Thursday 

Room 1 

16:20 - 17:20 

(UTC+01

Talk (60 min)

Supercharging Incident Response: Practical Automation and AI-Driven Investigations

automation is rapidly becoming a fundamental pillar of effective Incident Response and Security Operations. This talk explores how structured automation, combined with emerging AI-driven capabilities, can dramatically improve detection, triage, containment, and remediation workflows across a SOC.

Process
AI/ML
Platforms
Security Tooling
Tools

Through real-world examples and practical playbooks, we will examine automated alert enrichment, intelligent case prioritization, and workflow orchestration that reduce analyst workload while increasing consistency and response velocity. The session will also highlight automated containment actions—such as host isolation, identity lockdown, and network control—along with safe and auditable remediation patterns.

Finally, we will dive into how AI can assist analysts during investigations: from natural-language querying of security data, to contextual reasoning over incidents, to guided hypothesis testing. Attendees will walk away with a clear understanding of where automation delivers the most value today, how to integrate it into existing SOC processes, and how AI is shaping the future of incident response.

Giorgio Perticone

Cyber Security Consultant obsessed with the idea of ​​playing detective in front of a pc, catching bad (cyber) guys and saving (business) damsels in distress.

Active player for various community projects, he recently started hosting a CyberSecurity Podcast called SECURITYbreak