Automated response

Move from detection to a safe response
without losing control.

Build structured actions for common threats, require approval where it matters and keep a complete record of what changed and why.

Preview before executionNamed approvalsRollback controlsEvidence preserved
Response builder preview

Suspicious administrator access

Draft
01
Trigger

High-risk administrator login

New network + repeated failures + privileged account.

02
Preserve evidence

Capture session and related events

Store request metadata, timeline and affected account.

03
Contain

Revoke suspicious session

End the session without disabling the entire website.

04
Protect

Require password reset and MFA review

Guide the verified owner through secure recovery.

05
Notify

Alert account owner and security team

Send a concise summary with evidence and next steps.

Common response actions

Automate the repetitive parts. Protect human judgement.

×

Block malicious sources

Apply a time-limited block with reason, scope and expiry.

Revoke suspicious sessions

End affected sessions while preserving evidence for review.

Quarantine changed files

Move suspicious files out of service and preserve the original.

Restore a known-good version

Recover selected content or configuration with approval and rollback.

!

Escalate critical incidents

Notify named responders with an evidence-rich incident summary.

Verify recovery

Re-scan the website and confirm the original risk is no longer present.

Action policyDefault approval
Temporary IP blockAutomatic
Revoke one suspicious sessionOwner approval
Disable administrator accountTwo-person approval
Restore production backupTwo-person approval
Send customer notificationOwner approval
Approval by impact

Not every action should run the same way.

Set boundaries according to the potential effect on customers, data and website availability.

  • Least-disruptive actionPrefer narrow, temporary controls before broad shutdowns.
  • Scoped permissionsLimit who can create, approve and execute response rules.
  • Two-person controlsRequire additional approval for destructive or customer-facing actions.
  • Automatic verificationCheck whether the response actually resolved the original issue.
Full response record

Know what ran, who approved it and what happened next.

Original evidence

Preserve the trigger and related security events before changing the environment.

Decision history

Record approvals, comments, owners and rejected recommendations.

Action log

Keep exact timestamps, scope, systems touched and external integrations.

Outcome verification

Recheck the website and document whether the threat was contained or needs escalation.

Start from a proven workflow

Use a protection playbook instead of starting from a blank page.

Preview structured response flows for login abuse, malware, file changes, forms and payment pages.