<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Research on automated security incident management in public cloud environments⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Oksana Sapsai</string-name>
          <email>oksana.sapsai.kb.2022@ipnu.ua</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yevhenii Martseniuk</string-name>
          <email>yevhenii.v.martseniuk@lpnu.ua</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Partyka</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleh Harasymchuk</string-name>
          <email>oleh.i.harasymchuk@lpnu.ua</email>
        </contrib>
      </contrib-group>
      <fpage>226</fpage>
      <lpage>249</lpage>
      <abstract>
        <p>Modern organizations are increasingly integrating public cloud platforms such as AWS, Azure, and Google Cloud Platform into their infrastructure to enhance flexibility and scalability. However, multicloud environments introduce new cybersecurity challenges. The human factor and careless use of access parameters to cloud resources can lead to serious threats. In particular, if an attacker gains access to authorization keys, they can not only take control of existing resources but also create new ones for their own purposes, such as carrying out attacks, distributing malware, or mining cryptocurrencies. Such incidents can quickly lead to financial losses, undermine user trust, and impact the stability of critical services. This study examines the use of Splunk SOAR (Security Orchestration, Automation, and Response) as a tool for the automatic detection, analysis, and response to threats in public cloud environments. The primary focus is on integrating Splunk SOAR with cloud provider APIs for dynamically blocking compromised resources and implementing detailed playbooks that allow for isolating threats at the level of individual components (virtual machines, network policies, user accounts). The research also explores the integration of Splunk for anomaly detection through Palo Alto Prisma as a comprehensive anomaly scanner, the use of HashiCorp Vault for credential protection, the implementation of a quarantine mode for isolating compromised resources, and improving incident response processes. The study results show that automating security processes with Splunk SOAR significantly reduces response time, minimizes the impact of the human factor, and lowers the risk of cloud infrastructure compromise. The proposed approach enhances an organization's resilience to threats in multi-cloud environments, ensuring an optimal balance between security, availability, and operational efficiency. Keywords-component: Splunk SOAR, public cloud environments, automated incident response, resource blocking, multi-cloud infrastructure, human factor, anomaly monitoring, cloud provider APIs.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;cloud security</kwd>
        <kwd>automation</kwd>
        <kwd>DevOps</kwd>
        <kwd>SOAR</kwd>
        <kwd>remediation</kwd>
        <kwd>incident management</kwd>
        <kwd>security operations</kwd>
        <kwd>threat intelligence</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>highlight the need for an automated, scalable, and intelligent solution for real-time detection,
analysis, and response to cloud security incidents.</p>
      <p>This study explores the application of an automated SOAR (Security Orchestration, Automation,
and Response) approach as a comprehensive solution for automating security incident management
in public cloud environments. The research focuses on integrating Palo Alto Prisma with cloud
provider APIs to detect and isolate compromised resources using automated scripts dynamically.
Key components include:
1. Anomaly monitoring through Palo Alto Prisma for detecting suspicious activities in cloud
environments.
2. Automated quarantine mechanisms (Quarantine Mode) to prevent security breaches with
minimal operational disruptions.
3. Integration with HashiCorp Vault to protect access credentials and prevent unauthorized
privilege escalation.
4. Granular resource blocking to mitigate threats without shutting down the entire cloud
environment.
5. Post-mortem analysis workflows for continuous security improvement and adaptive incident
response.</p>
      <p>
        The results of this study show that automated incident response using SOAR automation
significantly enhances cloud security by reducing response time, minimizing human intervention,
and ensuring effective resource isolation. By implementing structured response mechanisms and
leveraging automation, organizations can effectively mitigate threats while maintaining the
resilience and availability of their cloud infrastructure [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        The scientific novelty of this research lies in the development and practical implementation of a
multi-level architecture for automated security incident response in public cloud environments. The
proposed model integrates Splunk SOAR, Jenkins, and HashiCorp Vault, establishing a
comprehensive incident management framework. For the first time, a dynamically triggered
“RedButton” automation scenario is introduced for L2 SecOps teams, enabling real-time
orchestration of resource isolation across AWS, Azure, and GCP. This approach balances rapid
response, security, and operational continuity, while mitigating the risks of unauthorized access and
delayed remediation [
        <xref ref-type="bibr" rid="ref3 ref4 ref5 ref6">3–6</xref>
        ].
      </p>
      <p>Unlike traditional solutions where components operate in isolation, this model establishes a
unified automated response framework that integrates:</p>
    </sec>
    <sec id="sec-2">
      <title>1. threat detection tools (Prisma Cloud). 2. incident orchestration platforms (Splunk SOAR). 3. secure credential management systems (Vault). 4. infrastructure automation tools (Jenkins).</title>
      <p>
        The aim of this research is to develop a comprehensive architecture for automated security
incident response (SOAR) in multi-cloud environments that enables dynamic secrets management,
controlled infrastructure intervention, and scalability to environments with over 400 cloud accounts
without centralized administration. The research seeks to establish a formalized logic for
transforming anomalies into actionable infrastructure changes with authorization verification at
each stage, and to build a risk assessment model with quantitative impact metrics, including
economic valuation. Additionally, the goal is to integrate Zero Trust principles, UEBA, and machine
learning analytics into the decision-making process, and to implement a self-learning mechanism for
adaptive response policy updates based on accumulated experience, eliminating the need for manual
intervention [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>In contrast to existing solutions that are limited to alert generation or executing predefined
playbooks, the proposed model delivers a full response cycle—from threat detection to infrastructure
isolation—accompanied by self-documentation and audit reporting. This eliminates delays between
detection and action, reduces human dependency, enables effective scaling across hundreds of cloud
environments, and ensures compliance with security standards such as NIST 800-53, ISO 27001, and
SOC 2. The implementation of this model lays the foundation for next-generation self-managed
cloud security architectures operating in real-time with adaptive compliance capabilities.</p>
      <p>
        Numerous studies have explored the challenges and solutions related to cloud security and
automated incident response. Research such as [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] highlights the growing importance of
automation in cybersecurity, especially in the context of dynamic and scalable cloud environments.
      </p>
      <p>
        The concept of SOAR has evolved as a response to the need to reduce manual interventions and
increase the efficiency of Security Operations Centers (SOC). According to Suram [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], automation of
Identity and Access Management (IAM) plays a critical role in securing cloud platforms. Similarly,
Thokala [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] emphasizes the role of scalable cloud deployment and orchestration in maintaining
operational security in e-commerce systems.
      </p>
      <p>
        Recent studies research [
        <xref ref-type="bibr" rid="ref10 ref11">10, 11</xref>
        ] analyze shadow IT risks and centralized secret management,
pointing to the need for integrated orchestration tools like SOAR. These findings align with current
practices in leading organizations where tools such as Splunk SOAR and Prisma Cloud are used to
detect, classify, and respond to threats across public cloud environments.
      </p>
      <p>
        Furthermore, Soldatenko and Vik [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] investigated the use of infrastructure-as-a-service (IaaS)
and highlighted the operational benefits of automation in cloud infrastructure security. Other
research works [
        <xref ref-type="bibr" rid="ref13 ref14 ref15">13–15</xref>
        ] examine the intersection of AI, cloud pipelines, and blockchain-enabled
automation, pointing to promising directions for further enhancement of cloud security
management systems.
      </p>
      <sec id="sec-2-1">
        <title>2. Risk assessment and the role of SOAR in their mitigation</title>
        <p>
          In the context of ensuring information security in public cloud environments, a critical task is the
systematic identification and assessment of risks that may lead to data compromise or the disruption
of infrastructure integrity. Given the complexity of multi-cloud environments and the high
dynamics of change within them, the analysis of threats related to unauthorized access, weak
authentication mechanisms, and insufficient environment segmentation becomes particularly
relevant [
          <xref ref-type="bibr" rid="ref11 ref13">11, 13</xref>
          ].
        </p>
        <p>
          This research employed the risk assessment methodology defined by the NIST SP 800-30
standard, which is based on qualitative analysis of threats using two key parameters: the likelihood
of occurrence and the potential impact. This approach enabled the construction of a risk criticality
matrix, presented in Table 1. The identified risks are ranked by their level of criticality, providing a
foundation for developing an effective response strategy and designing robust security mechanisms
within multi-cloud environments [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ].
        </p>
        <p>
          The SOAR solution plays a pivotal role in minimizing risks associated with the security of public
cloud environments by enabling automated, rapid, and coordinated threat response. Its application
significantly reduces the time between risk detection and the implementation of mitigation
measures, which is critical in cases of unauthorized access or exploitation of vulnerabilities [
          <xref ref-type="bibr" rid="ref12 ref17">12, 17</xref>
          ].
Through integration with security monitoring systems, credential management platforms, and
infrastructure automation tools, SOAR establishes a unified response framework capable of
promptly neutralizing threats and isolating potentially compromised resources [
          <xref ref-type="bibr" rid="ref1 ref14">1, 14</xref>
          ].
        </p>
        <p>
          Furthermore, to enhance the effectiveness of automated incident management, it is advisable to
integrate information classification and risk assessment mechanisms based on SOC 2 Type II [
          <xref ref-type="bibr" rid="ref16 ref18">16,
18</xref>
          ]. The use of models that consider the interaction of antagonistic agents in cybersecurity systems
allows for more accurate prediction of potential threats and optimization of response scenarios [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
Additionally, the “Security-as-Code” approach facilitates the standardization of security policies and
reduces the time required to implement control measures across multi-cloud environments [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. As a
result, the SOAR system gains self-learning and adaptation capabilities to new attack types, thereby
increasing the overall security posture of the infrastructure [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
        </p>
        <p>
          Moreover, SOAR reduces the influence of the human factor in the response process, thereby
decreasing the likelihood of errors or delays in decision-making during incidents [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. The
incorporation of Zero Trust principles and User and Entity Behavior Analytics (UEBA) within SOAR
enables proactive detection of anomalies and potentially malicious behavior before a threat escalates
[
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. An additional advantage is the integration of machine learning mechanisms that ensure the
system’s self-learning capability based on prior incident experiences. This facilitates the continuous
adaptation of defense scenarios to emerging threat types, enhancing protection effectiveness in a
dynamic environment [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
Thus, the implementation of SOAR contributes to the development of a proactive and adaptive
information security system that not only reduces the probability of risk realization but also
mitigates the impact of incidents when they occur, ensuring compliance with contemporary
information protection standards [
          <xref ref-type="bibr" rid="ref21 ref8">8, 21</xref>
          ].
