What SOAR actually is
Security Orchestration, Automation, and Response tooling connects the systems a security team already uses — SIEM, ticketing, endpoint tools, threat intelligence feeds — and runs sequences of actions across them. A SOAR platform does not detect threats itself. It coordinates what happens when other systems do.
Where automation is a clear win
The most productive automation targets are the tasks that are repetitive, well-defined, and low-consequence when done at scale:
- Alert enrichment — pulling context from threat intelligence and internal systems so an analyst starts with a complete picture
- Deduplication and correlation of related alerts so analysts see one incident, not fifty tickets
- Evidence gathering during initial investigation, so the analyst is reviewing rather than collecting
- Routine, well-understood containment actions on user report of phishing
- User-facing communications that follow a template
Where automation should not go alone
Actions that are consequential, hard to reverse, or dependent on context should keep a human in the loop. Isolating a production server, disabling an executive’s account, or blocking a business partner’s IP range are all recoverable in theory and disruptive in practice. Automation that takes those actions without a check will eventually take them in error, and the recovery cost usually exceeds the analyst time saved.
The useful pattern is automation that prepares a decision — gathers the evidence, drafts the containment, presents the risk — and asks a human to approve it.
The maintenance problem
SOAR playbooks are software, and like all software they rot. APIs change, tools are replaced, and the assumptions built into a playbook drift from reality. Automation that runs unattended for months without review is a source of quiet failure. The best programmes treat playbook maintenance as part of the ongoing work, not as something done once at implementation.
Related in the Knowledge Base
- SOC Operations and Threat Hunting: Detection Beyond Alerts
- Incident Response: Playbooks, Forensics, and Why Preparation Wins
- Continuous Threat Exposure Management (CTEM): Beyond Periodic Scans
Know what an attacker sees before they do.
A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.
Free PDF · No spam · Unsubscribe anytime