* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What is security automation?
What is security automation?
============================
Published  February 27, 2026•*3*-minute read
Copy URL
Jump to section
---------------
How does security automation work?Why automate security processes?Which processes can you automate?Why Red Hat?
How does security automation work?
----------------------------------
Security automation uses software to automate the detection, prevention, investigation, and remediation of cyberattacks or similar threats to IT infrastructure. Security automation can reduce the number and severity of IT security incidents while reducing the need for human intervention. Security automation comprises 2 main functions:
### IT security
IT security protects the integrity of technology ecosystems—like computer systems, [networks](/en/technologies/management/ansible/network-automation), and data—from internal or external attack, damage, or unauthorized access. IT security establishes security strategies that work together to help protect [data](/en/topics/data-storage).
[Learn more about IT security](https://www.redhat.com/en/topics/security)
### IT automation
IT automation uses technology to perform repeatable tasks with minimal human assistance, which can reduce manual errors and improve efficiency. IT automation can help teams deliver applications and services faster and more consistently.
[Learn more about IT automation](https://www.redhat.com/en/topics/automation/what-is-it-automation)
By replacing manual [provisioning](/en/topics/automation/what-is-provisioning) and scripting, security automation empowers your teams to pivot from repetitive maintenance to complex, high-priority projects.
[Automate security across environments](/en/engage/automate-security-align-enterprise-ebook)
Why automate security processes?
--------------------------------
Computing environments have sprawled in size and complexity due to shifts like the rise of cloud-native development and distributed workforces. You need to provide security for your [infrastructure](/en/topics/cloud-computing/what-is-it-infrastructure) and networks—a job that keeps getting more difficult.
In such complex environments, manual operations can slow detection and remediation, cause resource [configuration](/en/topics/automation/what-is-configuration-management) errors, and create inconsistent policies. These failures can leave your systems vulnerable to attack and trigger expensive, unplanned downtime.
Automation can help simplify daily operations and integrate security into IT infrastructure, processes, hybrid cloud structures, and applications from the start. Deploying comprehensive security automation can drastically reduce breach-related expenses.
[See how 5 businesses benefit from security automation](/en/engage/enhance-security-with-automation)
Security automation with Red Hat Ansible Automation Platform
------------------------------------------------------------
[Learn more about this use case](/en/technologies/management/ansible/security-automation "Learn more about this use case")
Which security processes can you automate?
------------------------------------------
### Patch management
Patches are code updates that reduce security vulnerabilities. While managing patches across infrastructures is a complex task, keeping systems up-to-date is a primary defense against cyberattacks. Manually identifying vulnerabilities and deploying updates across multiple endpoints can exhaust production time and create unmanageable workloads for IT teams. [Patch management](/en/topics/management/what-patch-management-and-automation) tools automatically deploy and apply updates across systems while generating reports on system status and compliance.
### Threat hunting
Fast threat detection reduces the likelihood of a security breach and associated costs if a breach does occur. Manual processes can delay threat identification in complex IT environments, leaving your business vulnerable to attacks. Applying automation to your security processes can help identify, validate, and prioritize threats faster—without manual intervention.
### Security incident response
Quickly identifying and containing security breaches can significantly reduce the average cost of a breach. But when you’re managing an entire ecosystem of platforms and applications, remediating manually can be time-consuming and error-prone.
Automation empowers security teams to deploy tools that work concurrently, fix affected systems faster, and speed up incident response across the environment. It also simplifies operating and maintaining threat detection solutions like [security information and event management (SIEM)](/en/topics/security/what-is-SIEM) software and [intrusion detection and prevention systems (IDPS)](/en/topics/security/what-is-an-IDPS).
### Endpoint protection
Endpoint Protection Platforms (EPP) detect, investigate, and remediate malicious activities on endpoint devices, which represent the largest and most targeted attack surface in an IT infrastructure.
Unified automation solutions—like [Red Hat® Ansible® Automation Platform](/en/technologies/management/ansible)—help integrate EPP tools into larger security processes that provide event-driven detection, quarantining, and remediation.
[See how event-driven automation speeds up security responses](/en/topics/automation/what-is-event-driven-automation)
Why choose Red Hat for security automation?
-------------------------------------------
Red Hat provides the tools and expertise for a proactive automation strategy.   
As a comprehensive subscription product, [Red Hat Ansible Automation Platform](/en/technologies/management/ansible) can help eliminate manual intervention and ensure security guardrails remain consistent across everything from a single server to complex, multitier environments. By providing hundreds of human-readable [playbooks](/en/topics/automation/what-is-an-ansible-playbook) paired with [Ansible Content Collections](/en/technologies/management/ansible/content-collections), you can connect disparate security solutions and respond to threats rather than running 1 security task at a time.