        </p>
        <sec id="sec-2-1-1">
          <title>2.1. Vulnerabilities of Cloud Infrastructure in the absence of monitoring</title>
          <p>
            The use of public cloud services without the implementation of proper monitoring tools and
automated controls creates significant preconditions for violations of the core attributes of
information security—confidentiality, integrity, and availability of data [
            <xref ref-type="bibr" rid="ref10 ref8">8, 10</xref>
            ] . The absence of
continuous observation of anomalous activity, the inadequacy of security event correlation
mechanisms, and weak control over authentication and authorization processes significantly
increase the likelihood of prolonged undetected presence of adversaries in cloud environments
(commonly referred to as dwell time) [
            <xref ref-type="bibr" rid="ref13 ref22">13, 22</xref>
            ].
          </p>
          <p>
            This situation complicates the timely detection of incidents and rapid response, thereby
increasing the risk not only of localized compromise of individual resources but also of access
escalation, threat propagation, and potential cascading impact on adjacent information systems [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ],
[
            <xref ref-type="bibr" rid="ref17">17</xref>
            ]. Moreover, the lack of centralized monitoring limits an organization’s ability to detect security
policy violations, anomalous user behavior, and unauthorized API usage, all of which are critical in
the context of multicloud infrastructure with complex topologies and multiple access points [
            <xref ref-type="bibr" rid="ref12 ref14">12, 14</xref>
            ].
Incident Analysis in Cloud Environments (2023–2025): The Impact of Absent Monitoring on the
Emergence of Critical Threats.
          </p>
          <p>
            In the context of the evolving digital ecosystem, particularly with the growth of multicloud
architectures, the issue of timely detection of information security incidents and adequate response
has become increasingly critical [
            <xref ref-type="bibr" rid="ref10 ref2">2, 10</xref>
            ] . The lack of integrated monitoring tools, automated analysis
of security events, and real-time threat response capabilities creates conditions for large-scale
compromises of information assets [
            <xref ref-type="bibr" rid="ref11 ref15">11, 15</xref>
            ].
          </p>
          <p>
            Analysis of several high-profile incidents recorded between 2023 and 2025 reveals typical
vulnerability patterns that enabled the execution of advanced and complex attacks [
            <xref ref-type="bibr" rid="ref1 ref14">1, 14</xref>
            ].
          </p>
          <p>The most illustrative cases include:



</p>
          <p>
            The 2023 compromise of the MOVEit platform, hosted on Azure Blob Storage, due to a SQL
injection in the absence of API call monitoring [
            <xref ref-type="bibr" rid="ref9">9</xref>
            ]. The incident led to the data breach of
over 500 organizations, including multinational corporations and U.S. government agencies.
A targeted attack on Microsoft Exchange Online (2023) by the Storm-0558 group, which used
a compromised signing key to forge OAuth tokens [
            <xref ref-type="bibr" rid="ref13">13</xref>
            ]. This resulted in unauthorized access
to the email accounts of U.S. government entities.
          </p>
          <p>
            The 2024 Snowflake incident, which caused a data breach of AT&amp;T users due to the absence
of multi-factor authentication and inadequate monitoring of user sessions [
            <xref ref-type="bibr" rid="ref23">23</xref>
            ].
          </p>
          <p>
            The 2025 compromise of the Sisense environment, which occurred due to hardcoded secrets
and the absence of inter-environment isolation [
            <xref ref-type="bibr" rid="ref8">8</xref>
            ], leading to the exposure of confidential
data belonging to government and corporate clients.
          </p>
          <p>Additional incidents recorded in 2025 further confirm the relevance of this issue:

</p>
          <p>
            Zero-day vulnerability CVE-2025-53770 in Microsoft SharePoint Server, which enabled
spoofing attacks and resulted in the compromise of at least 75 servers [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ].
          </p>
          <p>
            The Azure Blob Storage exposure incident at TalentHook, which led to the disclosure of over
26 million resumes containing personal data, highlighting the criticality of configuration
errors [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ].
          </p>
          <p>
            A massive data breach stemming from an attack on Oracle Cloud authentication services
(SSO/LDAP), which compromised over 6 million user accounts [
            <xref ref-type="bibr" rid="ref2">2</xref>
            ].
          </p>
          <p>
            The exploitation of CVE-2025-3928 in Commvault Metallic, which allowed unauthorized
access to clients’ Microsoft 365 environments and underscored the risks of relying on
thirdparty SaaS solutions without sufficient monitoring [
            <xref ref-type="bibr" rid="ref17">17</xref>
            ].
          </p>
          <p>An academically grounded summary of these cases is presented in Table 2.</p>
          <p>
            All of the aforementioned cases highlight the limitations of traditional security approaches in the
absence of adaptive monitoring, proper access management, and automated response mechanisms
[
            <xref ref-type="bibr" rid="ref10 ref24">10, 24</xref>
            ]. As a result, threat actors remain undetected in the system for extended periods (dwell time),
escalate attacks to interconnected components, and cause large-scale asset compromise [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ].
          </p>
          <p>The use of SOAR-type systems addresses these shortcomings by enabling:</p>
          <p>Snowflake /
AT&amp;T</p>
          <p>Compromise of
customer accounts</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Snowflake FinSec</title>
    </sec>
    <sec id="sec-4">
      <title>SharePoint</title>
      <p>CVE-202553770
Access to banks’
financial data</p>
    </sec>
    <sec id="sec-5">
      <title>Zero-day attack on SharePoint Server</title>
    </sec>
    <sec id="sec-6">
      <title>TalentHook / Public container</title>
      <p>Azure Blob with 26 million</p>
      <p>résumés
Oracle SSO / Attack on
LDAP authentication</p>
      <p>service
Commvault / Vulnerability in Third-party
Jupiter Commvault Metallic SaaS
SaaS solution vulnerability</p>
    </sec>
    <sec id="sec-7">
      <title>Exploited Vulnerability SQL injection</title>
    </sec>
    <sec id="sec-8">
      <title>OAuth token forgery</title>
    </sec>
    <sec id="sec-9">
      <title>Lack of MFA</title>
    </sec>
    <sec id="sec-10">
      <title>Causes of</title>
      <p>Compromise
Lack of API
monitoring, low
transparency of
calls
Key
compromise,
lack of token
control</p>
    </sec>
    <sec id="sec-11">
      <title>Poor session control, lack of UEBA</title>
    </sec>
    <sec id="sec-12">
      <title>Privileged No Zero Trust, service weak access accounts audit, lack of UEBA</title>
      <p>Zero-day / Lack of
spoofing verification,
non-isolated
traffic
Misconfigurati Lack of access
on control,
misconfiguration
Authentication Lack of domain
compromise isolation, poor
account security
Lack of
monitoring,
absence of
behavioral
analytics</p>
    </sec>
    <sec id="sec-13">
      <title>Consequences</title>
    </sec>
    <sec id="sec-14">
      <title>Data breach</title>
      <p>affecting 500+
organizations
(BBC, Shell, BA)
Access to emails
of 25
organizations,
including the US
government
Compromise of
data from 160+
organizations,
metadata leak
Exfiltration of
transactions from
several banks</p>
    </sec>
    <sec id="sec-15">
      <title>Compromise of</title>
      <p>75 servers,
including
government ones
Massive leak of
personal data</p>
    </sec>
    <sec id="sec-16">
      <title>Compromise of 6 million user accounts Access to</title>
      <p>Microsoft 365
environments</p>
      <p>Real-time automated verification of access configuration parameters.</p>
      <p>Execution of immediate response scenarios through integrated playbooks.</p>
      <p>Isolation and disconnection of compromised infrastructure components.</p>
      <p>
        Formalized auditing of response actions, which ensures event traceability and compliance
with regulatory requirements [
        <xref ref-type="bibr" rid="ref18 ref25">18, 25</xref>
        ].
      </p>
      <p>
        Thus, the updated overview of threats observed in 2025 confirms the necessity of transitioning to
a proactive, automated model for cloud security—one in which SOAR solutions play a critical role in
risk mitigation and the enhancement of digital infrastructure resilience [
        <xref ref-type="bibr" rid="ref14 ref26">14, 26</xref>
        ].
      </p>
      <sec id="sec-16-1">
        <title>2.3. Economic impact of Security incidents in Cloud Environments</title>
        <p>
          Beyond the technical threat vectors associated with cloud infrastructure compromise, a critical
rationale for implementing integrated monitoring and automated response systems lies in their
economic viability. According to IBM Security’s “Cost of a Data Breach Report 2024” [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ], the
average cost of a single data breach in a cloud environment is estimated at $5.17 million. In
multicloud architectures with fragmented access control, these figures may rise significantly, elevating
financial risk for organizations lacking sufficient automation in their security processes [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>
          The MOVEit platform incident (2023) exemplifies both the scale and cost of impact mitigation.
Independent audit reports estimate total losses due to unauthorized access to Azure Blob Storage at
over $410 million [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. This figure encompasses costs related to breach containment, regulatory fines
(GDPR, HIPAA), litigation from affected parties, and investments in reputational recovery.
        </p>
        <p>
          Similarly, the leak of 26 million résumés caused by a misconfiguration of Azure Blob Storage by
TalentHook (2025) demonstrated that even non-malicious errors can result in severe economic
consequences [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. Direct damages in this case amounted to several million dollars, with a
significant portion attributed to reputational harm, increased cyber insurance premiums, and
forensic analysis expenses (see Table 3) [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ].
        </p>
        <p>The 2025 compromise of Oracle Cloud’s authentication infrastructure, resulting in the theft of
over 6 million user accounts, highlighted the economic vulnerability of centralized access systems
such as SSO and LDAP. Due to lateral movement, attackers escalated privileges and compromised
adjacent services. Cumulative losses for Oracle and its partners are estimated between $4.5 million
and $20 million, depending on industry sector, regulatory exposure, and the depth of the breach
[2, 11].</p>
        <p>
          According to the same IBM report, organizations without SOAR-class solutions take, on average,
76 days longer to detect and contain a breach [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. Increased dwell time directly correlates with
breach severity and financial impact, while complicating compliance audits for SOC 2, ISO/IEC
27001, and PCI DSS standards [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>
          Thus, the implementation of automated security systems—especially those based on SOAR, Zero
Trust, and UEBA concepts—not only enhances technical resilience but also optimizes incident
response expenditures. Public ROI evaluation models in cybersecurity indicate that deploying a
fullfledged SOAR solution can reduce economic losses from incidents by at least 25–50% compared to
traditional reactive security models [
          <xref ref-type="bibr" rid="ref13 ref15">13, 15</xref>
          ].
