-
Featured services
Think beyond the robots
The successful integration of AI and IoT in manufacturing will depend on effective change management, upskilling and rethinking business models.
Read the blog -
Services
Leverage our capabilities to accelerate your business transformation.
-
Services
Network Services
Popular Products
-
Services
Cloud
Popular Products
-
Cloud Architecture and Modernization
Discover how to achieve your business goals through cloud modernization practices, that deliver improved agility, reusability and scalability.
-
Cloud Optimization
Discover how to maximize operational excellence, business continuity and financial sustainability through our cloud-advanced optimization services.
-
-
Services
Consulting
-
-
Services
Data and Artificial intelligence
-
Services
Technology Solutions
Client stories
-
Services
Global Data Centers
-
Services
CX and Design
-
Services
Application Services
-
Services
Sustainability Services
-
Services
Digital Workplace
-
Services
Business Process Services
Master your GenAI destiny
We’ll help you navigate the complexities and opportunities of GenAI.
Explore GenAI -
-
-
Insights
Recent Insights
-
The Future of Networking in 2025 and Beyond
-
Using the cloud to cut costs needs the right approach
When organizations focus on transformation, a move to the cloud can deliver cost savings – but they often need expert advice to help them along their journey
-
Make zero trust security work for your organization
Make zero trust security work for your organization across hybrid work environments.
-
-
Master your GenAI destiny
We’ll help you navigate the complexities and opportunities of GenAI.
Explore GenAI -
-
Master your GenAI destiny
We’ll help you navigate the complexities and opportunities of GenAI.
Explore GenAI -
Discover how we accelerate your business transformation
-
About us
CLIENT STORIES
-
Liantis
Over time, Liantis – an established HR company in Belgium – had built up data islands and isolated solutions as part of their legacy system.
-
Randstad
We ensured that Randstad’s migration to Genesys Cloud CX had no impact on availability, ensuring an exceptional user experience for clients and talent.
-
-
CLIENT STORIES
-
Liantis
Over time, Liantis – an established HR company in Belgium – had built up data islands and isolated solutions as part of their legacy system.
-
Randstad
We ensured that Randstad’s migration to Genesys Cloud CX had no impact on availability, ensuring an exceptional user experience for clients and talent.
-
-
Sponsorships
CLIENT STORIES
-
Liantis
Over time, Liantis – an established HR company in Belgium – had built up data islands and isolated solutions as part of their legacy system.
-
Randstad
We ensured that Randstad’s migration to Genesys Cloud CX had no impact on availability, ensuring an exceptional user experience for clients and talent.
-
Everest Group PEAK Matrix® Assessment
NTT DATA is a Leader and Star Performer in the Everest Group Sustainability Enablement Technology Services PEAK Matrix® Assessment 2024.
Get the Everest report -
- Careers
Topics in this article
Without some form of automation, larger scale infrastructure deployments, in particular, will struggle to maintain even the status quo in operational disciplines required today. A material number of incidents are related to poor systems hygiene through vulnerability, configuration, privilege and asset management. At a basic level, these operational requirements are ripe for automation and will help meet compliance obligations and reduce risk.
Starting the journey to automation
Defining a strategy to help shape your automation journey is critical to responding to rapid change and making way for digital transformation.
Below is an illustration of some different approaches to automation, depending on your risk profile, operational maturity and enterprise scale.
For many companies though, the journey begins with leveraging scripts as they are the foundation to build on further automation. Moving forwards into an automation stack will provide opportunities to automate mundane tasks; while not specific to security they may help streamline your operational objectives. This could involve scheduling regular audits across your infrastructure to patching systems.
Security Orchestration and Automation Response (SOAR) platforms combine multiple security processes and tools that assist with orchestration, automation, and response.
There is now significant interest in SOAR platforms, as they can automate once laborious tasks performed by security analysts to deliver faster response times and – as a result – can save you from a security breach.
Take, for example, the use case of responding to an email incident, where potentially hundreds of malicious emails are sent to a company to harvest passwords through a fake login page hosted on a website. In the past, the task of identifying impacted users, blocking the domain, resetting passwords and removing email from mailboxes could take many hours. With automation, this task can be reduced to mere seconds or minutes.
A Security Service Gateway is a concept of providing an abstraction layer platform for all operational staff, not just for security personnel in your SOC. Much like the move from EDR (Endpoint Detect and Respond) to XDR (X replaces Endpoint with anything), I suggest such a gateway is akin to a transition from SOAR to XOAR. It may not be an off-the-shelf product and we can expect highly motivated or well-resourced companies to create customized platforms to fill this need. Depending on the design, a gateway would be an API-first platform with built-in high-performance applications delivered through a microservice architecture. These applications will integrate through a workflow system to combine different data points to expose information relevant to the use cases that are defined by operational teams. Empowering your operational teams to tie together information across systems, applications or platforms regardless of where they will help support a digital journey.
Despite automation being a long-term commitment, the above examples are not mutually exclusive, and we can expect companies to employ multiple platform strategies to support the objectives of automation.
Evaluating your success
Success is a broad term but being able to evaluate how well your automation platform stacks up against your objectives using quantifiable metrics is vital to measure its effectiveness. Below are some strategies to evaluate and compare when using an automation platform versus performing the tasks manually:
- Lead time to enrich, triage, respond: How long did the case take the ingested alert to be enriched with contextual data e.g., domain reputation and determining asset ownership to establishing priority and risk to then responding through a block action?
- Keyboard stroke and mouse clicks: How streamlined is the process for the team logging cases, extracting necessary information and updating those service tickets? Count every keyboard stroke and mouse click and compare results.
- Rate of overall case closure: How long did it take to close the case end-to-end? Take into consideration when the alert was first known through to following your incident management process to closure.
Learning and reflecting as you go
SOAR use cases will be similar; but their implementation will be unique and based on your company’s requirements. As your company changes, analyst feedback is critical to success, requiring continuous engagement between your operations and SOC teams.
If there are any takeaways you should consider, begin by asking the following questions:
- Do your operational processes allow you to respond quickly enough?
- Where are you on your automation journey?
- Do you have a strategy that is endorsed by senior management to execute?