Dynamic Playbook Workflows for Cross-Department Incident Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing incident response systems, such as those based on SOAR frameworks, are inadequate for responding to a wide variety of risks including natural disasters and equipment failures due to the inability to define workflows in advance for all possible incidents, leading to insufficient recovery and maintenance of business KPIs.

Innovation Solution

An incident response system that generates and configures processing workflows based on a playbook database, selecting appropriate workflows for individual risks and incorporating external systems and components, allowing for dynamic response to various incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static and fixed workflow is defined in a playbook for cyber attacks, then response effectiveness against cyber attacks is improved, but the system cannot respond to a wide variety of risks including natural disasters and equipment failures

Engineering Contradiction:
Improveresponse effectivenessVSAvoidresponse coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static workflow system into a dynamic one by introducing a workflow generation section that creates customized workflows at runtime based on incident type and severity. The system dynamically selects from multiple playbook templates (cyber attack playbook, natural disaster playbook, equipment failure playbook) and generates appropriate workflows rather than relying on a single fixed workflow, thereby achieving both reliability for specific incident types and versatility across diverse risks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of workflow configuration from fixed to variable by introducing incident-specific parameters (incident type, severity level, affected systems) that determine which playbook template is selected and how the workflow is customized. This allows the same system to adapt its response parameters based on the specific incident characteristics, resolving the contradiction between having a reliable fixed process and needing versatile response coverage.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If conventional point solutions are adopted by each business and department individually, then implementation simplicity is improved, but adequate response to wide-ranging risks is not achieved

Engineering Contradiction:
Improveimplementation simplicityVSAvoidcross-departmental response capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal incident response system that serves multiple departments and incident types through a centralized platform. The system provides multi-functionality by handling cyber attacks, natural disasters, and equipment failures through a unified architecture with standardized interfaces. Each department can adopt the system individually while it automatically coordinates cross-departmental responses when incidents require multiple departments, thus maintaining implementation simplicity while achieving versatile response capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the incident response capability into modular components (incident detection module, playbook selection module, workflow generation module, workflow execution module) that can be independently deployed and configured. This segmentation allows individual departments to implement the system at their own pace while the modular architecture enables seamless integration and coordination across departments when cross-departmental response is required.

Inventive Principle:
Principle #1Segmentation

3Speed

If all workflows for individual incidents are predefined using IF-THEN rules, then response speed is improved, but the system cannot handle the complexity of diverse risk incidents

Engineering Contradiction:
Improveresponse speedVSAvoidworkflow configuration complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-defining playbook templates with common response patterns for different incident types (cyber attack playbook, natural disaster playbook, equipment failure playbook). These templates contain pre-configured workflows for typical scenarios, enabling rapid response for common incidents. When novel or complex incidents occur, the workflow generation section dynamically creates appropriate workflows by combining and customizing these pre-defined templates, thus maintaining fast response speed while handling complex diverse risks without requiring all possible workflows to be explicitly predefined.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4583023A1Incident handling system and incident handling method
Publication Date: 2025.07.09 HITACHI LTD
  • EP4583023A1 patent drawingFigure 1
  • EP4583023A1 patent drawingFigure 2
  • EP4583023A1 patent drawingFigure 3

AI summary

Provided are an incident response system and an incident response method that are able to generate and configure a processing workflow that includes a combination of external systems and individual processing components depending on the type of risk in order to respond to individual incidents. The incident response system, which responds to the individual incidents, includes a playbook DB, a playbook selection section, a workflow generation section, and a workflow engine section. The playbook DB stores processing workflows which are response flows for incidents of risks, as playbooks for individual types of risks. The playbook selection section acquires incident information regarding an incident that has occurred or appears to occur, and extracts a corresponding one of the playbooks that is appropriate for the incident from the playbooks created for the individual types of risks. The workflow generation section generates the processing workflows appropriate for the individual incidents in accordance with the extracted playbook. The workflow engine section outputs a process for the incident.