NTT DATA Group leverages advanced AI models from OpenAI to automate security incident analysis, drastically reducing threat response times. Which processes have been streamlined, and what challenges did engineers face during implementation?
Modern cybersecurity faces a major problem: attacks are becoming increasingly sophisticated, and SOC (Security Operations Center) teams are drowning in a flood of alerts. Analyzing a single incident can take experts several hours – and in the world of digital threats, that is far too long to prevent serious damage. NTT DATA Group, a global IT services provider, decided to streamline this process by implementing advanced AI models from OpenAI as a key component of its threat response system.
Why AI, and not just traditional tools?
Traditional SIEM (Security Information and Event Management) systems, while excellent at detecting anomalies, generate massive amounts of data. Manual verification is tedious and prone to human error. NTT DATA Group was looking for a solution that would:
- Automatically translate raw technical alerts into plain language.
- Accelerate the generation of reports and remediation recommendations.
- Integrate seamlessly with existing infrastructure without requiring a complete overhaul.
The choice fell on advanced OpenAI language models. Within NTT DATA, AI is not used for writing applications, but for interpreting logs, rapidly detecting threat patterns, and proposing concrete countermeasures.
How does the system work in practice?
The implementation of OpenAI solutions at NTT DATA Group is based on several key processes:
1. Automatic log analysis and report generation
When the SIEM system detects a potential incident, the data is fed into the AI model, which prepares a detailed summary in minutes. The report includes:
- A description of the incident (e.g., detection of a brute force attack attempt on a specific server).
- An initial threat level assessment.
- Remediation recommendations (e.g., immediate IP blocking or device isolation).
- Links to documentation and best practices.
Before implementing AI, preparing such a document required manual work by analysts and took a significant amount of time. Today, the entire process is usually completed in just over ten minutes.
2. Translating technical alerts into business language
One of the biggest challenges in the industry is communication between technical teams and management. Language models handle this perfectly, automatically adjusting the tone and level of detail in reports based on the audience:
- For the SOC team: precise technical analysis with logs and vulnerability identification.
- For management: a concise summary of the incident's business impact and strategic recommendations.
As a result, crisis response decisions are made much faster.
3. Integration with SIEM systems and workflow automation
AI does not operate in a vacuum – it works with existing NTT DATA tools, such as Splunk or IBM QRadar. The workflow is simple:
- The SIEM system detects an anomaly and generates an alert.
- Data is sent to the OpenAI model via API.
- The AI analyzes the information and prepares a report.
- The report reaches analysts or automatically triggers basic defensive procedures.
This integration did not require an infrastructure revolution – the AI simply acts as an additional, intelligent analytical layer.
What benefits did the implementation of new technologies bring?
Although NTT DATA Group rarely shares precise internal financial metrics, experience to date points to several clear benefits:
1. Lightning-fast response time
The most important result is reducing incident analysis time from several hours to just a few dozen minutes. This translates into:
- Faster threat neutralization and lower risk of losses.
- Relieving specialists, who can focus on the most difficult, non-standard attacks.
2. Fewer false positives
AI models can analyze incidents in a broader context, making it easier to distinguish real attacks from harmless anomalies. This significantly reduces the number of false alarms that previously consumed the team's time.
3. Higher threat detection rate
Thanks to the ability to associate facts and identify subtle correlations in network traffic, AI helps detect threats that might have escaped traditional, rigid SIEM rules.
4. Operational cost optimization
Faster analysis and fewer false alarms mean real savings. The SOC team operates more efficiently, and the company avoids costly downtime caused by delayed incident response.
Challenges and limitations
Implementing such advanced technology was not without obstacles. NTT DATA had to face several challenges:
1. Integration with legacy systems
Older SIEM tools required API interface adjustments. Language models need structured input data, which forced the company to clean up and standardize log formats across the entire infrastructure.
2. Quality control of analyses
In the initial phase of implementation, the AI could generate inaccurate recommendations or misinterpret specific logs. This problem was solved by:
- Fine-tuning the model on secure, historical NTT DATA data.
