- Newest
- Most votes
- Most comments
Hello.
SIR[1] is a new service that helps you prepare for, respond to, and recover from security events, while IDR is designed to help you improve your operations, increase workload resiliency, and accelerate your recovery from critical incidents.
To sum up the above, SIR is used mainly around security events which helps you as an AWS user on managing security events (Prepare, respond, recover) and IDR is to assist operations, resiliency and recovery on incidents which is workload(s) / applications.
References:
[1] https://aws.amazon.com/about-aws/whats-new/2024/12/aws-security-incident-response/
[2] https://aws.amazon.com/premiumsupport/aws-incident-detection-response/
answered 2 years ago
AWS Security Incident Response (SIR) combines automated capabilities with human expertise to help you prepare for, respond to, and recover from security events — such as ransomware, cryptomining, credential theft, and resource hijacking.
How it works: Continuously monitors and triages security findings from Amazon GuardDuty and third-party detection tools through AWS Security Hub Uses agentic AI-powered investigation to accelerate evidence gathering and analysis Provides direct 24/7 access to Security Incident Response engineers who can investigate, coordinate response across providers, and perform containment actions on your behalf Covers the full incident lifecycle: prepare → detect & analyze → respond → recover Prerequisites: Enable across AWS Organizations; recommended to activate GuardDuty and Security Hub.
AWS Incident Detection and Response (IDR) A premium AWS Support add-on focused on operational uptime and workload resiliency — monitoring your critical production workloads for availability and performance incidents.
How it works: Dedicated Incident Management Engineers (IMEs) monitor your workloads 24/7 via CloudWatch alarms Proactively detects operational issues (e.g., application degradation, infrastructure failures) — sometimes before an AWS service event is even declared Provides single-threaded ownership and coordinates rapid resolution during critical incidents Delivers post-incident reviews and helps improve runbooks Prerequisites: Requires AWS Enterprise Support; per-workload fee; 90-day minimum subscription; workloads must go through onboarding.
When to Use Each Use SIR when you need help with a security event — unauthorized access, compromised credentials, malware, data exfiltration, or suspicious activity detected by GuardDuty **Use IDR when you need proactive monitoring and rapid response for operational incidents **— your critical workload is degraded, experiencing latency, or at risk of downtime
They are complementary — SIR protects against security threats while IDR ensures operational resilience. Many customers benefit from both.
answered a month ago
Relevant content
asked 5 years ago
- AWS OFFICIALUpdated a year ago

Quick correction here
This is not true and AWS AMS is not required to use IDR. However, it looks like you need to have AWS Enterprise Support. More info can be found at https://docs.aws.amazon.com/IDR/latest/userguide/idr-prod-terms.html