LIVE WEBINAR | DATA#3 × DATADOG × SECURITYHQ

Contain First or Investigate First?

The Trade-offs of Modern Incident Response in an AI-Accelerated Threat Landscape

  • Contain too fast and you risk disrupting something the business needs. Wait too long and an attacker gets more time to move.
  • As AI and automation accelerate both attacks and defense, security teams face a new challenge: not simply seeing threats faster, but making the right response decision fast enough.
FEATURING
Aaron Hambleton
Aaron Hambleton
Follow on
Senior Vice President
of Product & Services
@SecurityHQ
Jay Desai
Jay Desai
Follow on
Sr. Solutions Engineer
@Datadog
Lincoln Owens
Lincoln Owens
Follow on
Cyber Security Sales
Specialist
@DATA#3

Register to View

Join the Conversation

This isn’t a product demonstration. It’s a discussion between people working across technology, security operations and customer strategy about one of the most consequential questions facing modern security teams.

Aaron Hambleton

Aaron Hambleton, SecurityHQ

Follow on

Bringing the operational security perspective—how detection, investigation, containment and continuous engineering come together in real-world security environments.

Jay Desai

Jay Desai, Datadog

Follow on

Bringing the technology and AI perspective—how unified telemetry, AI and emerging agentic capabilities are changing how security teams understand, investigate and respond to threats.

Lincoln Owens

Lincoln Owens, Data+3

Follow on

Bringing the customer and business perspective—how organisations are balancing security transformation, AI adoption, operational resilience and risk.

Faster isn’t enough. You need to know when to act.

Modern security teams have unprecedented visibility. AI can correlate signals, accelerate investigations and increasingly take action on behalf of analysts.

But that creates a harder question:

When should you let technology act—and when does the business need a human to make the call?

The answer isn’t simply “automate more.”

The right response depends on confidence, context, business impact and the potential cost of waiting.

This session brings together technology and security operations experts to explore how those decisions are changing as AI becomes more deeply embedded in incident response.

What we’ll explore.

See faster. Decide with confidence. Stop what matters.

See Faster

How AI, telemetry and contextual intelligence are changing detection and investigation, and helping teams find the signals that actually matter.

Know When to Act

What should determine whether an organisation contains immediately, investigates first or allows an automated response to proceed?
Balance Speed and Business Impact
How security teams can reduce attacker dwell time without creating unnecessary operational disruption.

Put AI to Work, Responsibly

Where AI and emerging agentic capabilities can accelerate investigation and response, and where guardrails and human accountability remain essential.

Get Better Every Time

Why the end of an incident shouldn’t be the end of the process, and how response outcomes can help continuously improve security performance.

Key Takeaways: What You’ll Leave With

Attendees will gain a practical perspective on:

  • How to think about the trade-off between response speed, confidence and business consequence
  • Where AI and automation can meaningfully accelerate incident investigation and containment
  • The factors that should determine contain-first vs. investigate-first decisions
  • Why environmental and business context becomes more, not less important as security operations become increasingly automated
  • How organisations can move from simply responding to incidents toward continuously improving security performance

Join the Conversation

This isn’t a product demonstration. It’s a discussion between people working across technology, security operations and customer strategy about one of the most consequential questions facing modern security teams.

Aaron Hambleton

Aaron Hambleton, SecurityHQ

Follow on

Bringing the operational security perspective—how detection, investigation, containment and continuous engineering come together in real-world security environments.

Jay Desai

Jay Desai, Datadog

Follow on

Bringing the technology and AI perspective—how unified telemetry, AI and emerging agentic capabilities are changing how security teams understand, investigate and respond to threats.

Lincoln Owens

Lincoln Owens, Data#3

Follow on

Bringing the customer and business perspective—how organisations are balancing security transformation, AI adoption, operational resilience and risk.

About Datadog

Datadog is the leading observability and security platform for the AI era, providing businesses with unified visibility across the technology stack to manage complexity at scale. It brings applications, infrastructure, data, models, and security into one place, using AI to detect and resolve issues before they impact customers. Trusted globally by Fortune 500 companies and high-growth AI leaders, Datadog enables businesses to move faster with clarity and confidence.

About DATA#3

@DATA#3 Limited (ASX: DTL) is a leading Australian IT services and solutions provider, focused on helping its customers solve complex business challenges using innovative technology solutions. Built on a foundation of more than 48 years’ experience, combined with world-leading vendor technologies, Data#3 delivers an integrated array of solutions spanning cloud, modern workplace, security, data & analytics and connectivity. These technology solutions are delivered by combining Data#3’s services across consulting, project services and support services. Headquartered in Brisbane, it has more than 1,400 staff, and facilities across 12 locations in Australia and Fiji.

About SecurityHQ

SecurityHQ is a global cybersecurity company that helps organizations engineer, measure, and continuously improve the performance of their security operations. Founded in 2003, the company delivers flexible and technology-agnostic solutions through its Security Performance Engineering approach. Built around each customer’s environment, the approach brings together managed detection and response, threat and adversary intelligence, exposure management, and advisory services. With 400+ analysts and engineers across six global SecOps Centers, SecurityHQ provides 24/7 human-led detection, response, and continuous improvement. Its work is focused on reducing noise, improving decision-making, and strengthening security performance over time.

Security, Engineered

to Perform