Automatic incident handling – Experiences from laboratory trials
Publish date: 2026-03-02
Report number: FOI-R--5878--SE
Pages: 40
Written in: Swedish
Keywords:
- cyber defence
- incident handling
- cyber range
- intrusion detection
Abstract
FOI has participated in three projects that, in different ways, attempted to automate the incident handling process. In these projects, a large number of technical solutions for various subprocesses have been developed, along with proposals for how they should be integrated. In all projects, FOI has been responsible for creating test cases in which fictional incidents play out in a lab environment. These test cases have been used to test individual techniques and components, as well as in more comprehensive demonstrations where incidents play out. The tests and demonstrations indicate that much remains before the incident handling process can be fully automated. There are practical obstacles that have been intentionally simplified in the research projects, and only a few steps in the developed toolchains function as intended.