Security Automation (SOAR): Where Automation Helps, Where It Hurts

Automating the repetitive parts of security operations is a genuine win. Automating the wrong parts creates new problems that look like solutions.

What SOAR actually is

Security Orchestration, Automation, and Response tooling connects the systems a security team already uses — SIEM, ticketing, endpoint tools, threat intelligence feeds — and runs sequences of actions across them. A SOAR platform does not detect threats itself. It coordinates what happens when other systems do.

Where automation is a clear win

The most productive automation targets are the tasks that are repetitive, well-defined, and low-consequence when done at scale:

  • Alert enrichment — pulling context from threat intelligence and internal systems so an analyst starts with a complete picture
  • Deduplication and correlation of related alerts so analysts see one incident, not fifty tickets
  • Evidence gathering during initial investigation, so the analyst is reviewing rather than collecting
  • Routine, well-understood containment actions on user report of phishing
  • User-facing communications that follow a template

Where automation should not go alone

Actions that are consequential, hard to reverse, or dependent on context should keep a human in the loop. Isolating a production server, disabling an executive’s account, or blocking a business partner’s IP range are all recoverable in theory and disruptive in practice. Automation that takes those actions without a check will eventually take them in error, and the recovery cost usually exceeds the analyst time saved.

The useful pattern is automation that prepares a decision — gathers the evidence, drafts the containment, presents the risk — and asks a human to approve it.

The maintenance problem

SOAR playbooks are software, and like all software they rot. APIs change, tools are replaced, and the assumptions built into a playbook drift from reality. Automation that runs unattended for months without review is a source of quiet failure. The best programmes treat playbook maintenance as part of the ongoing work, not as something done once at implementation.

Related in the Knowledge Base

Free Download

Know what an attacker sees before they do.

A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.

Free PDF · No spam · Unsubscribe anytime

Send me the checklist