Editorial
SOAR Needs a Second Chance
Automation only works when the foundations do
For many security teams, SOAR became one of cybersecurity's biggest promises. Automate repetitive tasks, orchestrate multiple technologies, reduce analyst workload and respond to incidents faster.
On paper, it made complete sense. In practice, many organisations discovered that buying a SOAR platform was considerably easier than making it deliver meaningful operational value. As a result, SOAR has developed something of an image problem.
It is not uncommon to hear security leaders describe previous SOAR projects as expensive, resource-intensive and difficult to maintain. Playbooks became increasingly complex, integrations required constant attention, and automation often broke whenever a vendor updated an API or changed a workflow. In many environments, analysts simply reverted to doing things manually because it was faster than troubleshooting the automation.
That experience has understandably made some organisations cautious. The interesting question, however, is whether SOAR itself was ever really the problem. Most mature security operations teams would argue that it was not.
Successful automation depends on consistency. If alerts are poorly tuned, asset inventories are incomplete, identities are unmanaged and operational processes vary between teams, automation simply reproduces those inconsistencies at greater speed. SOAR cannot compensate for fragmented security operations any more than an orchestration platform can compensate for poor infrastructure design.
Many early deployments were introduced into environments that were still trying to establish basic operational maturity. Organisations expected automation to solve problems that were fundamentally related to visibility, governance or process standardisation. Unsurprisingly, the results rarely met expectations.
The operating environment has changed considerably since then.
Security platforms have become far more integrated, APIs are significantly more mature, identity has become central to detection and response, and artificial intelligence is beginning to remove much of the complexity involved in building and maintaining workflows. Modern SOAR capabilities increasingly focus on augmenting analysts rather than attempting to replace them entirely.
That distinction matters.
The most effective security operations centres are not pursuing automation for its own sake. They are identifying repetitive, well-understood activities that consume valuable analyst time and introducing automation where consistency delivers measurable operational benefit. Enrichment, threat intelligence correlation, ticket creation, evidence gathering, phishing triage and user notifications are all examples where automation can improve efficiency without removing human judgement from the decision-making process.
Equally important is recognising where automation should stop.
Containment decisions involving critical business systems, complex investigations or high-confidence ransomware events still require experienced analysts who understand both the technical and commercial implications of their actions. Automation can accelerate the process, but accountability remains firmly with people.
Perhaps this is where the conversation around SOAR is finally becoming more balanced.
Rather than viewing automation as a replacement for skilled analysts, organisations are increasingly treating it as a force multiplier that allows those analysts to focus on investigation, threat hunting and higher-value decision making. That represents a far more realistic expectation than the ambitious promises that surrounded the first generation of SOAR deployments.
The technology itself has continued to mature, but perhaps the biggest change has been within security operations teams. Experience has taught the industry that effective automation cannot be deployed in isolation. It depends on good operational discipline, well-defined processes and confidence in the quality of the data flowing through the platform.
When those foundations are in place, SOAR begins to deliver on the promise that first attracted the industry's attention. Without them, it simply automates inefficiency.
Community Note
SOAR continues to evolve alongside modern SOC operations, AI-assisted workflows and security automation. If you have practical experience implementing, managing or optimising SOAR and would like to share your perspective with the MYREDFORT community, we'd love to hear from you.
Please contact our Community Editor, Sam Redwood, at [email protected]