Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Security Automation Is The Solution For Overworked Cyber-Security Staff
Articles

Why Security Automation Is The Solution For Overworked Cyber-Security Staff

ISBuzz TeamBy ISBuzz TeamOctober 13, 2016Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security Operations Centres (SOCs) continue to be under significant pressure to respond, manage and assure security. Ponemon Institute finds it takes enterprises an average of 206 days to spot a breach and 69 days to contain it. The speed with which an organisation can identify and contain data breach incidents strongly corresponds with financial consequences, which are significant; the average total cost of a data breach increased 23 percent over the past two years to US$ 3.79 million (£2.9 million).

Cloud sprawl escalates risk

These escalating costs are set against a backdrop of the growth of the cloud and the resulting increased security risks. Recent independent research into the impact of public cloud services found that over 85 percent of CIOs believe the proliferation of public cloud services is reducing the control their organisation has over the IT services it uses. Cloud sprawl is a particular problem; 80 percent of CIOs think the widespread use of cloud services not sanctioned by IT, and not governed by IT Service Management (ITSM) processes, is creating longer-term security risks.

Overreliance on manual remediation continues

As threats and their impact continue to escalate, businesses are struggling to cope, particularly as staffing and skills shortages can make it difficult to find and retain security staff. As a result, many SOCs are exploring how automation can help them manage the workload and, equally importantly, deliver a better service. Automation is becoming more widespread but, while there are several tools and systems that provide automated incident visibility, few of them extend to the effective management of response and remediation.

In fact, incident response and remediation processes are typically manual, involving a variety of handoffs, systems, information sources and stakeholders. They generally do not provide a ‘closed loop’ solution; where vulnerabilities are not effectively managed, leading to continued risk. Further, reliance on tools such as emails, spreadsheets, phone calls, meetings and text messages, makes it difficult to analyse how processes are performing, where the bottlenecks are, and how to improve them. The number one issue cited in recent research was a lack of coordination between security and IT teams; while nine out of 10 respondents said that their incident response effectiveness and efficiency is limited by the burden of manual processes.

Service management technology integrates security

The good news, which many SOCs are unaware of, is that many can use their organisation’s current service management technology to improve automation and process management across security operations. Benefits of this approach include:

  • Providing a single platform for managing security incidents and vulnerabilities: Modern service management software offers workflow, automation, orchestration and systems management capabilities. These platforms enable teams to manage the process of responding to and remediating incidents, and remove manual processes that slow security incident resolution times.
  • Prioritising security risks with business criticality:Users can attach incidents to records, pairing security data with insight into the virtual or physical asset at risk, and the business service that asset supports. By doing this, a SOC can see, for instance, that the server being attacked contains sensitive HR data and should be prioritised accordingly.
  • Automating manual functions frees SOCs to address critical issues:Through service management platforms, SOC teams can trigger automatic patching and configuration changes to security infrastructure, or other standard workflows, to contain and fix security incidents and vulnerabilities. Automatic post‑incident reports crucial to the auditing process can be generated – eliminating the tedious manual process many organisations complete.
  • Gaining greater visibility into current security issues by category, class and priority, and status of tasks: Through the use of dashboards that service management solutions typically have, SOCs can access real‑time trending data that helps them understand their effectiveness in securing their enterprise.

To increase the value of security products that organisations have already deployed, these technologies can also integrate with third‑party software applications; including security incident and event managers, and vulnerability identification solutions.

Addressing the wider context

In addition to automating threat detection and remediation, the extension of ITSM technology to security operations also ensures higher security standards are applied to processes carried out across the business. For example, when onboarding a new employee, automation can complete a new password setup, or automate the authentication of a new mobile device/account, ensuring optimum security processes are built in from the outset. In the age of BYOD and ‘shadow IT’, this will increase in importance and value to businesses, as well as facilitating closer integration between security teams and other functions. Finally, automation of detection and remediation of security issues frees security teams to focus on mission-critical activities and improved collaboration.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}