[UPDATE] What is SOAR? What Are The Pros And Potential Pitfalls?

Stu Sjouwerman | Mar 25, 2021

PhishER-1Jessica Groopman at TechTarget's SearchSecurity forum has a great short post about SOAR, what it stands for and what the potential benefits and pitfalls are. Here is an extract with a link to the full article at the bottom. 

"As organizations around the world face a constant and dynamic barrage of cybersecurity threats, the development of tools to accelerate security operations, automation and response, or SOAR, has rapidly increased. SOAR tools are designed for the following functions:

  • Security Orchestration connects and coordinates heterogeneous tool sets and defines incident analysis parameters and processes.
  • Automation automatically triggers specific workflows, tasks and triages based on those parameters, including automated steps for lower-risk incidents.
  • Response accelerates general and targeted responses by enabling a single view for analysts to access, query and share threat intelligence.

There are two main business incentives for adopting SOAR tools in security programs.

  1. SOAR centralizes visibility and insights into threats.
  2. It simultaneously manages the more low-level incidents to support and scale human analysts

SOAR Benefits

Though adoption success may vary depending on the organization, security leaders can anticipate the following benefits of SOAR implementation:

  • improved productivity;
  • less tedious and repetitive work for humans;
  • more strategic allocation for human analysts;
  • process and operational efficiencies in alerts and triage;
  • faster incident response and remediation;
  • centralized and coordinated multivendor security tools and analytics; and
  • increased resilience against growing threat landscape.

Read the full article here, where they also list the possible pitfalls. PhishER is a great example of a SOAR product. 

https://searchsecurity.techtarget.com/feature/Top-benefits-of-SOAR-tools-plus-potential-pitfalls-to-consider

See PhishER Plus in Action

Keep users safe where the most dangers lie: their inboxes

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.