Amazon Web Services (AWS) is launching AWS Security Incident Response, a service that aims to reduce the time it takes businesses to recover from cyberattacks.

Companies are often targeted by hackers and often struggle to cope with a cyberattack. According to a recent survey, only three in five organizations have a plan in place , and only a third conduct regular reviews to check whether their plan remains effective over time.
Why is a cyber incident response plan important?
Incident response is a critical aspect of cybersecurity that involves detecting, investigating, and responding to security breaches and cyberattacks. In today's digital landscape, where cyber threats are becoming more sophisticated and frequent, having an effective incident response plan is vital for organizations that want to protect their sensitive data and maintain business continuity.
See also: New phishing attack uses corrupted Word documents to evade detection
Without an appropriate incident response strategy, organizations risk serious financial and reputational damage. The International Monetary Fund estimates that cyberattacks will cost more than $23 trillion by 2027. The longer the time passes, the greater the impact of an attack on the business. Therefore, a proactive approach to incident management can significantly reduce the consequences of an attack and limit its spread.
Given this data and the increased cyberattacks around the world, Amazon Web Services (AWS), the company's cloud computing division, has launched AWS Security Incident Response, a service that aims to help businesses reduce recovery time from a cyberattack.
Hart Rossman, an AWS executive, told TechCrunch that the new service is designed to help companies' security teams combat account theft, breaches, ransomware attacks , and other corporate intrusions.
See also: Which cyberattacks increase during the holidays?
“We’ve received feedback from customers that implementing effective cyber threat response programs is difficult due to reliance on various tools, services, and people,” he said. “AWS Security Incident Response can now be used as a […] single solution for responding to security incidents.”
AWS Security Incident Response is effective because it automatically leverages findings from Amazon GuardDuty, Amazon's threat detection service, and supported cybersecurity tools .
Using a dashboard with built-in messaging and data exchange modules, customers can customize alert settings and account permissioning and review active incidents, historical data, and metrics (e.g., average time taken to resolve an incident).

According to an AWS post, customers can also enable proactive incident response, which allows Security Incident Response to monitor and investigate findings. These findings are automatically classified and remediated through a combination of automated services and customer-specific data (including shared IP addresses). If something cannot be remediated, Security Incident Response will create a security case, which will notify the appropriate stakeholders within the customer's organization.
See also: Protect your digital identity from phishing attacks
Based on the above, AWS Security Incident Response isn’t much different from other companies’ similar tools. However, Rossman says this tool stands out because it includes support from incident response AWS’s. (Customers can choose to handle incidents themselves or work with third-party vendors and partners.) AWS Security Incident Response will also be a more convenient solution for companies that already rely on other AWS security solutions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“AWS Security Incident Response works with all AWS detection and response services,” Rossman said, “continuously identifying and prioritizing security issues.”
AWS Security Incident Response is available through the AWS management console and service-specific APIs.
Source: techcrunch.com
