Red Bull Powers Security Strategy With AI, Automation

  /     /     /  
Publicated : 22/11/2024   Category : security


Red Bull Powers Security Strategy With AI, Automation


When it comes to security, Red Bull is looking to close the gap by turning toward newer technologies, including automation, AI and machine learning.



Red Bull is well-known for projecting an energetic brand. Behind the scenes, its IT security team also likes to be energetic, however, not in the way the companys commercials would have you believe.
Despite the play-hard image of the brand, the Red Bull team likes to be very Zen. About a year ago, it began investing in automating some of its security processes, so the organization could free-up detection and response resources to become higher value, less tactical brains.
At times, an enterprise security strategy can be dangerous when it gets overly defensive. However, when security teams want to be strategic, as Red Bull has shown, automation technology can actually help the security team think, and not just act. (See
Unknown Document 741907
)
(Source:
Flickr
)
We dont want to lose the right focus or become over-protective, Jimmy Heschl, Red Bulls CISO, told Security Now, explaining how sometimes reacting to and resolving an incident can be a mistake. Even reacting and remediating correctly, shouldnt ideally -- in his world -- be done manually because its at the cost of contending against hackers who have time on their hands and are very inventive.
Overwhelming or excessively intrusive security controls are significant roadblocks, when [we] want to be creative, spontaneous and innovative, Heschl said. Overreaction from security -- as this is done by colleagues that are primarily driven by various compliance requirements -- has a significant impact on these objectives.
Advent of security automation
A number of tech vendors including Demisto, IBMs Resilient Systems, Microsofts Hexadite, and Red Bulls vendor, EnSilo, are capturing the mood with orchestration and automation offerings, powered by artificial intelligence, and more specifically, machine learning. (See
Automation Answers Security Skills Shortage
.)
Gartners 2017
Innovation Insight for Security Orchestration, Automation and Response
report finds enterprises hobbled because of analyst time lost to manual, heavy-lift processes.
Security operations still primarily rely on manually created and maintained, document-based procedures for operations, which leads to issues such as longer analyst onboarding times, stale procedures, tribal knowledge and inconsistencies in executing operational functions, according to the report.
Increasingly, the engine behind endpoint detection and response (EDR) system automation is AI and machine learning. These technologies are in the hype curve and for some organizations, offer not only to automate manual work, but to actively couple learned threat knowledge with their own business security policies and then independently remediate attacks.
But a lack of human intervention, on the other hand, worries Red Bull, for one.
Automated response is a challenge in itself, Heschl said. It has to do with giving away control, and automation always has some drawbacks. Its not the detection function that I fear, but automated response from simple mail filters and network blocks; via user and access management to advanced countermeasures: the more complexity you have in response, the more that can go wrong.
The cost of dwell time
The elapsed time between threat detection and response -- dwell time -- is what costs enterprises money in terms of increased risk of data theft or damage, and the price of running through investigation and remediation processes that usually take months.
Red Bull CISO Jimmy Heschl

(Source:
Red Bull
)
A 2017 study by the Ponemon Institute of 419 companies, entitled
The Cost of Data Breach
, reported that the time to identify and the time to contain malicious attacks were an average 214 and 77 days respectively. The average cost per breach is currently about $4 million.
Want to hear more about the leading operator use cases for AI technologies? Join us in Austin from May 14-16 at the fifth-annual
Big Communications Event
. Theres still time to register and communications service providers get in free!
Although a current drive towards zero dwell time is noble, its a massive challenge. Fortunately, a more realistic return on investment in automated EDR is already benefiting Red Bull.
Its the speed of initiating action [thats important], Heschl said. On the other side, its the automation of response that leaves [us] independent of scarce resources.
It helps me address my big fear: losing focus. My team can use their time to think and to improve rather than hunt adversaries, Heschl added.
Although its the computing and learning crunch power that AI and machine learning that support this drive, despite the hype, the technology itself is relatively unimportant.
I believe that machine learning and AI are the means to meet and achieve security initiatives, EnSilo CEO Roy Katmor said. [But] organizations believe in added value -- namely alert efficacy, in pre- and post-infection, and operational efficiency via automation. The technology behind it is less relevant.
Related posts:
GDPR, AI & a New Age of Consent for Enterprises
Cybersecurity AI: Addressing the Artificial Talent Shortage
AI Is Stealing These IT Security Jobs – Now
— Simon Marshall, Technology Journalist, special to Security Now

Last News

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Red Bull Powers Security Strategy With AI, Automation