AWS Security Incident Response

Prepare for, respond to, and recover from security events

What is AWS Security Incident Response?

AWS Security Incident Response helps you respond when it matters most. The service combines the power of automated monitoring and investigation, accelerated communication and coordination, and direct 24/7 access to the AWS Customer Incident Response Team (CIRT) to quickly prepare for, respond to, and recover from security events.

Benefits

Allow AWS Security Incident Response to access service-level permissions, enabling it to read security findings from Amazon GuardDuty and third-party detection tools through AWS Security Hub. This service uses automation and customer-specific data to filter and suppress security findings based on expected behavior, helping your team prioritize critical security alerts and free up resources.

Streamline security management by centralizing communication, coordination, and remediation in one place. Use service automation to handle routine administrative tasks, allowing your security teams to concentrate on responding to and recovering from security events.

Get 24/7 direct access to the AWS Customer Incident Response Team (CIRT). This dedicated group of security experts has specialized knowledge to help customers respond to and recover from security incidents.

Use the service to centralize the tracking, storage, and management of current and past security events. This provides your team with valuable insights, enables learning from historical data, and facilitates improvements to enhance your overall security posture.

Use cases

Utilize this service to prepare and equip your security teams for success. Conduct tabletop exercises and simulations to replicate potential scenarios, enhancing your team's ability to respond rapidly and recover effectively. By practicing your procedures, you can identify gaps, improve coordination, and ensure your team is ready to act decisively when a security event occurs.

When a security event occurs, you can use the service to respond in a way that best suits your organization's needs. The service offers multiple response options, including: internal response by your own security team, engagement of third-party security providers, or support from the AWS Customer Incident Response Team (CIRT). These options allow your organization to effectively manage and recover from security event.

Get a detailed report for any AWS-supported security case. These reports offer a complete summary of case activities, suggested remediation actions to improve your security posture, and key metrics about the security event.

  • PGA Tour

    AWS Security Incident Response’s 24/7 access to AWS security experts provides a reliable backstop, ensuring peace of mind. We can quickly obtain support when major security issues arise, accelerating our response time. This minimizes the damage and costs associated with security events, including cases internal teams may be unable to resolve, such as a root incident compromise or ransomware recovery.

    J. Oliva, Sr. Director of Cybersecurity, PGA Tour

Explore more of AWS