        </p>
        <sec id="sec-16-1-1">
          <title>3. Threat detection tools and automated response systems as the foundation of cloud security strategy</title>
          <p>
            An effective strategy for ensuring information security in public cloud environments requires the
integration of two key components: Threat Detection Tools and Security Orchestration,
Automation, and Response (SOAR) systems. This dual approach enables not only comprehensive
real-time monitoring of the cloud infrastructure’s state but also the generation of adaptive responses
to a wide range of threats, taking into account their nature, criticality, and potential impact on
organizational assets [
            <xref ref-type="bibr" rid="ref2 ref9">2, 9</xref>
            ].
          </p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-17">
      <title>Platform / Component</title>
    </sec>
    <sec id="sec-18">
      <title>Azure Blob Storage</title>
    </sec>
    <sec id="sec-19">
      <title>Microsoft Exchange Online Storm-0558 (2023)</title>
    </sec>
    <sec id="sec-20">
      <title>Snowflake / AT&amp;T (2024)</title>
    </sec>
    <sec id="sec-21">
      <title>Snowflake (multi-cloud)</title>
    </sec>
    <sec id="sec-22">
      <title>Sisense Snowflake / compromise (2025) Sisense</title>
    </sec>
    <sec id="sec-23">
      <title>SharePoint CVE-2025-53770</title>
    </sec>
    <sec id="sec-24">
      <title>TalentHook Azure Blob leak (2025) Oracle SSO/LDAP breach (2025)</title>
    </sec>
    <sec id="sec-25">
      <title>Commvault CVE-2025-3928 (2025)</title>
    </sec>
    <sec id="sec-26">
      <title>Microsoft SharePoint Server</title>
    </sec>
    <sec id="sec-27">
      <title>Azure Blob Storage Oracle Cloud</title>
    </sec>
    <sec id="sec-28">
      <title>Commvault Metallic (Azure SaaS)</title>
    </sec>
    <sec id="sec-29">
      <title>Vulnerability Type</title>
    </sec>
    <sec id="sec-30">
      <title>SQL injection, lack of API monitoring</title>
    </sec>
    <sec id="sec-31">
      <title>Key compromise,</title>
      <p>OAuth token
forgery
Missing MFA,
weak monitoring</p>
    </sec>
    <sec id="sec-32">
      <title>Lack of isolation, secrets stored insecurely</title>
    </sec>
    <sec id="sec-33">
      <title>Zero-day</title>
      <p>(spoofing), lack
of lateral
movement
control
Misconfiguration</p>
    </sec>
    <sec id="sec-34">
      <title>Credential theft, SSO compromise</title>
    </sec>
    <sec id="sec-35">
      <title>Third-party SaaS vulnerability Key Consequences</title>
    </sec>
    <sec id="sec-36">
      <title>Data breach</title>
      <p>affecting 500+
organizations
(BBC, Shell, etc.)
Compromise of
government
email accounts
Leakage of
telecom
metadata
Breach of
government and
corporate
customer data
Compromise of
75+ servers</p>
    </sec>
    <sec id="sec-37">
      <title>Exposure of 26</title>
      <p>million résumés
Leakage of 6
million user
accounts
Access to
Microsoft 365
customer
resources</p>
    </sec>
    <sec id="sec-38">
      <title>Estimated</title>
      <p>Financial
Loss (USD)</p>
      <p>~410 M
up to 20 M</p>
      <p>5–8 M</p>
      <p>
        Threat detection systems perform deep inspection of cloud environment telemetry using
behavioral pattern analysis, anomaly detection, event correlation, and threat intelligence feeds [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
Their role is to identify potential attack vectors, policy violations, and atypical usage patterns that
may indicate a security threat [
        <xref ref-type="bibr" rid="ref13 ref8">8, 13</xref>
        ].
      </p>
      <p>
        SOAR systems, on the other hand, function as strategic tools for automating the response to
detected incidents. They standardize response procedures, enable centralized coordination between
various security tools, and significantly reduce Mean Time to Respond (MTTR) [
        <xref ref-type="bibr" rid="ref11 ref14">11, 14</xref>
        ]. Integrating
these components into a unified security perimeter minimizes dependence on the human factor—a
critical concern in highly dynamic multi-cloud infrastructures—and ensures compliance with
international security standards such as NIST SP 800-53, ISO/IEC 27001, and SOC 2 [
        <xref ref-type="bibr" rid="ref1 ref15">1, 15</xref>
        ].
      </p>
      <p>
        Thus, the synergy between threat detection tools and SOAR platforms forms the backbone of a
modern cloud security strategy, capable of not only swiftly identifying and mitigating threats but
also enhancing infrastructure resilience against complex, multi-vector attacks [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <sec id="sec-38-1">
        <title>3.1. Threat detection systems as the basis of proactive Cloud Security</title>
        <p>
          The functional capabilities of threat detection systems extend far beyond merely identifying
intrusions or breaches. These systems perform deep inspection of user behavior, services, and
network connections by applying analytics based on security policies, signature-based methods,
heuristics, and behavioral models [
          <xref ref-type="bibr" rid="ref11 ref9">9, 11</xref>
          ]. This approach enables not only the detection of overt
incidents but also the proactive identification of latent threats that have not yet manifested as active
attacks—such as lateral movement, privilege escalation attempts, or the abuse of legitimate tools for
unauthorized actions (commonly referred to as Living off the Land, or LotL) [
          <xref ref-type="bibr" rid="ref12 ref14">12, 14</xref>
          ].
        </p>
        <p>
          A key advantage of these systems is their ability to classify identified incidents by criticality
level, which allows for the optimization of security resource allocation and the prioritization of
response actions. This is particularly important in environments with limited human resources
within Security Operations Centers (SOCs) and high levels of informational noise in the form of
false positives [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. Threat detection systems act as a filtering layer that not only suppresses
insignificant events but also enriches incident data with contextual information—such as user
identity, affected resource, geographic location, and threat type [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
        </p>
        <p>
          Strategically, threat detection systems also serve as a feedback mechanism for improving security
policies, forming threat intelligence feeds, and adapting defensive strategies in response to changes
in the threat landscape [
          <xref ref-type="bibr" rid="ref10 ref2">2, 10</xref>
          ]. Without this functionality, SOAR solutions cannot operate
effectively, as the structured and high-quality output from threat detection systems acts as the
primary trigger for initiating automated response playbooks [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
        </p>
      </sec>
      <sec id="sec-38-2">
        <title>3.1.1. Market leaders in proactive Threat Detection</title>
        <p>
          In the context of the increasing complexity of multicloud environments, the selection of threat
detection tools becomes a strategically critical step in building an effective security system. The
quality and functional capabilities of these tools determine the organization’s ability not only to
timely identify potential attacks or vulnerabilities, but also to provide the necessary context for
subsequent response activities [
          <xref ref-type="bibr" rid="ref2 ref22">2, 22</xref>
          ]. This is especially relevant in scenarios where incident
management is tightly integrated with security automation systems (SOAR), which require high
precision and completeness of data to support effective decision-making [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>
          Accordingly, this study presents a comparative analysis of leading threat detection platforms in
cloud environments, including Prisma Cloud, AWS GuardDuty, Microsoft Defender for Cloud,
Google Security Command Center, Orca Security, and Lacework. This analysis serves as the
foundation for selecting the most appropriate tool to meet multicloud security requirements,
ensuring not only comprehensive threat detection, but also efficient integration with SOAR
platforms for building a cohesive cloud infrastructure protection strategy [
          <xref ref-type="bibr" rid="ref15">15, 27</xref>
          ].
        </p>
      </sec>
      <sec id="sec-38-3">
        <title>3.1.1.1. Commercial and open solutions for Threat Detection</title>
        <p>
          Prisma Cloud is a comprehensive platform combining Cloud Security Posture Management (CSPM),
Cloud Workload Protection Platform (CWPP), and integrated capabilities for threat and anomaly
detection at the levels of resources, network traffic, configurations, and identity data [
          <xref ref-type="bibr" rid="ref13 ref15">13, 15</xref>
          ]. A key
advantage is its integration with the Cortex XSOAR ecosystem, enabling a seamless transition from
threat detection to automated response [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. The platform supports all three major cloud providers—
AWS, Azure, and GCP—without coverage limitations, which is critical for multicloud strategies.
        </p>
        <p>
          AWS GuardDuty is a native security service designed for the AWS environment. It performs
monitoring and threat detection based on log flows, VPC traffic, CloudTrail data, and DNS queries
[
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. Its primary limitation is its exclusive applicability within AWS, without support for other cloud
providers. Furthermore, GuardDuty focuses mostly on anomaly detection and lacks in-depth
configuration analysis or workload protection.
        </p>
        <p>
          Microsoft Defender for Cloud (formerly Azure Defender) offers a broad set of security features
for Azure, including CSPM, CWPP, and threat detection capabilities [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. Although the product
supports integration with AWS and GCP, such support is partial and does not offer functional parity
with its Azure-native features. Its tight integration with the Microsoft Security Stack makes it a
strong option for organizations based primarily on Azure.
Google Security Command Center (SCC) provides a centralized security monitoring platform for
GCP, including vulnerability detection, misconfiguration analysis, and indicators of compromise
[
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. However, SCC is restricted to Google Cloud, which reduces its effectiveness in multicloud
environments. While its CSPM features are competitive, the lack of integration with third-party
SOAR solutions creates a gap between detection and response.
        </p>
        <p>
          Orca Security offers an agentless architecture for in-depth scanning of AWS, Azure, and GCP
environments [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ]. The platform detects vulnerabilities, policy violations, and threats without the
need to install agents on individual resources. Its main strengths are rapid deployment and minimal
performance overhead. However, Orca does not include its own SOAR system, requiring integration
with external solutions.
        </p>
        <p>Lacework focuses on behavioral analytics and activity monitoring across cloud workloads [27].
