How to Automate Security Incident Response

TL;DR
Security teams can shorten incident response by codifying expert decisions, automating information collection, and triggering containment after a defined review period. At GE, automatically creating containment tickets and allowing business owners about one hour to object helped eliminate delays caused by manually locating asset owners, while preserving a limited opportunity for human intervention.
Transcript
All right, good morning, everybody. Uh, it's actually kind of funny. I was, um, at an event last night, and somebody told me that the RSA Conference was over on Thursday night, and I said, like, "No, I'm, I'm pretty sure it's still going. I'm, I, I've got a slot on Friday morning." Um, and they are sure. Like, "No, it's definitely over. You're wron... Read More
Key Insights
- Security automation is applicable to organizations of every size because both small and large response teams lose time to repetitive collection, communication, and decision steps. Automation can reduce that burden even when an organization has only one responder or a person working on security part time.
- Incident response speed depends on eliminating idle time within the process. GE used Lean Six Sigma value stream mapping to find pauses while information was collected, owners were contacted, or containment decisions were awaited, revealing that workflow delays were a major obstacle to faster response.
- Automated containment can combine rapid action with limited human oversight. GE automatically notified the relevant business, allowed about one hour for intervention, and then created a ticket to remove a confirmed compromised device from the network when no one stopped the action.
- The security talent crunch is especially severe in advanced activities such as incident response and threat hunting. Because qualified personnel and budgets are limited, organizations need workflows that reduce the amount of human effort required for both routine alerts and serious incidents.
- Attackers use automation more extensively than many defenders. APT30's Backspace controller automatically gathered system details and basic directory information from compromised devices, then supported command-line actions for deeper listings, file retrieval, and arbitrary script execution.
- Nation-state operations can divide responsibilities among groups handling initial infiltration, persistence, surveillance, and data exfiltration. Each group can apply specialized automation, including scripts that identify vulnerable systems, test where credentials work, support lateral movement, and search devices for information worth stealing.
- Codifying responder expertise means converting known attacker techniques and established response decisions into repeatable workflows. Knowledge acquired through incident investigations, security conferences, training, community reports, and documented adversary procedures can therefore become an operational basis for automation.
- Commercial and open-source tools offer different paths to security automation. The transcript identifies Bonita or Bonitasoft and Netflix's Fido as open-source examples, while commercial products may provide more prebuilt connectors, basic playbooks, and workflows that reduce initial integration work.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can security automation reduce incident response time?
Security automation reduces response time by removing pauses associated with collecting information, locating asset owners, contacting local IT staff, and waiting for routine decisions. A team can define conditions for action, send notifications automatically, allow a limited review period, and then create the containment ticket. This approach turns a slow sequence of manual handoffs into a repeatable workflow.
Q: How did GE automate containment of compromised devices?
GE automatically created a ticket to remove a confirmed compromised device from the network when it was actively spreading, moving laterally, or showing signs that an attacker was surveying the environment. The relevant business received an automatic notification and about one hour to intervene. If it did not stop the action, the containment ticket proceeded without waiting indefinitely for an asset owner.
Q: Why was GE's manual containment process too slow?
The manual process required responders to identify the asset owner, track that person down, call them, and contact the IT owner at the relevant location. Weekends and holidays could make those people unavailable, forcing the response team to wait. These communication delays prevented rapid containment even when the team already knew that a device was compromised and creating additional risk.
Q: What does codifying security expertise mean?
Codifying security expertise means translating what responders know about attacker techniques, investigative steps, and containment decisions into repeatable automated workflows. The source material for those workflows can include lessons from incidents, conference sessions, training, community reports, and descriptions of adversary techniques and procedures. Once encoded, that knowledge can guide routine actions without requiring an expert to manually repeat every step.
Q: How do attackers use automation during cyber operations?
Attackers use automation to gather system information, inspect directories, search for valuable files, identify vulnerable devices, test where credentials work, and support lateral movement. The APT30 example shows compromised machines automatically appearing in a controller with basic system and directory details. Command-line functions then allow operators to retrieve additional listings, obtain file contents, and run arbitrary scripts on those machines.
Q: Why is automation important during a security talent shortage?
Automation is important because organizations often lack enough qualified personnel and budget, particularly for advanced incident response and threat-hunting work. Automating repetitive collection, notification, and decision steps reduces the human effort required for ordinary alerts and severe incidents. It also lets available specialists spend more of their limited time on analysis and judgment that cannot be captured by a routine workflow.
Q: Should security containment always require a human decision?
The GE case suggests that containment does not always need an immediate human approval when a device is confirmed compromised and presents active danger. The team preserved oversight by notifying each business and allowing about one hour to stop the action. After that period, the workflow automatically initiated containment, preventing weekends, holidays, or unavailable owners from producing open-ended delays.
Q: What tools can organizations use for security automation?
Organizations can choose open-source or commercial automation tools. The transcript names Bonita or Bonitasoft, a business process management package flexible enough for security workflows, and Netflix's Fido as open-source options. Commercial packages may offer more prebuilt connectors, basic playbooks, and ready-made workflows. The appropriate choice depends on the organization's processes and integration needs described in its automation plan.
Summary & Key Takeaways
-
Security automation can benefit incident response teams of any size, from a single part-time responder to a group of forty people. Its primary value is reducing pauses caused by manual data collection, communication, and decision-making, which allows scarce security personnel to focus their time on incidents that genuinely require human judgment.
-
At GE, responders mapped their incident response process using Lean Six Sigma value stream mapping and identified waste. One major delay involved locating asset or IT owners before containing confirmed compromised devices. The team automated notifications and ticket creation, allowed about one hour for objections, and then initiated containment automatically.
-
Attackers already use extensive automation for infiltration, reconnaissance, lateral movement, persistence, and data theft. APT30's Backspace system automatically collected system information and directory listings, while command-line controls supported additional actions. Defenders can respond by codifying expertise from investigations, conferences, training, and threat reports into repeatable automated workflows.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator