1. Automation
Many IT administrators have avoided automated responses to attacks, especially in conservative environments such as healthcare that are averse to false positives. Unfortunately, AI's attack speed means that human-level response times are no longer good enough. Automate where possible to reduce response latency.
A key success factor here is to set boundaries on AI agents reacting to attacks: Under what conditions can an account be disabled? An endpoint quarantined? A server taken off the network or blocked at the firewall?
Incident response plans must allow for automated actions. Plans should list what types of attacks need an immediate and automated action. Fortunately, AI tools can be much smarter, more dynamic and nuanced about both attack and mitigation risk than older cybersecurity systems, something healthcare leaders should take advantage of for their incident response plans.
2. Feedback and Training
Letting AI agents respond to attacks doesn't mean accepting their advice as perfect and not to be questioned. Human analysts need to be in the loop for high-impact actions. Incident response plans should recognize this dual path: low-risk actions taken automatically, to be approved or rejected later, and high-risk actions requiring sign-off and validation by an analyst.
Automating the easy stuff frees up analysts to dive deep on high-risk attacks. Isolating network segments, disconnecting federated trust, revoking administrative credentials — these high-impact actions should be part of the plan, but only after a human has given their OK.
Just as important is the feedback to AI controllers and agents: Every now and then, you must tell your tools, “Your recommendation was erroneous or unsupported.” Training AI tools should be part of the incident response plan, so that lessons learned won't be quickly forgotten.
3. Anomaly Detection
Intrusion prevention systems identifying indicators of compromise used to be the gold standard for network protection. The unpredictable nature of AI-driven attacks has now changed that. Setting AI loose on the massive amounts of telemetry data available from networks, middleboxes and servers to identify anomalous behavior is the best way to catch an attack that has never been seen before. Now is the time to add AI-driven anomaly detection to incident response plans as a primary indicator of attack or compromise.
