Thursday
Room 1
16:20 - 17:20
(UTC+01)
Talk (60 min)
Supercharging Incident Response: Practical Automation and AI-Driven Investigations
automation is rapidly becoming a fundamental pillar of effective Incident Response and Security Operations. This talk explores how structured automation, combined with emerging AI-driven capabilities, can dramatically improve detection, triage, containment, and remediation workflows across a SOC.
Through real-world examples and practical playbooks, we will examine automated alert enrichment, intelligent case prioritization, and workflow orchestration that reduce analyst workload while increasing consistency and response velocity. The session will also highlight automated containment actions—such as host isolation, identity lockdown, and network control—along with safe and auditable remediation patterns.
Finally, we will dive into how AI can assist analysts during investigations: from natural-language querying of security data, to contextual reasoning over incidents, to guided hypothesis testing. Attendees will walk away with a clear understanding of where automation delivers the most value today, how to integrate it into existing SOC processes, and how AI is shaping the future of incident response.
