VOOZH about

URL: https://thenewstack.io/5-ways-to-reduce-toil-by-automating-incident-response/

⇱ 5 Ways to Reduce Toil by Automating Incident Response - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-04-22 09:00:24
5 Ways to Reduce Toil by Automating Incident Response
contributed,sponsor-torq,sponsored,sponsored-post-contributed,
DevOps / Security

5 Ways to Reduce Toil by Automating Incident Response

Rescue your SOC teams from the toil of mundane security tasks with incident response automation. Learn how in this post.
Apr 22nd, 2022 9:00am by Faith Kilonzi
👁 Featued image for: 5 Ways to Reduce Toil by Automating Incident Response
Featured image via Pexels.
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
Faith Kilonzi
Faith is a full-stack software engineer, technical writer and a DevOps enthusiast with a passion for problem-solving through implementation of high-quality software products. She holds a bachelor’s degree in computer science from Ashesi University.

Toil — endless, exhausting work that yields little value in DevOps and site reliability engineering (SRE) — is the scourge of security engineers everywhere. You end up with mountains of toil if you rely on manual effort to maintain cloud security. Your engineers spend a lot of time doing mundane jobs that don’t actually move the needle. Toil is detrimental to team morale because most technicians will become bored if they spend their days repeatedly solving the same problems. It’s also terrible for business since it implies engineering resources are being spent on projects that don’t add value to the company, making it more difficult to build new services or products — let alone innovate.

Automating incident response plays a central role in addressing toil. Once your incident response is automated, your security operations center (SOC) team will be able to triage alarms more efficiently, respond to critical events faster and seamlessly integrate your existing security solutions into a more efficient and comprehensive incident response program. By automating your response to security threats, you mitigate toil because mundane tasks — like looking for and responding to threats — can be performed automatically. The result is that your engineers will have more time to do work that is truly meaningful — for them, as well as for the business. Here are five ways automated incident response can reduce toil.

Why Automate Incident Response?

The purpose of automated incident response is to manage the endless alerts that security teams are receiving, and enable them to respond at machine speeds. The SOAR (security orchestration, automation and response) platform combines data collection, case management, standardization, workflow and analytics to enable organizations to respond quickly to critical incidents — beyond simple incident response. As a result, incident response can automatically resolve security issues arising from the convergence of three different technology markets: automation, security incident response and threat intelligence.

Among other benefits, automated incident response reduces toil by eliminating alert fatigue in SOC teams. Alert fatigue occurs when security tools generate an overwhelming number of alerts forcing the security analysts to manually check each alert message to distinguish genuine threats from false positives. This often leads to actual issues being ignored, leaving your company’s security posture vulnerable. Automated incident response handles this issue by eliminating the human element from alert processing and response, allowing security teams to analyze and fix more threats and enhance enterprise security.

Other benefits of automating incident response include faster response times, streamlined threat intelligence, cost reduction, reporting and metric automation capabilities.

5 Ways to Reduce Toil with Incident Response Automation

1. Reduce Context Switching

Context switching refers to the process of storing the system state for one task, so that task can be paused and another task resumed. Context switches are often caused by distractions and disruptions — brief interruptions that divert attention and break flow. Context switching can lower productivity, increase fatigue and, ultimately, lead to burnout. With incident response automation, you reduce the impact of context switching for team members, and the huge cost that comes with it.

2. Increase Telemetry 

Because most, or all, of the core control processes are automated in a DevOps environment, monitoring is critical. A robust, integrated monitoring solution with a full API and dashboard capabilities is by far the ideal choice for DevSecOps. As a result, automating incident response aids in the collection of more telemetry for threat intelligence. This automation generates telemetry in the form of time stamps, execution results and so on. Over time, this telemetry is key to improving processes and spotting areas of unnecessary work.

3. Increase Incident Context 

Engineers can use SOAR and incident response tools to extend the incident context surface and accomplish automated incident response. Through automation, the integrated technologies give improved continuity and an audit trail of all activities prior to and following an incident. You can’t do this manually.

4. Reduce Human Touch Points 

Incident response tools can be used by SOC teams to fully automate playbook actions, semi-automated actions or approval-based response actions, which allow people to monitor threat alerts before countermeasures are taken. As a result, engineers have fewer places where manual intervention, interpretation or judgment is required, thus reducing toil at those stages.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq

5. Accelerate Existing Processes

Teams must design a method in advance to establish incident response automation. To measure the success rate of their incident response automation, they first choose clear measures such as MTTR (mean time to repair). Increased productivity and DevOps maturity can be achieved as a result of the automated workflows and responses. This exercise will expose toil, which will be resolved (hopefully) before the automation is completed.

Modern Incident Response

Every organization’s cybersecurity posture requires a comprehensive incident response process. New tools have been developed to help fight these increasingly intricate attacks since manual processes cannot always provide the proactivity, quick reaction or real-time mitigation required to cope with modern threats and threat actors. As discussed in this post, these constraints, together with toil, can be overcome with automated incident response.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq
TRENDING STORIES
Faith Kilonzi is a full-stack software engineer, technical writer and a DevOps enthusiast with a passion for problem-solving through implementation of high-quality software products. She holds a bachelor’s degree in computer science from Ashesi University."
Read more from Faith Kilonzi
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Torq.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.