[Red Hat OpenShift®](/en/technologies/cloud-computing/openshift) is a hybrid cloud platform that uses Kubernetes components and built-in security features to manage user access to pods, nodes, and clusters—helping you stay compliant and efficient.
[Red Hat Advanced Cluster Security for Kubernetes](/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes)automates DevSecOps best practices across the build, deploy, and runtime workflows of the application development lifecycle. The platform works with any Kubernetes environment and integrates with DevOps and security tools. It provides developers with security guardrails and automated checks to help them address security concerns earlier in the development cycle.
### Red Hat’s approach to security and compliance
This video can't play due to privacy settings
To change your settings, select the "Cookie Preferences" link in the footer and opt in to "Advertising Cookies or try disabling adblockers."
Red Hat’s approach to security and compliance: The job is never done (2:21)
Resource
Simplify your security operations center
----------------------------------------
Ready to simplify your SOC? Learn how Red Hat Ansible Automation Platform can help safeguard your business with streamlined security operations.
[Get the resource](/en/engage/security-automation-ebook "Simplify your security operations center")
Red Hat Ansible Automation Platform | Product Trial
---------------------------------------------------
An agentless automation platform.
[Try it](/en/technologies/management/ansible/trial "Red Hat Ansible Automation Platform | Product Trial")
Keep reading
------------
### What is SOAR?
SOAR refers to 3 key software capabilities that security teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence.
[Read the article](/en/topics/security/what-is-soar "article | what is soar")
### What's an insider threat?
An insider threat is leaked or misused data that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
[Read the article](/en/topics/security/what-are-insider-threats "article | What's an insider threat")
### What is post-quantum cryptography?
Learn about Red Hat’s approach to post-quantum cryptography, which refers to encryption algorithms that can resist attacks from quantum computers.
[Read the article](/en/topics/security/post-quantum-cryptography "What is post-quantum cryptography?")
Security resources
------------------
### Related content
* Blog post
  [Build security into ITOps from the start with automation](/en/blog/build-security-itops-start-automation)
* Blog post
  [Managing IT Operations when AI outpaces your patching cycle](/en/blog/managing-it-operations-when-ai-outpaces-your-patching-cycle)
* Blog post
  [Beyond automation: Why the surge in AI-driven security vulnerabilities demands human technical advocacy](/en/blog/beyond-automation-why-surge-ai-driven-security-vulnerabilities-demands-human-technical-advocacy)
* Blog post
  [Fragnesia and friends: When page cache vulnerabilities keep coming back](/en/blog/fragnesia-and-friends-when-page-cache-vulnerabilities-keep-coming-back)
### Related articles
* [AI vs. automation: What’s the difference?](/en/topics/automation/ai-vs-automation-whats-difference)
* [What is microsegmentation?](/en/topics/virtualization/microsegmentation)
* [The journey from observability to AIOps automation](/en/topics/automation/observability-to-aiops-automation)
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [What is infrastructure automation?](/en/topics/automation/what-is-infrastructure-automation)
* [What is patch management?](/en/topics/management/what-patch-management-and-automation)
* [Why choose Red Hat for automation?](/en/topics/automation/why-choose-red-hat-for-automation)
* [What's an insider threat?](/en/topics/security/what-are-insider-threats)
* [What is an Ansible Playbook?](/en/topics/automation/what-is-an-ansible-playbook)
* [What is SOAR?](/en/topics/security/what-is-soar)
* [Learning Ansible basics](/en/topics/automation/learning-ansible-tutorial)
* [How to build an IT automation strategy](/en/topics/automation/build-an-automation-strategy)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [Ansible vs. Puppet: What you need to know](/en/topics/automation/ansible-vs-puppet)
* [Ansible vs. Salt: What you need to know](/en/topics/automation/ansible-vs-salt)
* [Ansible vs. Chef: What you need to know](/en/topics/automation/ansible-vs-chef)
* [Ansible vs. Terraform](/en/topics/automation/ansible-vs-terraform)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [What is IT service management (ITSM)?](/en/topics/automation/what-is-it-service-management-itsm)
* [Automating Microsoft Windows with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-microsoft-windows-with-ansible)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [What is DevOps automation?](/en/topics/automation/what-is-devops-automation)
* [What is Infrastructure as Code (IaC)?](/en/topics/automation/what-is-infrastructure-as-code-iac)
* [Ansible vs. Kubernetes: how they work together](/en/topics/automation/Ansible-vs-Kubernetes)
* [What is cloud migration? And how can automation help?](/en/topics/automation/what-is-cloud-migration)
* [What is a configuration management database (CMDB)?](/en/topics/automation/what-is-a-configuration-management-database-cmdb)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is a software-defined data center (SDDC)?](/en/topics/automation/what-is-a-sddc)
