29.07.2025
Blog
Cyber Security

Keeping security incidents under control through monitoring and integration with OpenText

In the third part of our blog series, we turn our attention to the topic of ‘risk’: How can security incidents be identified at an early stage, assessed and dealt with in a targeted manner? We’ll show you how monitoring and IT Service Management (ITSM) work together effectively. This post provides practical insights into how organisations can manage security incidents in an automated and structured way using OpenText Service Management – for greater security and responsiveness in everyday digital operations.

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Having examined the topic of governance in depth in the previous instalment of this series – and business continuity management (BCM) in particular – today we turn our attention to another key element: the handling of security incidents – and how monitoring and ITSM can work together most effectively in this context. The main focus here is on how OpenText Service Management can be used to identify, assess, control and mitigate risks.

Security incidents in OpenText – from alert to automated response

Security incidents cannot simply be generalised. Risks must be weighted differently depending on the organisational context. Let’s consider a simple example: a locked door poses a completely different risk for a jeweller than it does for a nursery. Whilst the jeweller wants to protect against burglary, the nursery’s priority is to prevent children from leaving the premises. Although both scenarios require a protective measure, the assessment and implementation are fundamentally different. It is precisely this way of thinking that can be applied directly to IT risks.

That is why a thorough analysis is required:

  • What exactly needs to be protected?
  • Where is protection required?
  • Which technical measures – from firewalls and intrusion detection systems (IDS) to anti-virus software – are appropriate and necessary?
  • And: How can we detect an impending incident at an early stage?

The role of IT service management

This is where the interplay between monitoring and IT service management with OpenText comes into play. After all, a security incident often begins with a simple event in the monitoring system. If this is detected at an early stage and automatically passed on to service management, a predefined playbook can be triggered: clear response steps, ideally already tested and established. In practice, this means that alerts from the monitoring system directly generate a ticket in the service management system – including all relevant information for the teams responsible.

An interesting feature: our middleware, developed in-house at Materna, checks for every event whether a corresponding ticket has already been created automatically. If one exists, it is simply updated. This provides a consolidated view of clusters of events – for example, just one ticket for 100 similar events. Unlike many standard solutions, where each event generates a separate ticket, this significantly reduces the administrative workload.

Key success factors: communication, awareness and automation

A major problem for many organisations is that security incidents are handled manually, i.e. via email. If the person responsible is unavailable, the entire process grinds to a halt. The situation is even more serious when there are several unconnected data sources – such as a shadow CMDB in Excel format – that are not linked to the central IT Service Management system. In such cases, incidents remain unprocessed or the process is cumbersome and slow.

Our survey, which we carried out as part of a workshop, revealed that there is often a lack of process automation, a lack of central integration of security processes into ITSM – and a lack of security awareness within the organisation. Yet the latter can be practised very effectively in day-to-day work: training sessions, simulated phishing emails or web portals with targeted communication are effective ways of raising awareness of the issue. This, too, can be implemented in a modern service portal.

From event to decision – with data analysis and risk reporting

Finally, there is still a need for integrated analysis of security events. As soon as an event occurs repeatedly in the same location, the system can detect it, analyse it and evaluate it as a pattern or cluster. This makes it possible to identify causes – such as a particular service that keeps attracting attention – and take targeted action.

Risk management does not stop at security incidents: risks can also arise from other areas such as contracts, services, assets, service providers, suppliers or employee data. These are reported – regardless of their source – in the integrated ITSM system and subsequently analysed and assessed by a specialist team using dedicated tools. This provides a centralised overview of all risk factors within the organisation. The key advantage is that the risks under consideration are directly linked to the relevant data records (e.g. configuration items or contracts), thereby ensuring maximum transparency and traceability.

Conclusion: Security as an integrated ITSM process

This article has made it clear that risks can only be actively managed – from detection and assessment through to a structured response – if security processes are fully integrated into IT and Enterprise Service Management, for example using OpenText. Playbooks, reports, automated workflows and clear reporting channels ensure that a security incident does not turn into an emergency. And if it does, the BCM module within the same system has already laid the groundwork for the next step.

In the next instalment of our series, we’ll be looking at compliance: how can regulatory requirements, contracts and internal policies be systematically monitored and managed?

 

Further articles in this series:

Part 1: Governance, Risk and Compliance in Service Management – Materna Blog

Part 2: Business Continuity Management (BCM) and OpenText Service Management: A strong partnership for greater security and efficiency – Materna Blog

Are you interested in further security solutions? Click here to view our cyber security offering.

Dr. Verena Pawolski
Consultant, OpenText Consulting Services

Dr Verena Pawolski works at Materna as a consultant in the OpenText Consulting Services division. She deals with a wide range of aspects relating to IT and enterprise service management and how these are mapped within the tool.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more