29.07.2025
Blog
Cyber Security

Keeping security incidents under control through monitoring and integration with OpenText

In the third part of our blog series, we turn our attention to the topic of ‘risk’: How can security incidents be identified at an early stage, assessed and dealt with in a targeted manner? We’ll show you how monitoring and IT Service Management (ITSM) work together effectively. This post provides practical insights into how organisations can manage security incidents in an automated and structured way using OpenText Service Management – for greater security and responsiveness in everyday digital operations.

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Having examined the topic of governance in depth in the previous instalment of this series – and business continuity management (BCM) in particular – today we turn our attention to another key element: the handling of security incidents – and how monitoring and ITSM can work together most effectively in this context. The main focus here is on how OpenText Service Management can be used to identify, assess, control and mitigate risks.

Security incidents in OpenText – from alert to automated response

Security incidents cannot simply be generalised. Risks must be weighted differently depending on the organisational context. Let’s consider a simple example: a locked door poses a completely different risk for a jeweller than it does for a nursery. Whilst the jeweller wants to protect against burglary, the nursery’s priority is to prevent children from leaving the premises. Although both scenarios require a protective measure, the assessment and implementation are fundamentally different. It is precisely this way of thinking that can be applied directly to IT risks.

That is why a thorough analysis is required:

  • What exactly needs to be protected?
  • Where is protection required?
  • Which technical measures – from firewalls and intrusion detection systems (IDS) to anti-virus software – are appropriate and necessary?
  • And: How can we detect an impending incident at an early stage?

The role of IT service management

This is where the interplay between monitoring and IT service management with OpenText comes into play. After all, a security incident often begins with a simple event in the monitoring system. If this is detected at an early stage and automatically passed on to service management, a predefined playbook can be triggered: clear response steps, ideally already tested and established. In practice, this means that alerts from the monitoring system directly generate a ticket in the service management system – including all relevant information for the teams responsible.

An interesting feature: our middleware, developed in-house at Materna, checks for every event whether a corresponding ticket has already been created automatically. If one exists, it is simply updated. This provides a consolidated view of clusters of events – for example, just one ticket for 100 similar events. Unlike many standard solutions, where each event generates a separate ticket, this significantly reduces the administrative workload.

Key success factors: communication, awareness and automation

A major problem for many organisations is that security incidents are handled manually, i.e. via email. If the person responsible is unavailable, the entire process grinds to a halt. The situation is even more serious when there are several unconnected data sources – such as a shadow CMDB in Excel format – that are not linked to the central IT Service Management system. In such cases, incidents remain unprocessed or the process is cumbersome and slow.

Our survey, which we carried out as part of a workshop, revealed that there is often a lack of process automation, a lack of central integration of security processes into ITSM – and a lack of security awareness within the organisation. Yet the latter can be practised very effectively in day-to-day work: training sessions, simulated phishing emails or web portals with targeted communication are effective ways of raising awareness of the issue. This, too, can be implemented in a modern service portal.

From event to decision – with data analysis and risk reporting

Finally, there is still a need for integrated analysis of security events. As soon as an event occurs repeatedly in the same location, the system can detect it, analyse it and evaluate it as a pattern or cluster. This makes it possible to identify causes – such as a particular service that keeps attracting attention – and take targeted action.

Risk management does not stop at security incidents: risks can also arise from other areas such as contracts, services, assets, service providers, suppliers or employee data. These are reported – regardless of their source – in the integrated ITSM system and subsequently analysed and assessed by a specialist team using dedicated tools. This provides a centralised overview of all risk factors within the organisation. The key advantage is that the risks under consideration are directly linked to the relevant data records (e.g. configuration items or contracts), thereby ensuring maximum transparency and traceability.

Conclusion: Security as an integrated ITSM process

This article has made it clear that risks can only be actively managed – from detection and assessment through to a structured response – if security processes are fully integrated into IT and Enterprise Service Management, for example using OpenText. Playbooks, reports, automated workflows and clear reporting channels ensure that a security incident does not turn into an emergency. And if it does, the BCM module within the same system has already laid the groundwork for the next step.

In the next instalment of our series, we’ll be looking at compliance: how can regulatory requirements, contracts and internal policies be systematically monitored and managed?

 

Further articles in this series:

Part 1: Governance, Risk and Compliance in Service Management – Materna Blog

Part 2: Business Continuity Management (BCM) and OpenText Service Management: A strong partnership for greater security and efficiency – Materna Blog

Are you interested in further security solutions? Click here to view our cyber security offering.

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Dr. Verena Pawolski arbeitet bei Materna als Consultant im Bereich OpenText Consulting Services. Sie beschäftigt sich mit den verschiedensten Aspekten rund um die Themen IT- und Enterprise Service Management und deren Abbildung im Tool.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more