement incident-handling practices based on recommendations from NIST.
- Tactical reports are designed to communicate what happened during a specific incident quickly and accurately. They allow security teams to select an appropriate level of detail when updating internal stakeholders or sharing information with relevant external parties.
- Operational reports are designed to measure security operations center activity over time. They can show progress against service-level agreements, containment, response, and remediation goals while also quantifying the types of threats appearing within an organization’s environment.
- Incident data is useful for management decisions because evidence collected from actual operations can support requests for additional resources. Organizations can also use the data to guide investments in security controls and evaluate whether those controls are producing the intended results.
- Orchestration improves responder efficiency by allowing actions inside the platform to trigger other actions. Examples include enriching an indicator of compromise, performing a DNS lookup on a fully qualified domain name, or sending a Slack notification after a significant event.
- Reduced manual work is intended to lower the cognitive burden on incident responders. Removing repetitive copying and data entry can make their work easier and less stressful, addressing the cyber fatigue and burnout described as common within the profession.
- Cydarm differs from generic case management tools by focusing on incident response across the organization. Its data can support security teams, legal staff, human resources, and other roles, while its pricing uses a straightforward per-SOC-seat model.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does Cydarm improve cybersecurity incident response?
Cydarm improves incident response by placing alerts, cases, workflows, collaboration, reporting, and orchestrated actions in a secure platform built for the task. It reduces manual ticket creation, copying, and data entry, while helping teams gather context and maintain accurate records. The platform also supports tactical communication, operational measurement, data enrichment, notifications, and practices based on NIST recommendations.
Q: Why are generic ticketing systems inadequate for incident response?
Generic ticketing systems and office applications can leave incident response dependent on copying, manual data entry, and disconnected communication. According to the presentation, this makes context gathering, alert triage, reporting, and disclosure decisions slow and difficult. Case management features included in SIEM platforms may also be treated as secondary additions rather than tools designed around the broader needs of incident responders and organizational stakeholders.
Q: What is the difference between tactical and operational incident reports?
Tactical reports describe what happened in a particular incident and help teams update internal or external stakeholders with an appropriate level of detail. Operational reports examine security operations center activity across a period of time. They help organizations assess service-level performance, containment, response, remediation, and threat patterns, providing evidence for resource allocation and security-control investment decisions.
Q: How does Cydarm integrate with a SIEM platform?
Cydarm integrates alerts from the SIEM monitoring process so responders do not have to take an alert and manually create a separate ticket. Once the alert enters the case management workflow, actions performed by a responder can trigger additional automated steps. This approach connects detection with case handling, enrichment, communication, and documentation while reducing repetitive transfers between systems.
Q: What incident response tasks can Cydarm orchestrate?
Cydarm can trigger an action when an incident responder performs an action within the platform. The examples provided include enriching a piece of data, looking up an indicator of compromise, performing a DNS lookup on a fully qualified domain name, and notifying people through Slack when a significant event occurs. These capabilities are intended to reduce repetitive work and accelerate response activities.
Q: How can incident reporting support security investment decisions?
Operational reporting converts incident activity and field data into measurable evidence. Teams can track performance against service-level agreements, examine progress through containment and remediation, and quantify the threats appearing in their environment. Leaders can use these findings to justify additional resources, decide where to invest in security controls, and measure whether existing controls are effectively addressing observed threats.
Q: How does Cydarm support teams outside the security operations center?
Cydarm treats incident response as an activity involving the wider organization, not only the security operations center. Its case data and reports can be made useful to legal teams, human resources, and other organizational roles that participate in an incident. Secure collaboration, controlled levels of reporting detail, and accurate records help different stakeholders work with relevant information while addressing disclosure concerns.
Q: Who is Cydarm designed for, and how is it priced?
Cydarm is intended for large organizations, government bodies that require accurate record keeping, and managed security service providers seeking greater efficiency and evidence of the value they deliver. The presentation states that an ASX 50 Australian company used the product. Pricing is described as a simple per-seat model, specifically based on seats in the security operations center.
Summary & Key Takeaways
-
Cydarm was created after Vaughn Shanks observed that sophisticated analysis tools could identify incidents but left subsequent communication and coordination to phone calls and manual processes. His experience in large government organizations highlighted the need for accountability, secure collaboration, reliable records, and processes that support continuous operational improvement.
-
The secure case management platform supports incident response through structured workflows, secure collaboration, report generation, and orchestration aligned with NIST recommendations. Tactical reports communicate individual incidents at an appropriate level of detail, while operational reports track security operations activity, service levels, containment, response, remediation, and observed threats over time.
-
Cydarm integrates alerts from SIEM products, eliminates manual ticket creation, and lets platform actions trigger enrichment or notifications. The company serves large organizations, government bodies, and managed security service providers. At the time of the presentation, it had fewer than ten employees, was based in Melbourne, and had raised half a million dollars.
-
Key Insights
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator