Breach news and various studies show that organizations are taking too long to remediate critical vulnerabilities and respond to the tidal wave of alerts from the various protection and detection tools. Despite the significant investment Organizations have made in security, every incident still needs a response from the organization—and in some cases, the response needs to be lightning fast. The challenge is that most companies are still responding at “people speed”—following long runbooks, relying on multiple sources of data, moving data between spreadsheets, responding to long email threads, and creating manual reports. The incident response function is a chronically unstructured and unproductive process. But it doesn’t have to be. In this talk, we’ll address the challenges and dysfunction majority of organizations face responding to security incidents and events. In particular, how to operationalize the telemetry that is coming out of those investments in vulnerability management, protection, anddetection.