VOOZH about

URL: https://thenewstack.io/automating-security-7-major-benefits-of-a-soar/

⇱ Automating Security: 7 Major Benefits of a SOAR - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-01-10 06:33:14
Automating Security: 7 Major Benefits of a SOAR
contributed,sponsor-torq,sponsored,sponsored-post-contributed,
Observability / Security

Automating Security: 7 Major Benefits of a SOAR

SOAR platforms are a hot topic in cybersecurity these days, and with good reason. Let’s look at the top seven advantages that modern SOAR platforms provide.
Jan 10th, 2022 6:33am by Chris Tozzi
👁 Featued image for: Automating Security: 7 Major Benefits of a SOAR
Feature image via Pixabay
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
This is the first part of a two-part series. The second part is here.
Chris Tozzi
Chris has worked as a Linux systems administrator and freelance writer with more than 10 years of experience covering the tech industry, especially open source, DevOps, cloud native and security. He also teaches courses on the history and culture of technology at a major university in upstate New York.

SOAR — or security orchestration, automation and response — is a collection of processes, software and tools that allows teams to streamline security operations. SOAR platforms are a hot topic in the realm of cybersecurity these days, and with good reason.

By helping to plan and orchestrate responses to security incidents, SOARs offer critical functionality that extends beyond that provided by security incident and event management (SIEM) platforms, a more conventional type of security tool.

That, at least, is a high-level overview of why SOARs are beneficial. To dive deeper, let’s take a look at the top seven advantages that modern SOAR platforms provide, while also briefly exploring their limitations.

1. Automated Incident Response

By helping to automate the complex tasks that engineers must perform when responding to security incidents, SOAR solutions reduce tedium and toil. Instead of spending time manually assessing risks, formulating a response plan and sharing it with stakeholders, teams can use SOAR tools to automate most aspects of this work.

This makes the security response less burdensome. It also lets engineers focus on the work that feels most important and impactful — remediating complex threats — as opposed to the tedium of poring through alert streams, inviting stakeholders to Slack channels and so on.

2. Faster Incident Response

For related reasons, SOAR platforms increase the velocity of security incident response. The less time engineers have to spend manually planning and orchestrating their response to security incidents, the faster they can work and the shorter their mean time to resolve (MTTR).

That’s important, of course, not just because bosses and customers like faster results, but also because when it comes to security in particular, time is of the essence. The longer a breach remains active and uncontained, the greater the chances that it will escalate, leading to higher costs and greater disruption.

3. Security Process Consistency

Because SOAR platforms automate threat intelligence and response based on rules and conditions that teams configure, they result in highly consistent security operations. Each incident will be handled in the same way, no matter who happens to be on call when it occurs or which type of resource the incident affects.

It’s harder to achieve this type of consistency using tools like SIEMs. The latter rely more heavily on manual processes and therefore result in operational variation from one engineer or incident to the next.

4. Complex Threat Detection

One of the main drawbacks of using a SIEM alone is that SIEMs largely leave it up to users to interpret security alerts and data. As a result, it may be hard to detect threats that are too complex for humans to identify easily. For example, a threat may only become obvious after carefully comparing different types of alerts and contextualizing them with logs and event data, a task that humans are hard-pressed to perform.

SOARs, however, can automatically interpret large volumes of data in order to recognize complex threat patterns. In this regard, SOARs increase businesses’ ability to identify risks, especially those that are particularly complicated in nature.

5. Lower Costs

The automations that SOARs provide typically translate to lower total spend on cybersecurity response. By allowing businesses to handle more threats with fewer engineers, SOAR platforms reduce staffing costs.

SOARs also, as noted above, play an important role in reducing the impact of breaches, which in turn means less financial loss due to disruptions to business operations and compliance fines.

6. Automated Security Reporting

In addition to automating security incident detection and response, SOAR platforms usually provide automated reporting features that record what happened, who did what and which steps ultimately mitigated the threat.

This data is crucial for performing postmortems, as well as for tracking trends in security risks and response over time. It may also be useful for auditing and compliance purposes in cases where businesses are required to document their security operations.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq

7. Limitless Integrations

SOAR solutions can typically integrate with a wide variety of external tools and platforms. Integrations help with two main tasks: collecting the data that SOARs use to detect and assess risks, and managing responses when incidents take place.

Thanks to extensive integrations, it’s usually easy to brick SOARs into any type of environment or technology stack without having to worry about manually moving data into and out of them. The integrations may not always be trivial to set up, and that’s one of the limitations of SOARs, but they at least exist.

SIEMs may also provide some integrations. But, because the functionality of SIEMs is narrower, their integrations are fewer, and they fit less naturally into complex toolchains.

Conclusion: SOAR Platforms Are Awesome, but They’re Not Perfect

In short, SOARs are an essential tool for any organization that aims to take a modern approach to cybersecurity.

However, just because SOARs are great and valuable doesn’t mean they’re the be-all, end-all of security operations and management. On the contrary, SOARs are subject to a variety of limitations, such as being designed mostly for use only by elite security teams or requiring special expertise to integrate with other tools. Understanding and addressing those limitations, which we will discuss more extensively in next week’s article on the drawbacks of SOAR, is critical for any business that uses a SOAR platform today.

But, for now, let’s close by saying that we love SOARs. They’re great and they’re awesome, even if they are not enough on their own to manage all types of security needs and challenges.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq
TRENDING STORIES
Chris Tozzi has worked as a Linux systems administrator and freelance writer. He has more than 10 years of experience covering the tech industry, especially open source, DevOps, cloud native technology and security.
Read more from Chris Tozzi
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma, Torq.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.