WHOOP Cuts Vulnerability Response From Days to Hours With Datadog Automation
The fitness-tracking company replaced its labor-intensive manual triage process with an automated workflow built in a single afternoon, using Datadog's AI and automation tools to identify and remediate security exposures at scale.
Handling a critical vulnerability at WHOOP once demanded the full attention of multiple engineers working through several days of manual investigation: locating the vulnerability, mapping affected systems, and orchestrating the fix. The company has since deployed a Datadog-powered system that monitors vulnerability sources around the clock, pinpoints where the organization faces exposure, and launches remediation efforts with minimal human intervention.
During a virtual event, TNS host Jennifer Riggins spoke with WHOOP Staff Engineer Vinay Raghu and Datadog Senior Product Manager Amber Tunnell about the automated vulnerability-response workflow WHOOP created using Datadog Bits AI and Workflow Automation. Raghu demonstrated the workflow's operation and discussed the technical, operational, and trust factors the team had to navigate when automating such a sensitive security function.
The discussion explored how Bits AI and Workflow Automation combine to enable engineering teams to transition from labor-intensive, all-hands vulnerability response to a faster, more efficient model.
Key Takeaways
- A process that previously consumed three days and four engineers now runs largely on its own, as demonstrated in the live workflow
- The team had to evolve its practices and mindset, not merely swap out tools, before embracing automation for vulnerability response
- WHOOP deliberately preserved human oversight in specific areas and made deliberate choices about where that involvement remains essential
Source: The New Stack