Automating incident response and mitigation process for networks and endpoint devices has been a tough nut to crack. Automation includes automatically re-imaging endpoint devices, isolating devices from corporate networks, or shutting down particular networks. Full incident response automation is probably three to five years from becoming reality, analyst says. Companies can also approach automation without a machine learning system, if they already have incident response playbooks in use at their company, Ariel Tseitlin, partner at Foster City, California, said.”]

