
It’s difficult to protect organizations amid today’s rapidly evolving cyberthreat landscape. Attackers are now incorporating artificial intelligence (AI) technologies to advance their bad-actor tactics — for example, using generative AI to develop malware, according to a recent article in CSO.1
Organizations also contend with cyber disruptions such as natural disasters, and struggle to get ahead of cyber risks due to skills shortages and the complexity of managing numerous security tools.
An integrated approach to security and resiliency helps enterprises improve their security posture. By incorporating actionable threat intelligence for faster identification and remediation, organizations can more rapidly detect and respond to threats.
Cyber resilience is a priority
Appropriately responding to a security incident is the number one priority among security leaders, according to the Foundry 2023 Security Priorities study.2
However, security operations centers (SOCs) often use disparate tools that hinder teams from quickly gaining a clear, consolidated view into potential threats. And it may expose their organizations to vulnerabilities. For example, a recent Kyndryl study of 600 IT professionals worldwide found that:
- 61% of enterprises with 21+ tools experienced a cyberattack within the past 12 months — compared to 39% of companies using up to 10 tools
Meanwhile, security analysts can become fatigued from having to monitor multiple solutions and investigate a variety of alerts across the digital estate.
In addition, 43% of organizations cite skills shortages as a top cybersecurity challenge, according to the Kyndryl research. And 74% struggle to integrate new data sources.
All these challenges can cause security leaders to believe their organizations are falling short in addressing cyber risks. But adopting an integrated data model including capabilities like security lakes allows enterprises to better manage and integrate data across toolsets. The Kyndryl study found that organizations using a unified data view with robust analytics to are more likely to feel prepared for potential disruptions.
The way forward: Next-generation security
Another critical factor is the ability to leverage AI for threat and malware detection, alert and triage, real-time risk prediction, and incident response. A recent Ponemon Institute survey 3 found that 69% of IT security practitioners believe defensive AI is essential to block attacks at speed.
In particular, CISOs and CEOs are seeking:
- Faster identification of unknown threats
- Increased detection and response times
- Reduced manual or time-consuming tasks
- Proactive cybersecurity stance
Yet, they shouldn’t stop there. In addition to incorporating AI capabilities into existing security solutions, organizations benefit from an integrated approach for greater detection and response. For example, by combining existing security tools with next-generation threat insights using capabilities like security data lakes, organizations can achieve:
- Actionable intelligence to get critical insights faster
- Advanced visibility to monitor cybersecurity posture in one consolidated place
- AI-powered interventions and threat investigations to accelerate threat response
- End-to-end support that enables risk quantification and operationalized security insights across the digital estate
By leveraging these capabilities, security leaders can make faster decisions, with greater confidence that those decisions will enhance compliance and reduce business risk.
Security Operations with Kyndryl Threat Insights
The AWS Global Partner Security Initiative leverages the deep expertise and differentiated security capabilities of AWS Global Systems Integrators with the secure, scalable cloud technology of AWS — including Amazon Security Lake (ASL) and Amazon Bedrock.
Kyndryl, a global leader in managed security services, is a proven partner in this AWS initiative. The alliance has closely collaborated to marry their core competencies for a joint solution that addresses the need for improved managed detection and response.
Kyndryl’s Threat Insights provides more comprehensive visibility to help security leaders better identify and quantify security risks that could impact their business. Data is integrated via the Open Cybersecurity Schema Framework (OCSF). This may include data from customer security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and more. Kyndryl Threat Insights service enriches your security data with the latest threat intelligence and Kyndryl’s global security observations to gain actionable insights into cyber risks.
Kyndryl’s Threat Insights services also increases SOC team productivity by reducing the volume of alerts to be investigated. It uses AI to determine the degree to which threats can cause potential harm or disruption, then prioritizes alerts for investigation.
By integrating your existing security solutions with Threat Insights, you can:
- Receive accurate insights faster
- Empower investigation capabilities for an accelerated response
- Increase security posture to protect against modern threats
Proactive security for greater detection
Security leaders understand that cyber incidents are inevitable — so it’s essential to have effective detection driving quick response.
Thanks to the AWS and Kyndryl partnership, organizations can now capitalize on their existing security solutions to empower their security operations teams with actionable threat insights.
Visit this page to book a consultation with Kyndryl.
1 CSO, Sept. 7, 2023, https://www.csoonline.com/article/651125/emerging-cyber-threats-in-2023-from-ai-to-quantum-to-data-poisoning.html
2 Foundry, 2023 Security Priorities Study, https://foundryco.com/tools-for-marketers/research-security-priorities/
3 Ponemon Institute and MixMode, February 2024, https://www.csoonline.com/article/1307294/ai-adoption-in-security-taking-off-amid-budget-trust-and-skill-based-issues.html
