Logo PTI Logo FedCSIS

Position Papers of the 21st Conference on Computer Science and Intelligence Systems

Annals of Computer Science and Information Systems, Volume 48

Towards Intelligent Incident Response: A Review of Adaptive and Automated Planning and Orchestration Approaches

, , ,

DOI: http://dx.doi.org/10.15439/2026F5303

Citation: Abir Benhizia, , ,

Full text

Abstract. The growing use of Artificial Intelligence (AI) by cyber attackers is changing the threat landscape. It enables attackers to launch adaptive and rapid attacks, which challenge traditional incident response activities. While Security Operations Centers (SOCs) increasingly leverage standardized processes, automation, and playbooks to sweeten response efficiency, investigation and containment phases continue to be the main bottleneck and the reason that drives elevated Mean Time To Respond (MTTR). This paper examines the latest studies on how to improve these activities' workload, using a global incident response playbook presented as a structured diagram of steps and decisions, based on the BPMN 2.0 standard. We discuss the effectiveness of a set of AI-assisted investigation and playbook/AI-driven containment approaches on MTTR reduction and identify limitations in real-world applicability, especially for long-term containment, and we propose our approach to address these gaps, providing a more adaptive, context-aware framework for sustained incident response.

References

  1. A. Ahmad, K. C. Desouza, S. B. Maynard, H. Naseer, and R. L. Baskerville. How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, Aug. 2020. https://dx.doi.org/10.1002/asi.24311.
  2. M. Akbari Gurabi, L. Nitz, A. Bregar, J. Popanda, C. Siemers, R. Matzutt, and A. Mandal. Requirements for Playbook-Assisted Cyber Incident Response, Reporting and Automation. Digital Threats: Research and Practice, Sept. 2024. https://dx.doi.org/10.1145/3688810.
  3. Z. O. Akinpelu. Artificial Intelligence in Offensive and Defensive Cybersecurity: Opportunities, Risks, and Ethical Boundaries. Iconic Research and Engineering Journals, Aug. 2025. issn: 2456-8880.
  4. M. Al-Azzawi, D. Doan, T. Sipola, J. Hautamäki, and T. Kokkonen. Red Teaming with Artificial IntelligenceDriven Cyberattacks: A Scoping Review, Mar. 2025. https://dx.doi.org/10.48550/arXiv.2503.19626.
  5. Anthropic Threat Intelligence. Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign. https://www.anthropic.com/news/disruptingAI-espionage, Nov. 2025. Threat intelligence report.
  6. K. G. Boamah, A. Asante, A. Timean, and K. F. Okai. Artificial intelligence integration in cyber incident response teams to enable faster containment, forensic accuracy, and resilient business continuity. International Journal of Science and Research Archive, Oct. 2025. https://dx.doi.org/10.30574/ijsra.2025.17.1.2933.
  7. R. A. Bridges, A. E. Rice, S. Oesch, J. A. Nichols, C. Watson, K. Spakes, S. Norem, M. Huettel, B. Jewell, B. Weber, C. Gannon, O. Bizovi, S. C. Hollifield, and S. Erwin. Testing SOAR Tools in Use. Computers & Security, June 2023. https://dx.doi.org/10.1016/j.cose.2023.103201.
  8. D. Canavese, R. Laborde, A. Laraba, A. Ferreira, and A. Benzekri. Game of Zones: An Automated IntentBased Network Micro-segmentation Methodology. IEEE Symposium on Network Operations and Management, May 2025. https://dx.doi.org/10.1109/NOMS57970.2025.11073630.
  9. S. A. Chamkar, Y. Maleh, and N. Gherabi. SOC Analyst Performance Metrics: Towards an optimal performance model. EDPACS, Sept. 2023. https://dx.doi.org/10.1080/07366981.2023.2259046.
  10. P. Cichonski, T. Millar, T. Grance, and K. Scarfone. Computer Security Incident Handling Guide. Nist special publication, National Institute of Standards and Technology, Aug. 2012. https://dx.doi.org/10.6028/NIST.SP.800-61r2.
  11. A. Clemm, L. Ciavaglia, L. Z. Granville, and J. Tantsura. Intent-Based Networking - Concepts and Definitions. Technical report, RFC Editor, Oct. 2022. https://dx.doi.org/10.17487/RFC9315.
  12. CrowdStrike Reserach Team. CrowdStrike 2025 European Threat Landscape Report. https://www.crowdstrike.com/explore/crowdstrikecontent/crowdstrike-2025-european-threat-landscapereport/, 2025.
  13. Elastic security Labs. Elastic-global-threat-report-2025. https://www.elastic.co/resources/security/report/globalthreat-report, 2025.