The platform excels at detecting anomalies and potentially malicious activity using machine
learning algorithms. While it supports multicloud environments, it has a more limited CSPM feature
set compared to Prisma Cloud and does not offer equally deep integration with automation
platforms.</p>
        <p>The comparative Table 4 below outlines the key characteristics of leading threat detection
platforms in cloud environments across several critical parameters relevant for integration into a
comprehensive cloud security strategy.</p>
        <p>The first criterion is multicloud support, assessing the platform’s ability to operate across
multiple cloud providers—AWS, Azure, and GCP. This is vital for organizations adopting multicloud
architectures that require centralized security oversight.</p>
        <p>The second aspect is the presence of Cloud Security Posture Management (CSPM), which
identifies and remediates misconfigured cloud resources that can create vulnerabilities. CSPM
ensures continuous configuration assessment and policy compliance.</p>
        <p>The third criterion, Cloud Workload Protection Platform (CWPP), covers the protection of
workloads such as virtual machines, containers, and serverless functions, which is particularly
relevant in cloud and hybrid environments.</p>
        <p>The fourth parameter is integration with SOAR platforms, indicating the ability to not only
detect threats but also automate incident response. A lack of such integration limits the capacity for
swift mitigation without operator intervention.</p>
        <p>The final criterion is the approach to threat detection, characterizing the platform’s
methodolog —whether through log analysis, API request monitoring, configuration scanning,
behavioral analytics, or machine learning–based anomaly detection.</p>
        <p>
          The conducted analysis demonstrates that Prisma Cloud stands out with the highest level of
functional completeness among the reviewed solutions [
          <xref ref-type="bibr" rid="ref13 ref15 ref24">13, 15, 24</xref>
          ], giving it a strategic advantage
within multicloud architectures. The platform integrates both Cloud Security Posture Management
(CSPM) capabilities—responsible for continuous auditing of cloud infrastructure configurations for
compliance with security policies and standards—and Cloud Workload Protection Platform (CWPP)
features, focused on protecting workloads ranging from virtual machines to containerized
applications and serverless functions. This combination ensures strategic configuration control and
tactical protection of dynamic workloads.
        </p>
        <p>
          Additionally, Prisma Cloud features native integration with the Cortex XSOAR platform [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ],
establishing a direct connection between threat detection and automated response. This allows not
only for timely identification of risks but also for immediate initiation of orchestrated response
scenarios, which is critical in the highly dynamic threat landscape of cloud environments.
        </p>
        <p>
          In contrast, other solutions such as AWS GuardDuty and Google Security Command Center
(SCC), while effective within their native ecosystems, remain limited in a multicloud context [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ],
[
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] due to the absence of a unified approach to CSPM and CWPP and a lack of—or limited—
integration with SOAR platforms. This reduces their adaptability and effectiveness in heterogeneous
infrastructures, where maintaining a unified standard for security management and incident
response across cloud providers is essential.
        </p>
        <p>Thus, Prisma Cloud’s multidimensional approach—combining comprehensive configuration
control, workload protection, and an uninterrupted chain of detection and response—positions it as
the optimal solution for organizations seeking to ensure cyber resilience within complex multicloud
ecosystems.</p>
      </sec>
      <sec id="sec-38-4">
        <title>3.2. The role of SOAR systems in security Incident Management strategy</title>
        <p>
          SOAR (Security Orchestration, Automation, and Response) systems represent a critical component
of modern cybersecurity, enabling automation, coordination, and standardization of threat
detection, analysis, and incident response processes [
          <xref ref-type="bibr" rid="ref12 ref9">9, 12</xref>
          ]. Their implementation significantly
reduces the mean time to detect (MTTD) and mean time to respond (MTTR), alleviates the workload
on SOC analysts, and minimizes human-factor-related risks [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>
          The relevance of SOAR increases markedly in multicloud environments, where the volume of
security events requiring processing often exceeds the capacity of traditional response teams [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
SOAR systems can integrate with a broad range of cloud security components—including cloud
platform APIs (AWS, Azure, GCP), SIEM systems (such as Splunk), vulnerability management tools,
identity and access management services (like HashiCorp Vault), and service desk tools [27].
        </p>
        <p>Key capabilities of SOAR systems include:



</p>
        <p>
          Automated detection of anomalous events based on data from monitoring systems (e.g.,
Prisma Cloud, GuardDuty, Splunk) [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
        </p>
        <p>
          Execution of standardized response playbooks, including actions such as account locking,
VM isolation, firewall policy modification, and alert generation in SIEM platforms [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
Orchestration of workflows across infrastructure components—from CMDB and EDR to
incident management platforms like Jira and ServiceNow [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ].
        </p>
        <p>Generation of auditable activity logs in compliance with standards such as NIST SP 800-61,
ISO/IEC 27035, SOC 2, HIPAA, and others [28].</p>
        <p>
          A typical SOAR use case involves automated response to the creation of cloud objects in atypical
regions, unauthorized API access, or out-of-hours use of privileged accounts. In these scenarios, the
system triggers appropriate actions—revoking access keys, isolating assets, and notifying the
responsible teams [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ].
A crucial aspect of SOAR integration is its interaction with secrets management systems like
HashiCorp Vault, which enable Just-In-Time Access and eliminate the need for persistent
credentials [29].
        </p>
        <p>
          In conclusion, SOAR systems provide the technical and organizational foundation for building
scalable, standards-compliant, and adaptive security strategies in cloud environments. Their
adoption significantly reduces attacker dwell time, improves response transparency, and enhances
the overall cyber resilience of the organization [
          <xref ref-type="bibr" rid="ref1 ref9">1, 9</xref>
          ].
        </p>
      </sec>
      <sec id="sec-38-5">
        <title>3.2.1. Technical implementation of Automated response based on SOAR</title>
        <p>
          The technological implementation of SOAR (Security Orchestration, Automation, and Response)
solutions involves the creation of an integrated infrastructure for security incident management,
enabling automation of critical stages—from anomaly detection to threat neutralization [
          <xref ref-type="bibr" rid="ref12 ref9">9, 12</xref>
          ]. In
public and multicloud environments, where the volume of events and data sources significantly
increases, SOAR becomes a foundational element for ensuring scalability, action consistency, and
compliance with regulatory requirements [
          <xref ref-type="bibr" rid="ref14">14, 27</xref>
          ].
        </p>
        <p>Architecturally, a SOAR platform functions as an orchestration node that interacts with the
following classes of components:


</p>
        <p>
          Telemetry and event sources: SIEM systems (such as Splunk, Chronicle), cloud monitoring
and protection services (e.g., Prisma Cloud, AWS GuardDuty), vulnerability management
systems, and authentication/identity services (Azure AD, Okta) [
          <xref ref-type="bibr" rid="ref11">11, 28</xref>
          ].
        </p>
        <p>
          Response orchestrator: the SOAR engine that correlates events, makes decisions, and
triggers response playbooks—often implemented as a dedicated software solution (e.g.,
Cortex XSOAR, Splunk SOAR) [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>Integration gateways: tools for executing automated actions in cloud environments (AWS
IAM, Azure Resource Manager), interfacing with incident management services
(ServiceNow, Jira), secrets management systems (HashiCorp Vault), and DevOps automation
tools (Ansible, Terraform) [29].</p>
        <p>
          A typical automated response scenario proceeds as follows:
1. Prisma Cloud detects potentially anomalous activity (e.g., access to a container from an
unusual region), which is classified as a high-risk event [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
2. The event is forwarded to the SIEM platform (e.g., Splunk), where predefined correlation
rules trigger an alert [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
3. The SOAR platform receives the alert from the SIEM and activates the corresponding
response playbook [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
4. The playbook executes a sequence of actions:
        </p>
        <p>Temporarily suspends credentials via integration with Vault [29].</p>
        <p>Isolates the suspicious virtual instance.</p>
        <p>Creates an incident in ServiceNow or Jira with relevant event attributes.</p>
        <p>
          Automatically notifies the responsible analyst or response team [
          <xref ref-type="bibr" rid="ref21 ref9">9, 21</xref>
          ].
        </p>
        <p>
          A key advantage of modern SOAR solutions is the ability to develop customized response
playbooks, formalized as machine-readable structures (YAML, JSON), with comprehensive logging
in accordance with audit trail principles. This ensures transparency and traceability, which are
essential for compliance with standards such as ISO/IEC 27035, NIST SP 800-61, SOC 2, and PCI DSS
[
          <xref ref-type="bibr" rid="ref21">21</xref>
          ].
        </p>
        <p>SOAR integration with secrets management systems (e.g., HashiCorp Vault) enables the
implementation of dynamic access control models such as Just-In-Time Access, where critical
privileges are granted only at the moment of execution. This significantly reduces the risk of
exploiting vulnerabilities associated with persistently stored credentials [28].</p>
        <p>
          Thus, the implementation of SOAR in cloud infrastructure establishes a technical and
organizational foundation for proactive security, minimizes mean time to respond (MTTR), and
optimizes coordination among subsystems within the cybersecurity architecture [
          <xref ref-type="bibr" rid="ref12 ref9">9, 12</xref>
          ].
        </p>
      </sec>
      <sec id="sec-38-6">
        <title>3.2.2. Common Security Challenges in Cloud Infrastructure and the Role of SOAR in Their Mitigation</title>
        <p>
          In the process of building multi-layered cloud architectures, organizations encounter a number of
systemic vulnerabilities that lower the overall level of security. These include fragmented access
control mechanisms, the absence of centralized oversight for inter-cloud interactions, the human
factor in response processes, and the lack of formalized incident management procedures [
          <xref ref-type="bibr" rid="ref12 ref14">12, 14</xref>
          ].
These challenges are critical for modern multi-cloud environments and require technological
solutions that enable scalable, standardized, and automated threat response. In this context, SOAR
(Security Orchestration, Automation, and Response) systems play a pivotal role by enabling
effective orchestration of detection, analysis, and incident response processes [
          <xref ref-type="bibr" rid="ref9">9, 27</xref>
          ].
        </p>
        <p>Below is an overview of the most common security issues in cloud infrastructures and the
mechanisms for their mitigation through SOAR solutions:</p>
      </sec>
    </sec>
    <sec id="sec-39">
      <title>1. Fragmented Access in Multi-Cloud Environments</title>
      <p>
        When multiple cloud providers (e.g., AWS, Azure, GCP) are used simultaneously, it becomes
increasingly difficult to manage access rights and audit user actions. SOAR provides
centralized aggregation of access logs and events, allowing for the detection of anomalous
cross-environment movements (lateral movement) and the implementation of dynamic Zero
Trust policies [
        <xref ref-type="bibr" rid="ref15 ref24">15, 24</xref>
        ].
