The Improvisation Tax
Every manual lookup adds minutes to response. An alert arrives. You panic, check Workday or Okta, find the device, query the CMDB, look up the IP, then hunt down the team owner who is out for coffee. Time zones add another layer. Attackers automate. Defenders who improvise lose the race. The goal is to buy time so the team can move from reacting to responding.
Five Pillars: From Detection to Governance
First, normalize all alerts into a single pane of glass. Second, define a command structure with one incident commander. Third, automate the war room: an alert creates a Slack channel and pages the right people. Fourth, execute containment before investigation. Fifth, preserve forensic snapshots and notify legal. Compliance saves the company even if technical response saves the team.
Where AI Helps and Where It Doesnβt
AI sweet spots are alert normalization, enrichment, and investigation assistance. It can pull context from multiple databases and answer questions about past IOC patterns. But fully autonomous containment is too risky for protected accounts. Legal and compliance decisions need a human in the loop. SOAR playbooks handle repeatable flows; AI adapts when context changes.
15 Minutes vs. 7 Minutes
A manual incident timeline: alert wakes you, 5 minutes to review, 5 minutes to look up host/IP/context, 5 minutes to block the IP and disable the user. The incident commander arrives at 15 minutes. An automated pipeline creates the ticket, spins up the Slack channel, enriches the alert, and for a non-protected account, disables the user and isolates the host by minute 7. The on-call engineer logs in to review scope, not to start from zero.
Q&A
Can you elaborate on auto remediation? Response stops the bleeding; remediation returns to normal. Auto remediation is hard because you must know what normal was, and the post-incident normal often changes. βΆ Watch (24:00)
How is AI used in investigations β feed data from multiple systems? AI in the SIEM can chat about context, look back 30 days for past IOCs, and tie together IP and threat intel sources to determine if an event is one-time or persistent. βΆ Watch (25:20)
What is better for automating incident response: SOAR playbooks or AI-based automation? SOAR playbooks excel at repeatable flows with fixed context. AI automation is better when playbooks require adaptation and changing context. βΆ Watch (26:38)
What is the recommended pipeline for evidence handling and who are the necessary stakeholders? If you are the only security engineer, stakeholders are yourself and legal. Include breach coaches, cyber insurance vendors, or a third-party incident response team if available. βΆ Watch (28:20)
Notable Quotes
containment beats documentation Geet Pradhan Β· βΆ Watch (22:21)
the more effort you spend on plumbing the pipes of this pipeline, the more time you can spend on actually thinking about the response Geet Pradhan Β· βΆ Watch (21:05)
everything that you do in an incident response is all about saving time Geet Pradhan Β· βΆ Watch (22:59)
Key Takeaways
- Automate enrichment and war room creation to buy minutes before a human logs on.
- Contain the attacker before starting investigation or documentation.
- Context is more important than the alert itself for triage and decision-making.
About the Speaker(s)
Geet Pradhan is the Sr Security Engineer at Lime. He is a big fan of Aesopβs hand cream.