General session image of Knowledge Forum D

From Alert to Action – SIEM Meets ITSM

Why Detection & Response is only the start – and how ITSM turns it into a controlled, traceable incident process.

Topic

Governance, Riskmanagement and ComplianceIdentity and access managementSIEM / Threat Analytics / SOC

When & Where

calendar_month

Wed, 10/28/2026 10:15 AM - 10:30 AM

location_on

Forum D, Booth 7-742

Download session as iCaldownload_for_offline

Details

  • Format:

    Management lecture

  • Language:

    German

Session description

Speaker: Marcello Centineo

A SIEM detects suspicious activity within seconds and can respond to threats automatically – but does that mean the incident is already resolved? In practice, this is often where the organizational challenge begins: the incident must be assessed and prioritized, responsibilities assigned, actions coordinated, and deadlines met.

This session shows why Detection & Response alone does not cover the entire incident response process of an organization – and how SIEM and ITSM can be connected to create an end-to-end workflow. Using ManageEngine Log360 and ServiceDesk Plus as an example, we follow a security incident from the initial alert through automated ticket creation and context enrichment to technical response and final resolution.

Respon ...