2. Lack of Standardized Response Procedures
      </p>
      <p>
        Manual response, which depends on the subjective perception of SOC analysts, often leads
to delays or erroneous decisions. SOAR employs predefined playbooks that automate the
resolution of common scenarios—such as isolating resources, revoking access keys, or
creating incidents in service desk systems [
        <xref ref-type="bibr" rid="ref11 ref9">9, 11</xref>
        ].
3. Human Factor and Limited SOC Resources
      </p>
      <p>
        A significant portion of incidents is not escalated in a timely manner due to the overload of
first-line security analysts or insufficient qualifications. SOAR enables the delegation of
routine tasks to automated mechanisms—such as creating and updating CMDB records,
processing SIEM events, or interacting with Vault to restrict access rights [
        <xref ref-type="bibr" rid="ref13">13, 29</xref>
        ].
4. Lack of Transparency and Auditability in Response
      </p>
      <p>In many cases, organizations fail to ensure an audit trail of actions taken during incident
response, making it impossible to achieve compliance certifications (SOC 2, ISO/IEC 27001,
PCI DSS). SOAR formalizes and logs every step taken within a playbook, indicating the
timestamp, initiator, and consequences of each action [28].
5. High Dwell Time of Threat Actors</p>
      <p>
        Due to the absence of automated anomaly analysis, threats may remain undetected for
several weeks. SOAR, in combination with UEBA modules or SIEM systems (e.g., Splunk,
Sentinel), can initiate detection based on behavioral patterns, promptly escalate incidents,
and trigger containment measures [
        <xref ref-type="bibr" rid="ref16 ref26">16, 26</xref>
        ].
      </p>
      <p>
        Thus, common security issues in cloud environments can be effectively mitigated through the
implementation of SOAR as a systemic component. Its ability to integrate with cloud APIs, manage
access via Vault, automate response playbooks, and retain a complete event log makes it an
indispensable tool for achieving both technological and regulatory maturity in cybersecurity [
        <xref ref-type="bibr" rid="ref9">9, 29</xref>
        ].
      </p>
      <sec id="sec-39-1">
        <title>3.3. Comparison of SOAR systems and justification of selection</title>
        <p>
          As part of this study, a comparative analysis was conducted on leading Security Orchestration,
Automation and Response (SOAR) solutions in order to justify the selection of tools for automating
security incident management in multi-cloud environments. The analysis covered four of the most
widely used platforms: Palo Alto Cortex XSOAR, Splunk SOAR, IBM QRadar SOAR, and Microsoft
Sentinel [
          <xref ref-type="bibr" rid="ref22 ref9">9, 22</xref>
          ]. The evaluation was based on the following criteria:





level of integration support for cloud providers (AWS, Azure, GCP).
flexibility and manageability of automation playbooks.
availability and capabilities for working with threat intelligence sources.
scalability across large distributed infrastructures.
compliance with international information security standards (NIST SP 800-53, ISO/IEC
27001, SOC 2, etc.) [
          <xref ref-type="bibr" rid="ref24">24, 28</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-40">
      <title>The results of the comparison are presented in Table 5.</title>
      <p>
        The conducted analysis has demonstrated that the most optimal configuration for the research
objectives is the combination of: Prisma Cloud (for anomaly detection and incident identification),
Splunk SOAR (for centralized response automation), HashiCorp Vault (for secure secrets
management), and Jenkins (as an execution tool for environment changes) [
        <xref ref-type="bibr" rid="ref12 ref13">12, 13, 30</xref>
        ]. This
selection is justified by the high degree of interoperability between the components, compliance
with industry standards, and the ability to scale across heterogeneous cloud environments.
      </p>
      <p>
        The proposed model also stands out by integrating preventive, detection, and response
components into a unified managed system. The use of SOAR significantly reduces the time
between incident detection and response (Mean Time to Detect / Mean Time to Respond), limits
adversary dwell time, and minimizes the impact of human error in response processes [
        <xref ref-type="bibr" rid="ref10 ref15">10, 15</xref>
        ].
      </p>
      <p>
        The scientific novelty of the proposed approach lies in constructing a holistic model of
automated incident response in a multi-cloud environment, taking into account the principles of
Zero Trust, least privilege, and automated protection of secret access through Vault. Unlike
conventional SOAR implementations, which often limit themselves to event logging and manual
intervention, this model demonstrates deep integration across monitoring, response, and automated
threat remediation [
        <xref ref-type="bibr" rid="ref14">14, 29</xref>
        ].
      </p>
      <sec id="sec-40-1">
        <title>4. Methodology for automation of security incident management in</title>
        <p>public cloud environments using PaloAlto Prisma</p>
        <sec id="sec-40-1-1">
          <title>4.1. Security standards as a foundation for Incident Response automation</title>
          <p>
            Automation of detection, classification, and response processes to incidents in cloud environments
must align with the requirements of international information security standards. These standards
not only formalize the expected behavior of an organization during a security incident but also
define criteria for evaluating the effectiveness of technical and organizational protective measures
[
            <xref ref-type="bibr" rid="ref19">19, 28</xref>
            ]. The deployment of SOAR solutions within multi-cloud infrastructure should rely on
normative frameworks such as SOC 2, NIST SP 800-53, ISO/IEC 27001, ISO/IEC 27035, PCI DSS, and
HIPAA [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ].
          </p>
          <p>
            The ISO/IEC 27001 standard mandates the implementation of procedures for detecting, logging,
and responding to information security events. Together with ISO/IEC 27035, which elaborates on
incident management processes, these standards form the foundation for designing SOAR
playbooks. Specifically, the standard requires the formalization of incident classification criteria,
limitations on response time, and maintenance of audit trails—all of which can be operationalized
through automated response scenarios [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ].
          </p>
          <p>The NIST SP 800-53 recommendations define a comprehensive set of control requirements for
information systems, including the IR (Incident Response) family, which mandates:</p>
          <p>Mechanisms for event detection (IR-4).</p>
          <p>Real-time response capabilities (IR-5).</p>
          <p>Methods to limit the impact of incidents (IR-6).</p>
          <p>Effectiveness analysis of response measures (IR-8) [30].</p>
          <p>Within a SOAR platform, these requirements can be fulfilled through automated incident
creation based on SIEM triggers, execution of response playbooks, action logging, and report
generation [27].</p>
          <p>
            SOC 2 focuses on building trust in cloud services based on five principles: security, availability,
processing integrity, confidentiality, and privacy. In this context, SOAR ensures continuous
monitoring and verification of access, reduces the impact of incidents on service availability, and
enables centralized retention of forensic evidence [
            <xref ref-type="bibr" rid="ref10">10</xref>
            ].
          </p>
          <p>
            In the financial services and e-commerce sectors, the PCI DSS standard is widely adopted,
mandating event logging (Req. 10), regular monitoring (Req. 11), and clearly defined response
procedures (Req. 12.10) [32]. The use of SOAR facilitates the automation of these processes, ensuring
audit transparency [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ].
          </p>
          <p>
            Regarding the protection of medical data, the HIPAA standard requires implementation of
technical safeguards for access control, intrusion detection, and user notification about unauthorized
access attempts. The integration of cloud logs with SOAR enables fulfillment of these requirements
through systematic access event processing, incident isolation, and subsequent analysis [
            <xref ref-type="bibr" rid="ref13">13</xref>
            ].
          </p>
          <p>
            Thus, compliance with international standards is not only a matter of audit readiness but also a
critical factor in building an effective, scalable, and regulatory-aligned architecture for automated
security in the cloud. Leveraging SOAR as a mechanism for implementing these standards ensures a
structured, controlled, and transparent threat response process [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ].
          </p>
        </sec>
        <sec id="sec-40-1-2">
          <title>4.2. Implementation of an Automated model in a multi-cloud environment</title>
          <p>
            Within the proposed architecture for automated incident response in information security, a central
role is played by the integration of the Palo Alto Prisma platform into the public cloud
infrastructure. In the context of multi-cloud deployments—particularly across Amazon Web Services
(AWS), Microsoft Azure, and Google Cloud Platform (GCP)—the processes of monitoring, threat
detection, and response become increasingly complex due to differences in access mechanisms,
authentication standards, and network isolation capabilities [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ]. Traditional methods that rely on
manual intervention prove ineffective under such conditions, as they are unable to ensure timely
response and are prone to delays, thereby increasing the risk of asset compromise [
            <xref ref-type="bibr" rid="ref18">18</xref>
            ].
          </p>
          <p>
            The introduction of automated approaches based on Jenkins enables the construction of response
logic that orchestrates security actions according to predefined scenarios. This is achieved through
the use of automated playbooks, enrichment of threat intelligence by analytical modules, and
continuous real-time incident monitoring [
            <xref ref-type="bibr" rid="ref17">17</xref>
            ]. Such mechanisms allow for the isolation of
infrastructure resources prior to the involvement of SecOps personnel, significantly reducing dwell
time and mitigating the risk of lateral movement and escalation [27].
          </p>
          <p>
            Orchestration via Jenkins is implemented through ready-to-use connectors and APIs that enable
unified interaction across different cloud service providers. This facilitates the enforcement of
consistent response standards across heterogeneous clouds without the need to develop separate
manual procedures for each platform [
            <xref ref-type="bibr" rid="ref26">26</xref>
            ]. A key advantage lies in enabling interoperability between
security tools, which collectively function as a coordinated system. This simplifies incident
management, unifies event sources, response actions, and reporting within a centralized platform
[
            <xref ref-type="bibr" rid="ref25">25</xref>
            ].
          </p>
          <p>
            Leveraging the expertise of Palo Alto and the analytical capabilities of Prisma allows for the
detection of emerging attack vectors based on anomalous behavior and the immediate application of
appropriate security policies [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ]. These data are subsequently forwarded to Security Operations
Centers (SOC) for analysis, enabling not only a timely response but also knowledge accumulation
for the continual enhancement of response mechanisms [
            <xref ref-type="bibr" rid="ref23">23</xref>
            ].
          </p>
          <p>
            Thus, the implementation of an automated model in a multi-cloud environment using Prisma,
Jenkins, and SOAR ensures scalable, efficient, and standardized incident response in alignment with
the requirements of modern dynamic infrastructures [
            <xref ref-type="bibr" rid="ref24">24</xref>
            ].