- Introducing a "human-in-the-loop" policy, meaning mandatory verification of every report by an experienced analyst.
Thanks to this, the margin of error was reduced to a minimal level.
3. Data privacy and legal issues
Sending sensitive network logs to external models raises understandable concerns. NTT DATA resolved this by:
- Using models within a secure, dedicated cloud, which prevents data from being used to train public algorithms.
- Rigorous data anonymization before analysis, in accordance with GDPR or NIS2 directive requirements.
4. Vendor lock-in
Relying on an external API for security carries risks related to pricing changes or service availability. For this reason, NTT DATA is simultaneously developing its own alternative solutions as a future safeguard.
What incidents does the AI analyze?
The system successfully supports the handling of various threats, including:
- Phishing campaigns – by analyzing suspicious messages and attachments.
- Unauthorized access attempts – e.g., detecting brute force attacks.
- Network anomalies – identifying unusual traffic that may indicate data exfiltration.
- Ransomware threats – early detection of processes attempting to encrypt files.
How does the solution compare to the competition?
There is no shortage of systems supporting SOCs on the market, but the approach based on generative models stands out due to several features:
| Tool | Manufacturer | Key features | Differences vs. OpenAI generative models |
|---|---|---|---|
| Darktrace | Darktrace | Self-learning system, real-time anomaly detection. | Focuses on detection; generating descriptive reports can be slower. |
| IBM QRadar + Watson | IBM | SIEM integration, threat analysis using cognitive algorithms. | Preparing full analyses can be more time-consuming and less flexible. |
| Splunk + ML Toolkit | Splunk | Machine learning-based log analysis, advanced visualizations. | Requires significant effort to configure models; lacks natural language in reports. |
| Microsoft Sentinel | Microsoft | Cloud-native SIEM, response scenario automation. | Less flexibility in deep fine-tuning of models for specific, niche systems. |
The main advantages of OpenAI models are primarily:
- Speed – creating ready-to-implement analyses in just over ten minutes.
- Natural language – exceptional ability to translate technical jargon into understandable conclusions.
- Flexibility – ease of adaptation to the specific needs and data formats of a given organization.
The future of SOC systems at NTT DATA
The company plans further development of these technologies, focusing on several areas:
1. Autonomous response
There are plans to implement secure, automatic remediation scripts. Upon detecting an infection, the system could independently isolate a machine or block traffic on a firewall, waiting only for final human approval.
2. Code security (DevSecOps)
AI is intended to analyze application code at the development stage, pointing out potential security vulnerabilities to developers before the software is deployed to production.
3. Compliance support
Generating compliance reports for standards such as ISO 27001 or PCI DSS based on current logs will save a significant amount of time during audits.
Will AI replace security analysts?
Despite immense progress, AI will not replace humans in SOCs. Its task is to eliminate repetitive, routine tasks, such as initial log screening or report writing. This allows specialists to focus on creatively hunting down advanced cybercriminals. At NTT DATA, this technology acts as an extremely efficient assistant, and the final say always belongs to the human.
Summary
The NTT DATA case shows that generative AI can truly transform the daily work of security teams. The key to success, however, is proper preparation: attention to data quality, ensuring privacy, and maintaining common sense through constant supervision by human experts.
If you want to learn more about AI tools supporting developers, check out our post on how Codex accelerates coding. And if you are interested in how AI is changing the job market, read our analysis of which jobs will disappear and which will emerge by 2030.
"AI will not replace security analysts, but specialists who learn to work effectively with it will quickly replace those who do not."
Sources
- https://openai.com/index/ntt-data
- https://www.blackhat.com/us-25/briefings/schedule/index.html#ntt-data-ai-driven-incident-response-32143
- https://www.forbes.com/sites/forbestechcouncil/2026/03/15/how-ntt-data-is-using-ai-to-revolutionize-cybersecurity/
- https://www.ibm.com/products/qradar-siem
- https://azure.microsoft.com/en-us/products/microsoft-sentinel/
Comments