Cybersecurity analytics and operations: Need for automation and orchestration
New research from Enterprise Strategy Group (ESG) shows that when it comes to the evolution of Cybersecurity Analytics and Operations, 71% of respondent organizations find it more difficult today than it was two years ago due to the changing threat landscape, followed by volume of alerts and increased regulatory changes.
Which of the following best describes your opinion about cybersecurity analytics and operations?
“Despite businesses making it a priority, there is great confusion on how to make sense of and integrate Security Analytics and Operations. Most organizations are dealing with 10 to 25 technologies ranging from SIEMs, vulnerability assessment, endpoint detection, threat intelligence and user behavior to incident response. They are challenged with the total cost of operations and spending too much time on emergency issues,” said Jon Oltsik, Senior Principal Analyst, ESG.
This need for strategy and process improvements is why purchasing security operations tools designed to help organizations automate and orchestrate security operations processes was cited as the second highest priority respondent organizations will take over the next two years. The majority (90%) of respondent organizations are planning to deploy, or have somehow deployed, technologies designed for Automation and Orchestration.
The research also revealed that Automation is a higher priority (66%) than Orchestration (31%) – pointing to the need for a maturity model to guide security operations centers (SOCs) and cybersecurity professionals on their journey.
“There is a lot of hype but these are not turnkey solutions. Most organizations start by employing automation to the most time-consuming low-level tasks, such as integrating external with internal IOCs; whereas orchestration, such as building a run book, requires more thought and planning and attention,” Oltsik added.
Finally, the survey found a shift in focus from threat detection to incident response. Eighty-six percent (86%) of respondent organizations are currently using or plan to use an incident response platform while 92% have deployed, plan to deploy or are interested in deploying Machine Learning technology to support Automation and Orchestration – with accelerating incident response as a top driver.