          </p>
        </sec>
        <sec id="sec-40-1-3">
          <title>4.3. Scenario of automated incident response</title>
          <p>The presented security automation architecture for public cloud environments utilizes integrated
solutions to detect threats, analyze them, and execute automated responses. This process involves a
step-by-step execution of actions aimed at isolating threats with minimal human intervention.</p>
          <p>
            At the initial stage, anomalies in cloud infrastructure behavior are detected using Prisma Cloud
(Step 1 in Figure 1). These anomalies, which may indicate potential security incidents, are
transmitted to Splunk for further processing (Step 2). In Splunk, the data is analyzed to determine
the criticality of events, after which a list of “notable events” requiring response is generated [
            <xref ref-type="bibr" rid="ref14 ref2">2, 14</xref>
            ].
          </p>
          <p>The decision on further actions is made by the Level 2 (L2) SecOps team (Step 3), which receives
notifications about critical events through Splunk (Step 4). SecOps waits for a response from the end
user within 15 minutes, after which blocking procedures are executed through automation. If the
threat is confirmed, the team activates an automated SOAR action known as “RedButton” (Step 5).
This action triggers an automation script in Splunk SOAR, which initiates the Jenkins automation
node (Step 6).</p>
          <p>
            Jenkins functions as a coordination node, obtaining the necessary credentials for accessing public
cloud platforms (AWS, Azure, Google Cloud Platform) from HashiCorp Vault. (Step 7) [
            <xref ref-type="bibr" rid="ref15 ref22">15, 22</xref>
            ]. This
ensures the secure use of credentials for executing blocking actions in the cloud infrastructure.
          </p>
          <p>
            Next, Jenkins applies the appropriate isolation policies defined in preconfigured playbooks
(Step 8). In Google Cloud Platform, this may include blocking access via Cloud IAM or modifying
virtual network (VPC) settings. In AWS, it involves disabling compromised IAM accounts, changing
security group rules, or restricting access through VPC. In Microsoft Azure, isolation is enforced by
modifying Azure IAM or restricting virtual networks. It is important to note that resources remain
operational, preventing a complete shutdown of infrastructure operations (Step 9) [
            <xref ref-type="bibr" rid="ref24">24</xref>
            ].
          </p>
          <p>
            After executing the actions, end users and administrators receive incident notifications via email
or Microsoft Teams. These notifications contain detailed information about the nature of the threat,
the measures taken, and further recommendations [
            <xref ref-type="bibr" rid="ref15 ref17">15, 17</xref>
            ].
          </p>
          <p>
            The final stage is the creation of a post-mortem report, which includes an analysis of the
incident’s causes, its consequences, the actions performed, and recommendations to prevent similar
situations in the future. This report aims to improve response processes and enhance the overall
effectiveness of the security system (Step 10) [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ].
          </p>
        </sec>
        <sec id="sec-40-1-4">
          <title>4.4. Technical and Organizational Risks of Deploying Automated Solutions in</title>
        </sec>
        <sec id="sec-40-1-5">
          <title>Multi-Cloud Environments</title>
          <p>Despite the economic and operational feasibility of implementing SOAR systems, a number of risks
must be considered that may limit their effectiveness or complicate their deployment:
1. Limited integration compatibility with private and on-premises infrastructures.</p>
          <p>
            A significant portion of local systems lacks support for standard interfaces (such as REST
API and Webhooks), which makes it impossible to fully automate incident response within
such environments [
            <xref ref-type="bibr" rid="ref13">13</xref>
            ].
2. Absence of unified API standards among cloud providers.
          </p>
          <p>The heterogeneity of event log formats, authentication protocols, and access structures
complicates the implementation of unified response scenarios across different platforms
[27].
3. Possibility of errors in automated scenarios.</p>
          <p>
            Insufficiently validated or improperly configured playbooks may cause service availability
disruptions, accidental blocking of legitimate traffic, or other operational failures [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ].
4. High dependency on third-party components.
          </p>
          <p>
            The operation of a SOAR system assumes stable functioning of the integrated platforms
(SIEM, Vault, CI/CD, log services). A failure in any one component can disrupt the entire
response chain [
            <xref ref-type="bibr" rid="ref18">18</xref>
            ].
5. Scalability and complexity management.
          </p>
          <p>
            As infrastructure scales, there arises a need for expanded computational resources, increased
throughput of logical links, and support for more complex response scenarios [
            <xref ref-type="bibr" rid="ref22">22</xref>
            ].
6. Organizational barriers.
          </p>
          <p>A low level of personnel awareness, lack of coordinated response procedures, and a shortage
of qualified specialists may significantly reduce the effectiveness of the implementation [32].</p>
          <p>
            To mitigate the above-mentioned risks, a phased implementation strategy is recommended. This
strategy should include pilot environment testing, gradual scaling, playbook revision, establishment
of fallback manual response mechanisms, and alignment with international incident response
standards (such as NIST SP 800-61 and ISO/IEC 27035) [
            <xref ref-type="bibr" rid="ref2">2</xref>
            ].
          </p>
        </sec>
        <sec id="sec-40-1-6">
          <title>4.5. Empirical testing of the implemented solution’s effectiveness</title>
          <p>
            To validate the effectiveness of the proposed model, experimental testing was conducted within a
controlled demonstration environment simulating the multi-cloud architecture of a mid-sized
enterprise. The evaluation focused on key operational metrics—Mean Time to Detect (MTTD), Mean
Time to Respond (MTTR), false positive rate, risk level, and SOC team workload [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ].
          </p>
          <p>The test environment included: AWS (3 accounts), Azure (2), and GCP (1); integrated with Prisma
Cloud, Jenkins, Vault, and Splunk SOAR. Typical simulated incidents involved suspicious account
activity, unauthorized API calls, and unauthorized modifications to security policies. The control
group operated without automated response.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-41">
      <title>Mean Time to Detect (MTTD / hours)</title>
      <p>Mean Time to Respond (MTTR /
hours)
False Positive Incident Rate (%)
SOC Analyst Workload (%)
Direct Loss per Incident (USD)
Potential Impact (Risk Score, out of 10)</p>
    </sec>
    <sec id="sec-42">
      <title>Without Automation</title>
      <p>(2025 estimate)</p>
    </sec>
    <sec id="sec-43">
      <title>With Automated</title>
      <p>Response</p>
      <p>Improvement</p>
      <p>(%)</p>
      <p>
        A comparison of the obtained results with analytical reports—particularly the IBM Cost of a Data
Breach Report 2023—confirms alignment with industry trends: on average, MTTR without
automation exceeds six hours, and direct losses surpass $4.45 million [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Thus, implementation of
the developed model demonstrates high effectiveness and strong potential for scalability within
organizations operating dynamic multi-cloud architectures [27].
      </p>
      <p>It should be noted that the model’s effectiveness is limited in cases of fragmented event logging
or incidents requiring deep contextual analysis, which is not achievable with current systems. This
highlights the need for further evolution of the solution through the integration of ML/AI
technologies, behavioral analytics, and UEBA mechanisms [33].</p>
      <sec id="sec-43-1">
        <title>4.6. Implementation results and future development directions</title>
        <p>
          The proposed model of automated incident management in public cloud environments has been
implemented through the integration of modern tools for detection, analysis, and response. The core
components include: Prisma Cloud by Palo Alto Networks as the primary risk detection platform
[
          <xref ref-type="bibr" rid="ref21">21</xref>
          ], Splunk SOAR as the orchestration and response automation system [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], Jenkins as an
execution mechanism for infrastructure-level changes [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ], and HashiCorp Vault for secure
credential management [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ]. All elements are interconnected within a closed-loop automated
response cycle (detect → analyze → respond → document), operating in real time without manual
operator intervention [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
        </p>
        <p>
          The model is adapted to multi-cloud infrastructures comprising more than 400 cloud accounts
across AWS, Azure, and GCP, accounting for typical characteristics such as asset distribution,
dynamic scaling, and heterogeneous authentication and access control policies [27]. The
architecture follows the principles of Zero Trust, ensuring isolation of environments, real-time
verification of every access request, and dynamic privilege management.
From a practical standpoint, the system enables a timely response to incidents such as:
1. Credential compromise due to leaked secrets or unauthorized access [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
2. Detection of geographic or session behavioral anomalies [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
3. Unauthorized infrastructure modification or policy violations.
4. Execution of suspicious API requests or privilege escalation attempts [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ].
        </p>
        <p>
          When an incident occurs, the system automatically detects the risk using Prisma Cloud,
generates an event in Splunk, which is then transformed via a playbook into an infrastructure-level
response action (e.g., VPC or IAM blocking), initiates secure retrieval of temporary credentials via
Vault, and executes the action using Jenkins. All stages are logged, and a post-incident report is
generated upon completion [
          <xref ref-type="bibr" rid="ref14 ref15 ref22">14, 15, 22</xref>
          ].
