L loyds Banking Group has transformed its cyberdefence operations as it looks to reduce alert fatigue and enable security teams to respond more quickly to genuine threats.
ALERT FATIGUE
Lloyds Banking Group rebuilds cyberdefence operations to tackle alert fatigue
Faced with hundreds of security alerts every day and teams working across separate processes, Lloyds Banking Group has overhauled its approach to detecting and responding to cyberthreats. The bank has built an engineering-led cyberdefence centre that uses automation to reduce routine workloads and allow security specialists to concentrate on higher-value analysis and threat hunting.
L loyds Banking Group has transformed its cyberdefence operations as it looks to reduce alert fatigue and enable security teams to respond more quickly to genuine threats.
The bank, which serves more than 30 million customers, previously generated around 300 security alerts during a typical 24-hour period. Analysts were required to investigate large numbers of events, including routine activity such as incorrectly entered passwords.
“ The problem we set out to solve is one every organisation is facing; human time spent on the least valuable work,” said Manija Poulatova, Director of Security Engineering and Operations at Lloyds Banking Group, according to a case study published by PwC.
The existing organisational structure also meant different security teams were responsible for individual stages of detection and response, resulting in incidents being passed between groups.
“ In our old way of working with our old processes and our old tooling, we were all in different teams,” said Daniel Horn, Cyber Security Manager at Lloyds Banking Group, in the PwC case study.“ And each had its own very fixed goals.”
Lloyds decided to rebuild its cyberdefence operation rather than transfer existing processes to a replacement platform. Working with PwC and Google Cloud, the bank developed a new cyberdefence centre on Google SecOps over a nine-month period.
The project adopted an‘ everything as code’ approach, with system configurations captured as code and managed centrally rather than individual tools being configured manually.
Automation now handles a significant proportion of the security workload.
“ Around 80 % of our alerts are processed through automation,” Poulatova said in the PwC case study.“ That means our people can focus on higher-value analysis, threat hunting and tuning the models and AI-based detections that sit underneath.”
The bank has also automated some incidents from initial detection through triage, investigation and resolution, while retaining human oversight of the models governing those processes.
According to Lloyds, the transformation has reduced the number of alerts generated over 24 hours from around 300 to as few as 10.
The changes have also altered how security teams operate. Rather than separate groups handling different stages of an incident, the same team can work across detection and response, giving engineers greater responsibility for understanding threats and improving future remediation.
The bank is now exploring how Artificial Intelligence can play a greater role in its cyberdefence operations as automation frees specialists from more repetitive tasks.
Matt Rowe, Chief Security Officer at Lloyds Banking Group, said in the PwC case study:“ As the organisation has been transforming, moving to modern technology and modern ways of working, we’ ve had to completely rebuild how security gets done as well.”
For Lloyds, the transformation represents a move away from a security operation dominated by alert volumes and hand-offs towards an engineering-led model designed to combine automation with human expertise.
WWW. INTELLIGENTCISO. COM 29