
teissLondon2022 kicked off on Thursday, 8th September, with a panel discussion on how organisations can use stress-testing to refine their incident response capabilities. In another highly engaging panel discussion, experts outlined how to automate incident response when relying on the actions of remote colleagues and third parties.
The panel discussion involved participation from Mike Johnson, Global Cyber Threat and Incident Response Manager at Verifone, Oisín Fouere, the Head of Incident Response at KPMG, Stephen Green, Vice President Cyber Risk at Kroll, and Bruce McClane, Senior technology consultant at Manage Engine
According to the Office for National Statistics, the percentage of people in the UK who are working in hybrid environments rose from 13% in early February 2022 to 24% in May 2022. With a quarter of the workforce working from remote locations, the panel discussion revolved around whether this has had an impact on organisations’ incident response capabilities.
According to Stephen Green, organisations should have the right tools in place to attain visibility into the larger network and should have plans to deploy tools, un-deploy them, what elements of data to process, and the tools they need to process the data. They should also ensure that all remote workers sign in to VPNs and other software that can help monitor the network.
Bruce McClane said that the best practice to automate incident response for a hybrid workforce is to adopt the practice of SIEM (Security information and event management) and to combine it an advanced threat intelligence platform to create a correlation rule and a custom workflow. The platform can generate event logs from various platforms and solutions, irrespective of whether a remote worker connects to a VPN or not.
According to Oisín Fouere, there is no such thing as a completely automated response and recovery programme as there is always a degree of manual intervention that needs to happen. What an organisation can do is leverage existing ER and forensic triage capability that can generate raw data from endpoint systems and use automation capabilities in case they need to collect data from many diverse systems using client scalable forensic ingestion capabilities.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543