        </p>
      </sec>
      <sec id="sec-43-2">
        <title>4.6.1. Implementation results</title>
        <p>The practical value of this model lies in its ability to provide centralized incident management
across an environment with over 400 cloud accounts. According to IBM’s Cost of a Data Breach
Report 2023, the average cost of a cloud data breach is $4.45 million [29], and the dwell time (i.e.,
time an attacker remains undetected in a system) may exceed 20–30 days [32]. The implemented
model reduces dwell time to a few hours, shortens Mean Time to Detect (MTTD) to minutes, and
decreases Mean Time to Respond (MTTR) to hours, collectively reducing financial risk by more than
80% compared to manual incident handling [28].</p>
        <p>The proposed solution was deployed within a complex multi-cloud environment encompassing
three major public cloud platforms—Amazon Web Services (AWS), Microsoft Azure, and Google
Cloud Platform (GCP)—with the total number of active accounts reaching 419 by mid-2025. This
environment was specifically chosen to mirror the scale and operational diversity of real-world
enterprise infrastructures, providing a representative foundation for a 19-month empirical
evaluation of the performance, adaptability, and scalability of the automated incident response
model based on SOAR principles.</p>
        <p>Prior to the implementation of the solution in March 2025, the security operations center (SOC)
was predominantly reliant on manual incident processing. During this period, the average monthly
exposure to cloud-related risks fluctuated between $20,000 and $39,000, driven by a persistent
stream of 12 to 23 major incidents each month. These incidents were primarily associated with
unauthorized access attempts, leakage of sensitive secrets, misconfigurations of cloud-native
services, and the absence of real-time detection mechanisms. The lack of standardization,
automation, and cross-cloud visibility not only delayed the response process but also imposed a
significant cognitive load on first-line analysts. As a result, the estimated annual potential financial
impact exceeded $370,000.</p>
        <p>To address these operational inefficiencies, an integrated incident response model leveraging
Prisma Cloud for threat detection and Splunk SOAR for orchestration and automation was
implemented in March 2025. This architecture enabled the real-time ingestion and correlation of
telemetry data from heterogeneous cloud environments, execution of automated playbooks for
critical incident types, validation of user actions against security policies, and escalation-free
handling of common security scenarios. The transformation from a reactive to a semi-autonomous
response workflow significantly accelerated decision-making and reduced false-positive rates.</p>
        <p>Within just four months following deployment, the number of major incidents dropped
dramatically to 2–3 per month, and the estimated financial exposure decreased to a range of $3,400–
$5,100 monthly (see Figure 2). This sharp decline in both operational noise and financial risk clearly
demonstrates the practical effectiveness of the solution in mitigating high-frequency, high-impact
threats. Based on historical expenditure trends, the total savings achieved during this initial
postdeployment phase exceeded $130,000, despite the relatively short observation window. These results
affirm the economic viability and strategic value of integrating automated response mechanisms
into large-scale, dynamic cloud environments, particularly in organizations facing increasing
demands for compliance, visibility, and operational resilience.</p>
      </sec>
      <sec id="sec-43-3">
        <title>4.6.2. Economic feasibility of implementing an automated response model in a multi-cloud environment</title>
        <p>The deployment of the proposed architecture for automated incident response in a multi-cloud
environment has demonstrated not only technical viability, but also a high level of economic
efficiency. The real-world deployment scenario encompassed three major public cloud platforms—
AWS, Azure, and GCP—with an overall scale of 419 cloud accounts, which reflects typical
enterprise-level complexity and variability.</p>
        <p>To validate the financial soundness of the implemented SOAR-based model, a comprehensive
cost–benefit analysis was performed covering a 12-month period before and after implementation.
The assessment incorporated both direct costs (such as SOC analyst salaries, incident-related
damages, and downtime) and indirect costs (including service unavailability, loss of productivity,
and system recovery efforts). Capital and operational investments associated with software and
automation tools—such as Prisma Cloud, Splunk SOAR, Jenkins, and Vault—were categorized
according to CAPEX and OPEX accounting standards.
Number of major incidents (per
month)
Risk potential cost (USD year)
Total annual incident-related losses
(USD millions/ year)
Annual cots of SOC analyst
expenses (USD year)
Investment in SOAR solution (USD)</p>
      </sec>
    </sec>
    <sec id="sec-44">
      <title>Before SOAR</title>
      <p>Implementation (2025)
23
370000
6.9
720000
—</p>
    </sec>
    <sec id="sec-45">
      <title>After SOAR Implementation Change % 2</title>
      <p>50000
0.55
540000
380000 (one-time)
91.3
83.3
92
25
—
As shown in Table 6, the average number of major monthly incidents decreased from 23 to just 2, a
91.3% reduction. The annual risk potential cost dropped from $370,000 to $50,000, representing an
83.3% decrease. Total estimated annual losses fell dramatically from $6.9 million to $550,000 (a 92%
reduction), largely due to faster containment, improved detection accuracy, and lower false positive
rates enabled by the new automated response framework.</p>
      <p>Additionally, the annual operational costs associated with SOC analyst teams were reduced by
25%, from $720,000 to $540,000, due to decreased workload and automation of standard incident
response scenarios. The one-time investment in the SOAR solution amounted to $380,000.</p>
      <p>Taken together, these results indicate that the total cost savings achieved in the first year of
operation exceeded $6 million, yielding a full return on investment (ROI) in under three months.
This clearly demonstrates the financial feasibility of scaling the SOAR-based automated response
model across large-scale multi-cloud environments. These findings reinforce the strategic
importance of integrating automation into cloud security operations for both risk mitigation and
operational efficiency.</p>
      <sec id="sec-45-1">
        <title>4.6.3. Future development directions</title>
        <p>
          Future development of the model is expected along the following strategic directions:
1. Integration of AI/ML analytics. The use of machine learning algorithms will improve
incident prioritization, reduce false positives, and enable dynamic adaptation of response
strategies based on behavioral patterns, time of day, and access level [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ].
2. UEBA (User and Entity Behavior Analytics). Implementing behavioral analysis of users and
services will help detect covert attacks, lateral movement, use of dormant accounts, and
nonobvious anomalies that traditional signature-based systems may miss [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ].
3. Deepening the Zero Trust model. The system will be enhanced to incorporate dynamic
access control, conditional authorization, micro-segmentation of cloud infrastructure, and
strict inter-region traffic controls [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
4. Post-incident automation and self-analysis. Mechanisms for automatic post-mortem analysis
of incidents will be developed to not only record events but also build causal graphs, offer
security policy improvement suggestions, and dynamically update playbooks [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ].
5. Audit and metrics-based control. Advanced reporting systems and dashboards monitoring
key security metrics (MTTD, MTTR, dwell time, alert fatigue level, compliance coverage
rate) will allow organizations to transparently track system effectiveness, ensure regulatory
compliance (SOC 2, ISO/IEC 27001, NIST 800-53), and prepare for external audits [
          <xref ref-type="bibr" rid="ref10">10, 33</xref>
          ].
6. Extending playbook adaptability. Leveraging branching mechanisms and contextual
response capabilities in Splunk SOAR, dynamic response scenarios can be implemented,
automatically considering resource type, event context, data sensitivity, and business
process criticality [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>
          The proposed model not only meets modern requirements for response agility, process
automation, and regulatory compliance, but also lays the foundation for an evolving, intelligent,
self-learning cloud security architecture based on the principles of Data-Driven Security and
Continuous Adaptive Risk and Trust Assessment [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <sec id="sec-45-1-1">
          <title>Conclusions</title>
          <p>Within the scope of the study, an architectural model for automated security incident management
in public cloud environments was developed based on the integration of Prisma Cloud, Splunk
SOAR, Jenkins, and HashiCorp Vault. The proposed model enables end-to-end automation of the
incident response cycle—from anomaly detection to execution of corrective infrastructure actions—
without operator intervention. This approach significantly reduces response time (MTTR),
minimizes human factor influence, and mitigates the risks associated with prolonged attacker
presence in the environment.</p>
          <p>The analysis of real-world cloud compromise cases revealed that the main pain points include the
lack of effective monitoring, weak authentication controls, absence of event correlation, and
inability to respond to incidents promptly. The proposed solution addresses these vulnerabilities
through flexible playbook-based logic, integration with threat intelligence sources, and activity
control enabled by a Zero Trust model.</p>
          <p>The scientific novelty of the research lies in the synthesis of SOAR principles, Zero Trust, ML
analytics, and UEBA into a unified architecture adapted to a multi-cloud infrastructure comprising
over 400 cloud accounts. The developed model not only automates incident response but also
enables scalable security policy enforcement without losing control, which is critical for modern
enterprises managing large numbers of cloud assets.</p>
          <p>From a practical perspective, the implementation of the described solution allows organizations
to reduce the risk of financial losses related to cloud environment compromises. Based on the
applied risk assessment model, it is estimated that the absence of automated incident management
may result in annual losses reaching hundreds of thousands of dollars due to response delays, data
leakage, and system downtime.</p>
          <p>Future research directions include enhancing behavioral incident analysis mechanisms using
machine learning methods, expanding platform support through dynamic API integration, and
implementing self-learning capabilities based on historical response scenarios. Additionally, a
formalized approach to regulatory compliance (NIST, ISO, SOC 2) via automated auditing and policy
enforcement control is recommended.</p>
        </sec>
        <sec id="sec-45-1-2">
          <title>Declaration on Generative AI</title>
          <p>While preparing this work, the authors used the AI programs Grammarly Pro to correct text
grammar and Strike Plagiarism to search for possible plagiarism. After using this tool, the authors
reviewed and edited the content as needed and took full responsibility for the publication’s content.
[27] M. Abbas, J. Iqbal, Autonomous Threat Response Systems: A New Paradigm for Intelligent</p>
          <p>Cloud Security Automation, 2025. doi:10.13140/RG.2.2.13750.20800
[28] A. Mahida, Real-Time Incident Response and Remediation—A Review Paper, J. Artif. Intell.</p>
          <p>Cloud Comput. (2023) 1–3. doi:10.47363/JAICC/2023(2)247
[29] V. Jangampet, S. Pulyala, A. Desetty, The Impact of Security Orchestration, Automation, and
Response (SOAR) on Security Operations Center (SOC) Efficiency: A Comprehensive Analysis,
Turk. J. Comput. Math. Educ., 10 (2019) 1545–1549. doi:10.61841/turcomat.v10i3.14323
[30] R. Vast, S. Sawant, A. Thorbole, V. Badgujar, Artificial Intelligence based Security
Orchestration, Automation and Response System, (2021) 1–5. doi:10.1109/I2CT51068.2021.9418109
[31] Ismail, R. Kurnia, Z. Brata, G. Nelistiani, S. Heo, H. Kim, H. Kim, Toward Robust Security
Orchestration and Automated Response in Security Operations Centers with a
HyperAutomation Approach using Agentic Artificial Intelligence, Information, 16 (2025) 365.
doi:10.3390/info16050365
[32] O. Mercy, Holistic Security Solutions for Complex Multi-Cloud Ecosystems, Int. J. Novel Res.</p>
          <p>Dev. (2023).
[33] H. Pitkar, Cloud Security Automation through Symmetry: Threat Detection and Response,
Symmetry, 17 (2025) 859. doi:10.3390/sym17060859</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>O.</given-names>
             
            <surname>Vakhula</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
             
            <surname>Opirskyy</surname>
          </string-name>
          ,
          <string-name>
            <surname>O.</surname>
          </string-name>
           
          <article-title>Mykhaylova, Research on Security Challenges in Cloud Environments and Solutions based on the “Security-as-code” Approach</article-title>
          , in: Cybersecurity
          <source>Providing in Information and Telecommunication Systems</source>
          ,
          <volume>3550</volume>
          ,
          <year>2023</year>
          ,
          <fpage>55</fpage>
          -
          <lpage>69</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Vasylyshyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Susukailo</surname>
          </string-name>
          , I. Opirskyy,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Kurii</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Tyshyk</surname>
          </string-name>
          ,
          <article-title>A Model of Decoy System based on Dynamic Attributes for Cybercrime Investigation</article-title>
          ,
          <string-name>
            <surname>Eastern-European</surname>
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Enterp</surname>
          </string-name>
          . Technol.,
          <volume>1</volume>
          .9(
          <issue>121</issue>
          ) (
          <year>2023</year>
          )
          <fpage>6</fpage>
          -
          <lpage>20</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2023</year>
          .273363
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Kostiuk</surname>
          </string-name>
          , et al.,
          <article-title>A System for Assessing the Interdependencies of Information System Agents in Information Security Risk Management using Cognitive Maps</article-title>
          ,
          <source>in: 3rd Int. Conf. on Cyber Hygiene &amp; Conflict Management in Global Information Networks (CH&amp;CMiGIN)</source>
          , Kyiv, Ukraine, vol.
