Security orchestration, automation and response (SOAR) is a category of security software that connects an organization’s security and IT tools, runs automated workflows called playbooks to triage and respond to alerts, and tracks investigations as cases. It takes the repetitive steps analysts would otherwise do by hand, such as looking up an IP address, checking a file’s reputation, opening a ticket or isolating a device, and performs them consistently in seconds or minutes. SOAR is used by security operations teams and by managed security providers, and its features are increasingly built into SIEM and XDR platforms.
At a glance
- SOAR connects security tools through integrations and runs playbooks that automate parts of alert triage and response.
- Typical automations include alert enrichment, phishing triage, ticketing and pre-approved containment actions.
- Case management gives analysts a single record of each incident and what was done.
- Value depends on well-designed, tested playbooks and the people who maintain them.
- Often sold as part of a SIEM or XDR platform, or used behind the scenes by MDR providers, rather than bought standalone.
What problem it solves
A typical security team uses many tools: a SIEM, endpoint protection, email security, identity, firewalls and threat intelligence. Each alert may require an analyst to jump between several of them to gather context, decide whether it matters and take action, then record what happened. With hundreds or thousands of alerts a day, that manual work causes alert fatigue, slow response and inconsistent handling.
SOAR automates the repetitive parts. When an alert arrives, a playbook can pull related logs, check reputations, look up the user and device, and either close obvious false positives or present the analyst with a ready-made case. For confirmed threats, it can run approved response steps, such as quarantining an email or isolating a device, across several tools at once.
How it works
Integrations. SOAR platforms connect to other tools through APIs: SIEM, endpoint and XDR tools, email security, identity providers, firewalls, ticketing systems and threat intelligence feeds. The breadth and quality of these integrations largely determine what can be automated.
Playbooks. A playbook is an automated workflow for a type of incident, often built in a visual editor. It is the automated version of a runbook. For example, a phishing playbook might extract links and attachments from a reported email, check them against threat intelligence, search for the same message in other mailboxes, remove it, and notify the user.
Case management. Alerts are grouped into cases with a timeline of evidence, actions and analyst notes. This supports collaboration, handoffs and later review.
Human approval steps. Playbooks can pause for an analyst to approve high-impact actions, such as disabling an executive’s account, before continuing.
Reporting. Dashboards show alert volumes, time to triage and resolve, and how much work was automated, which helps tune playbooks and justify staffing.
When it matters for buyers
- When your SOC is overwhelmed. If analysts spend most of their time on repetitive enrichment and ticketing, automation can free time for real investigation.
- When choosing a SIEM or XDR platform. Built-in automation may cover your needs without a separate SOAR product.
- When evaluating MDR providers. Ask how much of their triage and response is automated, what actions they can take in your environment, and what you can see.
- When you need consistent, documented response. Playbooks make handling repeatable and create a record that supports incident response reviews, audits and cyber resilience efforts.
- When your team lacks automation skills. Standalone SOAR needs people who can build and maintain playbooks; without them, a managed service may be a better fit.
See our security information and event management overview for platforms that combine detection and automated response.
Questions to ask vendors
- Which of our existing tools do you integrate with out of the box, and who maintains those integrations?
- What prebuilt playbooks are included, and how easily can we change them?
- What skills are needed to build and maintain playbooks: visual editor, scripting or both?
- How are approvals, permissions and audit logs handled for automated actions?
- Is SOAR included in your SIEM or XDR license, or priced separately, and on what basis?
- What metrics show how much time automation is saving?
- If we use an MDR provider, can they use or contribute to our playbooks?
How it differs from SIEM
A security information and event management (SIEM) platform is mainly about data and detection: it collects logs from across your environment, correlates them to spot threats and keeps them for investigation and compliance. SOAR is mainly about action: it takes alerts, from a SIEM or elsewhere, and orchestrates the steps to triage and respond to them. The two are often deployed together, and many vendors now sell them as one platform. A security operations center (SOC) is the team that uses both, and a managed detection and response (MDR) provider is a service that runs that work for you, often using its own automation.
