AWS Unveils Incident Response Service to Tackle Rising Cyber Threats
AWS introduces a new security incident response service to help organizations quickly recover from cyberattacks and ransomware. The tool automatically triages threats and serves as a central hub for managing security crises.
Amazon Web Services (AWS) launches a new service called AWS Security Incident Response to help businesses combat cyberattacks like ransomware and account takeovers. This release comes as many organizations struggle to manage effective incident response plans, with global cyberattack costs projected to exceed $23 trillion by 2027. The service acts as a single source of truth for security teams to coordinate their recovery efforts.
The new platform automatically triages threat findings from Amazon GuardDuty and supported third-party cybersecurity tools. Through a centralized dashboard, customers adjust alert settings, manage account permissions, and track key metrics such as the average time it takes to resolve an incident. A proactive incident response feature also grants the service permissions to actively monitor and investigate potential security issues.
When the system encounters a threat, it uses automated services and customer-specific data to sort and remediate the finding. If a threat cannot be fixed automatically, the platform creates a dedicated security case and notifies the appropriate stakeholders within the organization. Ultimately, this offering places AWS in direct competition with specialized incident response startups by providing a scalable, integrated solution for corporate security teams.