          <volume>3925</volume>
          ,
          <year>2025</year>
          ,
          <fpage>249</fpage>
          -
          <lpage>264</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Kostiuk</surname>
          </string-name>
          , et al.,
          <article-title>Models and Algorithms for Analyzing Information Risks during the Security Audit of Personal Data Information System</article-title>
          ,
          <source>in: 3rd Int. Conf. on Cyber Hygiene &amp; Conflict Management in Global Information Networks (CH&amp;CMiGIN)</source>
          , Kyiv, Ukraine, vol.
          <volume>3925</volume>
          ,
          <year>2025</year>
          ,
          <fpage>155</fpage>
          -
          <lpage>171</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <article-title>Information Security Risk Management using Cognitive Modeling, in: Cybersecurity Providing in Information and Telecommunication Systems II, CPITS-II, vol</article-title>
          .
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>297</fpage>
          -
          <lpage>305</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Protection of Information in Telecommunication Medical Systems based on a Risk-Oriented Approach, in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>158</fpage>
          -
          <lpage>167</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>I.</given-names>
            <surname>Hanhalo</surname>
          </string-name>
          , et al.,
          <article-title>Adaptive Approach to Ensuring the Functional Stability of Corporate Educational Platforms under Dynamic Cyber Threats</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3991</volume>
          (
          <year>2025</year>
          )
          <fpage>481</fpage>
          -
          <lpage>491</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Suram</surname>
          </string-name>
          , Innovations in Infrastructure Automation:
          <article-title>Advancing IAM in Cloud Security</article-title>
          ,
          <source>Int. J. Sci. Res. Comput. Sci. Eng</source>
          . Inf. Technol.,
          <volume>11</volume>
          (
          <year>2025</year>
          )
          <fpage>255</fpage>
          -
          <lpage>263</lpage>
          . doi:
          <volume>10</volume>
          .32628/CSEIT25111223
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Martseniuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          ,
          <source>Universal Centralized Secret Data Management for Automated Public Cloud Provisioning, in: Cybersecurity Providing in Information and Telecommunication Systems II, 3826</source>
          ,
          <year>2024</year>
          ,
          <fpage>72</fpage>
          -
          <lpage>81</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Martseniuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          , E. Nyemkova,
          <string-name>
            <given-names>M.</given-names>
            <surname>Karpinski</surname>
          </string-name>
          ,
          <article-title>Shadow IT Risk Analysis in Public Cloud Infrastructure</article-title>
          ,
          <source>in: Cyber Security and Data Protection</source>
          ,
          <volume>3800</volume>
          ,
          <year>2024</year>
          ,
          <fpage>22</fpage>
          -
          <lpage>31</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Thokala</surname>
          </string-name>
          ,
          <article-title>Scalable Cloud Deployment and Automation for e-Commerce Platforms using AWS, Heroku</article-title>
          , and Ruby on Rails,
          <source>Int. J. Adv. Res. Sci. Commun</source>
          . Technol. (
          <year>2023</year>
          )
          <fpage>349</fpage>
          -
          <lpage>362</lpage>
          . doi:
          <volume>10</volume>
          .48175/IJARSCT-13555A
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>D.</given-names>
            <surname>Soldatenko</surname>
          </string-name>
          ,
          <article-title>Study of Efficiency of using IT-Infrastructure-as-a-Service for Cloud computing, System Technol</article-title>
          .,
          <volume>2</volume>
          (
          <year>2022</year>
          )
          <fpage>68</fpage>
          -
          <lpage>76</lpage>
          . doi:
          <volume>10</volume>
          .34185/
          <fpage>1562</fpage>
          -9945-2-
          <fpage>139</fpage>
          -2022-07
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>D.</given-names>
            <surname>Narayanasamy</surname>
          </string-name>
          ,
          <article-title>Transforming Healthcare with Secure Cloud Infrastructure</article-title>
          ,
          <source>Int. J. Sci. Res. Comput. Sci. Eng</source>
          . Inf. Technol.,
          <volume>11</volume>
          (
          <year>2025</year>
          )
          <fpage>633</fpage>
          -
          <lpage>644</lpage>
          . doi:
          <volume>10</volume>
          .32628/CSEIT25111271
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>P.</given-names>
            <surname>Narayanan</surname>
          </string-name>
          ,
          <source>Engineering Data Pipelines using Google Cloud Platform</source>
          ,
          <year>2024</year>
          . doi:
          <volume>10</volume>
          .1007/979- 8-
          <fpage>8688</fpage>
          -0602-5_
          <fpage>16</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sreerangapuri</surname>
          </string-name>
          ,
          <article-title>Blockchain-enabled AI Governance for Scalable Cloud Security Automation</article-title>
          ,
          <string-name>
            <given-names>Int. J.</given-names>
            <surname>Comput</surname>
          </string-name>
          . Eng. Technol.,
          <volume>15</volume>
          (
          <year>2024</year>
          )
          <fpage>947</fpage>
          -
          <lpage>959</lpage>
          . doi:
          <volume>10</volume>
          .5281/zenodo.13962366
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>O.</given-names>
            <surname>Deineka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Obshta</surname>
          </string-name>
          ,
          <article-title>Application of LLM for Assessing the Effectiveness and Potential Risks of the Information Classification System According to SOC 2 Type II</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          ,
          <volume>3991</volume>
          ,
          <year>2025</year>
          ,
          <fpage>215</fpage>
          -
          <lpage>232</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>J.</given-names>
            <surname>Ramya</surname>
          </string-name>
          ,
          <article-title>Data-Driven Framework for Cloud Storage Security Optimization: Leveraging Predictive Analytics and Machine Learning to Enhance Threat Detection</article-title>
          and
          <string-name>
            <given-names>Incident</given-names>
            <surname>Response</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Electr</surname>
          </string-name>
          . Syst.,
          <volume>20</volume>
          (
          <year>2024</year>
          )
          <fpage>6646</fpage>
          -
          <lpage>6653</lpage>
          . doi:
          <volume>10</volume>
          .52783/jes.6721
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Deineka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kozachok</surname>
          </string-name>
          ,
          <article-title>Information Classification Framework According to SOC 2 Type II, in: Cybersecurity Providing in Information and Telecommunication Systems II,</article-title>
          <year>3826</year>
          ,
          <year>2024</year>
          ,
          <fpage>182</fpage>
          -
          <lpage>189</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>O.</given-names>
            <surname>Milov</surname>
          </string-name>
          , et al.,
          <article-title>Development of Methodology for Modeling the Interaction of Antagonistic Agents in Cybersecurity Systems</article-title>
          ,
          <string-name>
            <surname>Eastern-European</surname>
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Enterp</surname>
          </string-name>
          . Technol.,
          <volume>2</volume>
          .9(
          <issue>98</issue>
          ) (
          <year>2019</year>
          )
          <fpage>56</fpage>
          -
          <lpage>66</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2019</year>
          .164730
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>D.</given-names>
            <surname>Shevchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Korshun</surname>
          </string-name>
          , Designing Secured Services for Authentication, Authorization, and Accounting of Users,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems II, 3550</source>
          ,
          <year>2023</year>
          ,
          <fpage>217</fpage>
          -
          <lpage>225</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>K.</given-names>
            <surname>Torkura</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. I. H.</given-names>
            <surname>Sukmana</surname>
          </string-name>
          , F. Cheng, C. Meinel, Continuous Auditing &amp;
          <article-title>Threat Detection in Multi-Cloud Infrastructure</article-title>
          , TechRxiv,
          <year>2020</year>
          . doi:
          <volume>10</volume>
          .36227/techrxiv.13108313
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Martseniuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Partyka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Harasymchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Cherevyk</surname>
          </string-name>
          , N. Dovzhenko,
          <article-title>Research of the Centralized Configuration Repository Efficiency for Secure Cloud Service Infrastructure Management</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          ,
          <volume>3991</volume>
          ,
          <year>2025</year>
          ,
          <fpage>260</fpage>
          -
          <lpage>274</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>J. Christian</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
           
          <string-name>
            <surname>Paulino</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
           
          <string-name>
            <surname>Sá</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          <string-name>
            <surname>Low-Cost</surname>
          </string-name>
          and
          <article-title>Cloud Native Solution for Security Orchestration</article-title>
          , Automation, and
          <string-name>
            <surname>Response</surname>
          </string-name>
          ,
          <year>2022</year>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>031</fpage>
          -21280-
          <issue>2</issue>
          _
          <fpage>7</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>H.</given-names>
            <surname>Rehan</surname>
          </string-name>
          ,
          <string-name>
            <surname>Zero-Trust Architecture for Securing Multi-Cloud</surname>
            <given-names>Environments</given-names>
          </string-name>
          , (
          <year>2022</year>
          )
          <fpage>236</fpage>
          -
          <lpage>273</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>J.</given-names>
            <surname>Smith</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Johnson</surname>
          </string-name>
          , R. Patel, G. Christopher,
          <article-title>Enhancing Cloud Security Incident Response with AI</article-title>
          and
          <string-name>
            <surname>Big Data Integration</surname>
          </string-name>
          ,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>P.</given-names>
            <surname>Varadaraj</surname>
          </string-name>
          <article-title>, Multi-Cloud and Hybrid Infrastructure: Addressing Consistency Challenges Across Cloud Providers</article-title>
          ,
          <source>Int. J. Adv. Res. Sci. Commun</source>
          . Technol. (
          <year>2025</year>
          )
          <fpage>520</fpage>
          -
          <lpage>526</lpage>
          . doi:
          <volume>10</volume>
          .48175/IJARSCT-24465
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>