Event-Driven Security Workflows for Automated Incident Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security awareness training methods are inadequate in addressing specific security incidents and user behaviors, as they often rely on generic approaches that do not adapt in real-time and are not tailored to individual user actions or conditions, leading to ineffective responses to cybersecurity threats.

Innovation Solution

The development of event-driven orchestrated workflows that allow for the creation of customized security awareness training responses, triggered by specific user actions, conditions, and schedules, enabling automated and targeted remedial actions to be delivered via various channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If generic security awareness training approaches are used, then training coverage is broad, but training effectiveness is low

Engineering Contradiction:
Improvetraining effectivenessVSAvoidtraining system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The training system dynamically adapts to user behaviors and security incidents in real-time. Workflows automatically adjust training content, timing, and delivery based on detected user actions (e.g., phishing attempts, password violations) and organizational context, transforming static training into living, responsive interventions that evolve with security threats and user needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system delivers personalized training experiences tailored to individual users, groups, or organizations based on their specific risk profiles, behaviors, and contexts. Different users receive customized training content and approaches - for example, users with high-risk behaviors receive targeted remedial training while low-risk users receive periodic updates, ensuring training relevance and effectiveness for each audience segment

Inventive Principle:
Principle #3Local quality

2Speed

If real-time automated responses are implemented, then response timeliness is improved, but system complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoidworkflow system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

Security awareness workflows are pre-configured with automated actions, conditions, and timing parameters before security incidents occur. When incidents happen, the system executes predetermined responses immediately - such as automatically sending phishing awareness emails, triggering password reset flows, or initiating awareness campaigns - eliminating manual response delays while keeping the automation logic organized and manageable through template-based design

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces workflow automation as an intermediary layer between security incident detection and training delivery. This intermediary coordinates multiple systems (security monitoring, communication channels, training content management) through standardized workflow templates, managing complexity by abstracting the coordination logic into reusable patterns rather than requiring direct integration of all components

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If customized training responses are delivered, then training relevance is improved, but delivery complexity increases

Engineering Contradiction:
Improvetraining customizationVSAvoidtraining delivery operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The workflow system provides universal templates and patterns that can be applied across multiple training scenarios and delivery channels. Administrators select from pre-built workflow types (e.g., incident response, periodic training, targeted awareness campaigns) and configure parameters rather than building custom systems, while the same workflow engine handles diverse delivery methods including email, mobile notifications, and learning management systems through unified abstraction layers

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240073252A1Systems and methods for event-driven orchestrated workflows with automated actions in response to security incidents
Publication Date: 2024.02.29 KNOWBE4 INC
  • US20240073252A1 patent drawing
  • US20240073252A1 patent drawing
  • US20240073252A1 patent drawing

AI summary

Systems and methods are described for creating event-driven orchestrated workflows with automated actions in response to security incidents. In an example, a method is described that includes receiving an indication to create a workflow for automating a response to one or more users engaging in an action associated with a security incident and receiving a selection of the action associated with the security incident from a plurality of selectable actions. The selected action is configured into the workflow and configured to trigger execution of the workflow by a user of the one or more users taking the selected action.