  14. P. Empl, D. Schlette, L. Stöger, et al. Generating ICS vulnerability playbooks with open standards. International Journal of Information Security, Dec. 2023. https://dx.doi.org/10.1007/s10207-023-00760-5.
  15. Ismail, R. Kurnia, Z. A. Brata, G. A. Nelistiani, S. Heo, H. Kim, and H. Kim. Toward Robust Security Orchestration and Automated Response in Security Operations Centers with a Hyper-Automation Approach Using Agentic Artificial Intelligence. Information, Apr. 2025. https://dx.doi.org/10.3390/info16050365.
  16. B. Kabbani, R. Laborde, F. Barrere, and A. Benzekri. Specification and Enforcement of Dynamic Authorization Policies Oriented by Situations. In 2014 6th International Conference on New Technologies, Mobility and Security (NTMS). IEEE, May 2014. https://dx.doi.org/10.1109/NTMS.2014.6814050.
  17. J. Kinyua and L. Awuah. AI/ML in Security Orchestration, Automation and Response: Future Research Directions. Intelligent Automation & Soft Computing, Jan. 2021. https://dx.doi.org/10.32604/iasc.2021.016240.
  18. P. Kral. The Incident Handler’s Handbook: GIAC (GCIH) Gold Certification. https://sansorg.egnyte.com/dl/SzUc95nE0x, Dec. 2011.
  19. C. Luo, J. Goncalves, E. Velloso, and V. Kostakos. A Survey of Context Simulation for Testing Mobile Context-Aware Applications. ACM Comput. Surv., Feb. 2020. https://dx.doi.org/10.1145/3372788.
  20. S. Mahajan, M. Khurana, and V. V. Estrela. Applying Artificial Intelligence in Cybersecurity Analytics and Cyber Threat Detection. In Applying Artificial Intelligence in Cybersecurity Analytics and Cyber Threat Detection, June 2024. https://dx.doi.org/10.1002/9781394196470.fmatter.
  21. G. Malik. Business Continuity & Incident Response. Journal of Information Systems Engineering and Management, Apr. 2025. https://dx.doi.org/10.52783/jisem.v10i45s.8891.
  22. P. Maynard, Y. Cherdantseva, A. Shaked, P. Burnap, and A. Mehmood. Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure. Journal of Cybersecurity and Privacy, June 2026. https://www.mdpi.com/2624-800X/6/4/109.
  23. MITRE. MITRE D3FEND: A Knowledge Graph of Cybersecurity Countermeasures. https://d3fend.mitre.org/. Accessed 2026-06-28.
  24. N. Mohamed. Cutting-edge advances in AI and ML for cybersecurity: a comprehensive review of emerging trends and future directions. Cogent Business & Management, Dec. 2025. https://dx.doi.org/10.1080/23311975.2025.2518496.
  25. A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone. Incident response recommendations and considerations for cybersecurity risk management: A csf 2.0 community profile. NIST Special Publication 800-61 Rev. 3, National Institute of Standards and Technology, Apr. 2025. https://dx.doi.org/10.6028/NIST.SP.800-61r3.
  26. S. Rose, O. Borchert, S. Mitchell, and S. Connelly. Zero Trust Architecture. Technical report, National Institute of Standards and Technology, Aug. 2020. https://dx.doi.org/10.6028/NIST.SP.800-207.
  27. S. Roy. AgenticCyber: A GenAI-Powered MultiAgent System for Multimodal Threat Detection and Adaptive Response in Cybersecurity, Dec. 2025. https://dx.doi.org/10.48550/arXiv.2512.06396.
  28. D. Schlette, P. Empl, M. Caselli, T. Schreck, and G. Pernul. Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing Factors. In 2024 IEEE Symposium on Security and Privacy (SP), May 2024. https://dx.doi.org/10.1109/SP54263.2024.00060.
  29. M. Turcotte, F. Labrèche, and S.-O. Paquette. Automated Alert Classification and Triage (AACT): An Intelligent System for the Prioritisation of Cybersecurity Alerts, 2025. https://dx.doi.org/10.48550/arXiv.2505.09843.
  30. Unit 42. 2025 Unit 42 Global Incident Response Report. https://www.paloaltonetworks.com/engage/unit422025-global-incident-response-report, 2025.
  31. M. Vielberth. Security Operations Center (SOC). In S. Jajodia, P. Samarati, and M. Yung, editors, Encyclopedia of Cryptography, Security and Privacy. Springer Berlin Heidelberg, Feb. 2021. https://dx.doi.org/10.1007/978-3-64227739-9 1680-1.
  32. M. Zych, V. Mavroeidis, K. Fysarakis, and M. Athanatos. Reviewing BPMN as a Modeling Notation for CACAO Security Playbooks. In 2023 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE, July 2023. https://dx.doi.org/10.1109/CSR57506.2023.10224922.