Hey there, my readers! Today, I will be discussing the security autonomy matrix. In terms of cybersecurity, it has been based on the use of human expertise, security tools, and pre-established rules of operation. The task of the security department includes analyzing alerts and suspicious activities, as well as evaluating threats. However, the continuously generated enormous amount of security information, together with the growing complexity of cyberattacks, makes that approach less and less viable.
Young organizations create huge amounts of information concerning security on their endpoints, cloud systems, applications, networks, identities, and business systems. At the same time, criminals use artificial intelligence and automation to speed up their process of attack.
This brings about the necessity of using automated cybersecurity operations. The idea of the Security Autonomy Matrix offers a new perspective on the way that security operations can be automated. The matrix gives an opportunity to define the level of autonomy of different security operations.
If you are looking for an easy guide to understand the framework properly, you are at the right place. Continue reading to learn everything about the matrix.
What Is the Security Autonomy Matrix?
The Security Autonomy Matrix is a conceptual structure for measuring cybersecurity tasks depending on how automated they are and how much humans are involved in them. The main essence is simple. Different security tasks need to be automated to different extents.
Some tasks can be repeated so many times that it is a reasonable idea to automate them. Other issues are uncertain and nuanced due to business needs, legal matters, or possible damage. With the help of the security automation matrix, companies can understand where automation can be applied independently, what needs recommendations, and what actions require the involvement of people.
The importance of this distinction is growing with the expansion of AI activity in the field of security. While an AI algorithm may be able to catch any suspicious activity and suggest an adequate action, making a decision on blocking a crucial production system would be drastically different.
Why Security Autonomy Matters?
Security teams are faced with a growing attack surface. They might deal with thousands of devices, applications, connected devices, and cloud resources, all of which can trigger security events. Security teams can now expect to receive large quantities of alerts, including false ones.
Humans cannot investigate every incident perfectly. This is where automation comes in. It can help to cope with lesser executions while giving security professionals freedom to investigate crucial events.
This raises a question of how to find a middle ground. Too little automation leads to a situation where security teams are inundated with needless alerts, while too much can create new issues.
Four Levels of Security Autonomy
The Security Autonomy Matrix consists of four levels of security autonomy: human-led, human-assisted, machine-led with human oversight, and fully autonomous. These levels should not be viewed as absolute categories, as there may be other security functions within an organization that utilize different levels of independence.
Level One: Human-Led Security
At this level, human beings perform the most work needed for security purposes. Security experts monitor alerts, examine logs, detect suspicious behavior, identify vulnerabilities, and respond accordingly.
However, technology plays a critical role at this level, but professionals are still the ones making the final decision. This model is suitable for sensitive issues or small enterprises.
Yet, human security is not working effectively when there are numerous security incidents. Moreover, manual work might slow things down.
Level Two: Human-Assisted Security
The second level is when the services implement automation to assist human experts. Security systems are able to gather data, correlate occurrences of events, add context to an alert and assess possible threats by means of automation.
An analyst gets an alert that already includes additional information regarding the device, user, IP address, application, etc. Besides, an AI can summarize an incident and propose investigation steps. The decision is still made by the person; the technology only minimizes the amount of work done manually.
Level Three: Machines Doing the Job with Human Assistance
Automated systems on this level are capable of performing some security tasks without human input except for those actions that would involve more significant risks.
For instance, a system may automatically block a malicious domain, cut off an endpoint that shows suspicious behavior, terminate a hijacked session, or turn off an evidently malicious program.
Actions that may have more serious consequences can be authorized only by a security professional. That is why it is possible to deal with widespread threats much quicker than if everything is done manually.
Level Four: Highly Autonomous Security
The highest level refers to security systems that could detect, analyze, decide, and respond independently to various types of threats.
In this system, security telemetry could be used to analyze security data on an ongoing basis, recognize the patterns of attacks, analyze connections between the different events, and use responses that could be either predefined or newly chosen dynamically.
