Skip to main content
Cloud / AWS / Products / AWS Security Incident Response: Managed Incident Response

AWS Security Incident Response: Managed Incident Response

AWS Security Incident Response automatically triages security findings and gives you 24/7 access to AWS security engineers.

Security, Identity & Compliance
Pricing Model Billed by the number of security findings ingested, with a free monthly allowance; included at no additional cost with the Enterprise Support and Unified Operations plans
Availability Per provider / see official documentation
Data Sovereignty Per provider / see official documentation
Reliability Per provider / see official documentation SLA

What is AWS Security Incident Response?

AWS Security Incident Response is a managed service that, according to AWS, helps you prepare for, respond to, and recover from security events faster and more effectively. It combines automated workflows with 24/7 access to AWS security engineers.

It works from security findings produced by Amazon GuardDuty and by third-party detection tools connected through AWS Security Hub. AWS made the service generally available on 1 December 2024.

Core Features

  • Automated triage: Continuous monitoring of findings from Amazon GuardDuty and connected third-party tools; according to AWS, over 99 percent of the findings processed are filtered out automatically
  • Proactive case creation: For critical events the service opens a security case on its own and notifies the stakeholders you designated
  • AI-assisted investigation: AWS describes AI-powered investigation capabilities as well as automated operational tasks and containment actions
  • Centralised communication: A shared platform for communication and coordination across everyone involved
  • 24/7 access to AWS engineers: Direct access to Security Incident Response engineers who, per AWS, respond within minutes; at launch AWS named 24/7 access to the AWS Customer Incident Response Team (CIRT)
  • Activation through AWS Organizations: Set up from the management account or a delegated administrator account
  • Partner involvement: Coordination with specialised partner security providers

Typical Use Cases

Relieving the security team: Automated triage reduces the volume of findings your team has to review manually and surfaces the ones that matter.

Escalation without an in-house 24/7 team: Organisations without a round-the-clock security operations centre use direct access to AWS security engineers as reinforcement.

Coordinated incident handling: Communication, task assignment, and tracking of an incident run through one shared interface instead of scattered channels.

Preparing for the real thing: As AWS presents it, the service addresses not only response but also preparation and recovery.

Benefits

  • Substantially less manual review effort thanks to automated triage
  • Access to AWS security engineers around the clock, with response within minutes per the provider’s statement
  • Existing detection tools connect through AWS Security Hub instead of a separate tool landscape
  • Free allowance of 10,000 findings per month, tiered pricing above that
  • Included at no additional cost with the Enterprise Support and Unified Operations plans
  • Membership can be cancelled at any time

Integration with innFactory

As an AWS Reseller, innFactory supports you with AWS Security Incident Response: activation through AWS Organizations, connecting Amazon GuardDuty and AWS Security Hub, defining escalation paths and points of contact, and aligning the service with your existing incident response processes.

Typical Use Cases

Security operations
Incident response
Triage of security findings
24/7 escalation to AWS experts

Frequently Asked Questions

What does AWS Security Incident Response do?

According to AWS, the service helps you prepare for, respond to, and recover from security events. It continuously monitors and triages security findings from Amazon GuardDuty and from third-party detection tools connected through AWS Security Hub, combining that automation with access to AWS security engineers.

How many findings does automated triage filter out?

On its product page AWS states that automated triage filters over 99 percent of the findings processed. When an event is assessed as critical, the service proactively opens a security case and notifies the stakeholders you designated as your incident response team.

How do I reach the AWS security engineers?

AWS describes 24/7 direct access to Security Incident Response engineers who, per the product page, respond to requests within minutes. At launch AWS also highlighted direct 24/7 access to the AWS Customer Incident Response Team (CIRT). You can open and handle cases yourself as well.

How is the service activated?

According to the FAQ you enable AWS Security Incident Response across AWS Organizations from your management account or a delegated administrator account. AWS additionally recommends enabling Amazon GuardDuty and AWS Security Hub.

How is it billed?

Billing is based on the number of security findings ingested from Amazon GuardDuty and supported third-party tools through AWS Security Hub. The first 10,000 findings per month are free, above which tiered pricing applies. The service is included at no additional cost with the AWS Support plans Enterprise Support and Unified Operations. You can cancel your membership at any time; it remains active through the current billing cycle.

Since when is the service available?

AWS made AWS Security Incident Response generally available on 1 December 2024. For current Region availability, consult the official documentation.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of AWS (official documentation). This page does not represent an offer by AWS.

AWS Cloud Expertise

innFactory is an AWS Reseller with certified cloud architects. We provide consulting, implementation, and managed services for AWS.

Ready to start with AWS Security Incident Response: Managed Incident Response?

Our certified AWS experts help you with architecture, integration, and optimization.

Schedule Consultation