* [What is IT automation?](/en/topics/automation/what-is-it-automation)
* [Why choose Red Hat Ansible Automation Platform as your AI foundation?](/en/topics/automation/automation-and-ai)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is virtual infrastructure management? And how can automation help?](/en/topics/automation/virtual-infrastructure-management)
* [What is IT migration?](/en/topics/automation/what-is-it-migration)
* [How to automate migrations with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-migrations-with-red-hat-ansible-automation-platform)
* [Why use Red Hat Ansible Automation Platform with Red Hat OpenShift?](/en/technologies/cloud-computing/openshift/ansible-on-openshift)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [What is CloudOps?](/en/topics/automation/what-is-cloudops)
* [Red Hat Satellite on Red Hat Enterprise Linux](/en/technologies/management/satellite/satellite-for-rhel)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [Which Red Hat Ansible Automation Platform deployment option is right for you?](/en/technologies/management/ansible/ansible-deployment-options)
* [What is an Ansible module—and how does it work?](/en/topics/automation/what-is-an-ansible-module)
* [How to manage and automate applications at the edge](/en/topics/edge-computing/how-to-manage-automate-applications-edge)
* [How to build an automation Center of Excellence](/en/topics/automation/how-to-build-automation-center-of-excellence)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [What is orchestration?](/en/topics/automation/what-is-orchestration)
* [How to adopt Automation as Code: Extending Infrastructure as Code into Policy as Code](/en/topics/automation/how-to-adopt-automation-as-code)
* [What is a webhook?](/en/topics/automation/what-is-a-webhook)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is an Ansible Role—and how is it used?](/en/topics/automation/what-is-an-ansible-role)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [What is data management?](/en/topics/data-services/what-is-data-management)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is NetOps?](/en/topics/automation/what-is-netops)
* [What is an Ansible Rulebook?](/en/topics/automation/what-is-an-ansible-rulebook)
* [What is edge security?](/en/topics/security/what-is-edge-security)
* [What is configuration management](/en/topics/automation/what-is-configuration-management)
* [What is event-driven automation?](/en/topics/automation/what-is-event-driven-automation)
* [Zero-Touch Provisioning and telco automation with Red Hat](/en/topics/telecommunications/zero-touch-provisioning-and-telco-automation-at-red-hat)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is YAML?](/en/topics/automation/what-is-yaml)
* [What is provisioning?](/en/topics/automation/what-is-provisioning)
* [Understanding Ansible, Terraform, Puppet, Chef, and Salt](/en/topics/automation/understanding-ansible-vs-terraform-puppet-chef-and-salt)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is cloud orchestration?](/en/topics/automation/what-is-cloud-orchestration)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [What is a configuration file?](/en/topics/linux/what-configuration-file)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [Ansible vs. Red Hat Ansible Automation Platform](/en/technologies/management/ansible/ansible-vs-red-hat-ansible-automation-platform)
* [What is cloud automation?](/en/topics/automation/what-is-cloud-automation)
* [What is network automation?](/en/topics/automation/what-is-network-automation)
* [What are managed IT services?](/en/topics/cloud-computing/what-are-managed-it-services)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [What is business process management?](/en/topics/automation/what-is-business-process-management)
* [What is the Red Hat Ansible Automation Platform automation controller?](/en/technologies/management/ansible/automation-controller-product-feature)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [What is business process automation?](/en/topics/automation/what-is-business-process-automation)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [What is IT process automation?](/en/topics/automation/what-is-it-process-automation)
* [What is deployment automation?](/en/topics/automation/what-is-deployment-automation)
* [What is business optimization?](/en/topics/automation/business-optimization)
* [What is Kubernetes cluster management?](/en/topics/containers/what-is-kubernetes-cluster-management)
* [What is SRE?](/en/topics/devops/what-is-sre)
* [What is risk management?](/en/topics/management/what-is-risk-management)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is network management?](/en/topics/management/what-is-network-management)
* [What is financial services security (and compliance)?](/en/topics/security/security-and-compliance-financial-services)
* [What is an SOE?](/en/topics/management/what-is-an-soe)
* [What is IT system life-cycle management?](/en/topics/management/it-system-life-cycle-management)
* [What is API security?](/en/topics/security/api-security)
* [What is robotic process automation (RPA?)](/en/topics/automation/what-is-robotic-process-automation)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
* [What is cloud management?](/en/topics/cloud-computing/what-is-cloud-management)
* [What's business automation?](/en/topics/automation/whats-business-automation)
[More about this topic](/en/topics/security "More about this topic")