AI-based technologies or ML could be expected to facilitate this model by processing huge volumes of data and adjusting to stable patterns. But once again, models of highly autonomous cybersecurity must be governed with great caution.
In particular, it means that a security system that makes decisions independently of human supervision must be extremely reliable, understandable, transparent, and operate in accordance with the proper set of guidelines.
In other words, full autonomy should be treated with great caution, especially in the case of sensitive environments.
Detection and Response through the Autonomy Matrix
The automation of security detection is simpler than that of other complex decisions.
For instance, the tracking of a file that is known to be dangerous and is connected to a certain threat could be done automatically.
Likewise, if there are examples of failed logins and usage of evil infrastructure, it can lead to an automatic investigation. The fault is a little complex.
If the connection is being stopped automatically, it does not mean a lot to the business. Manual shutdown of the servers might be problematic, especially if it is done inappropriately.
The Importance of Artificial Intelligence
Artificial intelligence plays an important role in making security autonomous. Security automation based on the traditional model is implemented based on known rules; the system performs a pre-arranged action when a specific condition occurs.
Artificial intelligence, in contrast, is capable of recognizing much more complicated situations and patterns. This allows it to analyze huge amounts of telemetry data, find relations between events, summarize incidents, detect anomalies, and help security experts gain insight into possible ways of an attack.
Generative AI can also facilitate the work of the security team as it helps to translate complicated technical information into something more understandable. Nonetheless, AI cannot replace the expertise of people in the field of security.
Since AI systems are prone to mistakes, misinterpretation of the context of information, and can be abused by hackers, security creation, therefore, has to be based on the safe use of AI systems rather than on blind trust in AI system decisions.
Building a Security Autonomy Approach
To start developing a security autonomy strategy, businesses should assess their present security operations. Each task should subsequently be analyzed in terms of its complexity, frequency, risk, and effect. High-frequency, low-risk tasks make good candidates for automation.
Any task that carries a considerable level of uncertainty or could have a significant effect on business outcomes should be kept under human control or validation. Organizations should proceed with automation gradually and implement an incremental approach. Instead of aiming to create a fully automated SOC, businesses may start by automating the enrichment of alerts, supporting investigations, creating tickets, and setting in motion low-risk remediation processes.
As soon as confidence in automated solutions grows, automating more complex workflows will become possible. Each automated action should be recorded and traceable.
The Future of the Security Autonomy Matrix
In the future of the Security Autonomy Matrix, the line separating automated cybersecurity processes from those driven by humans will be increasingly blurred. As AI will be able to analyze larger amounts of security data, businesses will surely automate more processes.
Security solutions will be more likely to function as interconnected systems, and not standalone instruments anymore. For instance, AI technology can detect something suspicious, analyze relevant endpoint behaviour, review cloud logs, identify the attack process, and generate a relevant response.
Nevertheless, full automation is not expected so far. Since cybersecurity is about uncertainty, risk, legal issues, consequences etc., which can only be assessed with the help of human understanding.
Summary
In summary, the Security Autonomy Matrix serves as a helpful guide for companies on how to employ automation in cybersecurity by promoting a gradual acceptance of autonomous systems instead of an abrupt change from unautomated operations to full automation.
Various security functions lend themselves well to automation due to their repetitive nature and low-stakes risk. Some functions, however, need human oversight because the errors made in their course may have dire operational or business implications.
Artificial intelligence broadens the list of operations available for automation in security, from the assessment of alerts and detection of threats to prioritization of vulnerabilities and incident response.
Yet an increase in automation should go hand in hand with tighter governance. Companies should set clear limits on what situations or tasks can be automated, ensure the efficiency of security telemetry, establish least-privilege controls, track automated decisions, and set in place escalation procedures in case of critical events.
The goal is not to construct a security setup with machines taking all the decisions. Instead, the aim is to set up an arrangement whereby machines and people participate in the different processes at which they excel.
