02Program
SOAR and security automation services for security operations
SOAR implementation, enrichment automation and workflow engineering that removes the mechanical work from security operations, without removing human judgment from decisions.
- Name
- SOAR & Security Automation
- Line
- 02 · AI
- Type
- Outcome program, combines several practices
01The problem
Analyst time goes to work a machine should do.
Analyst time is the scarcest resource in any SOC, and much of it is spent on work a machine should do: pulling context, pivoting between consoles, copying indicators, writing the same closure notes. Automation projects fail when they try to automate judgment instead of toil.
02Scope
What the security automation program covers.
- SOC workflow and toil analysis
- SOAR platform implementation and playbook engineering
- Enrichment automation across telemetry sources
- Approval-gated response automation
- Automation performance measurement
- Playbook governance and change control
03Approach
How a security automation engagement runs.
Platform-agnostic across SOAR products and native automation such as Microsoft Sentinel playbooks and XSOAR-class tooling. The same patterns inform the design of [Autonomous SOC Analyst L1 & L2](/products/autonomous-soc), which is in development, and [security automation research](/security-labs/security-automation) in Security Labs.
Find the toil
Workflow analysis of what your analysts actually do all shift (measured, not guessed) to identify automation with real payback.
Automate enrichment first
Context gathering, entity lookup and intelligence enrichment automated so every alert arrives pre-investigated.
Graduate to response
Containment playbooks automated only where confidence is proven and approval is pre-granted, with audit trails throughout.
04Outcomes
What the security automation program is built to achieve.
- Alert enrichment automated so analysts start with context, not queries
- Repetitive triage steps executed consistently by machine
- Response playbooks for proven scenarios, approval-gated and audited
- Analyst hours redirected from gathering to investigation and hunting
When this work fits
- Security operations teams where enrichment and ticketing consume most of each analyst shift
- Organizations that own a SOAR or SIEM automation feature and have not put it to use
- Teams that want automated containment but need approval gates and an audit trail
- SOC leads who must show measured efficiency gains before adding headcount
05Questions
Security automation: questions we are asked
Start with work that gathers information and changes nothing: alert enrichment, reputation and asset lookups, deduplication, ticket creation and evidence collection. These remove the most analyst time with the least risk. Actions that change state, such as isolating a host, disabling an account or blocking a sender, come later and run behind an approval step until their behavior is proven.
It depends on volume and on how many tools must be coordinated. Native automation in a SIEM or XDR handles simple enrichment and notification well. A SOAR platform earns its cost when playbooks span several products, need case management and need an audit trail. Scripts work for a small team but become hard to maintain and hard to audit. We design for the tools you already own first.
Each playbook is developed against recorded alerts, then run in a mode that logs what it would have done without doing it. Results are compared with analyst decisions on the same alerts. Only when the two agree consistently does the playbook act, and state-changing steps keep an approval gate and a documented way to reverse the action.
By comparing the same measures before and after: analyst time per alert type, time from alert to first decision, the share of alerts closed without human handling, and how often automated decisions are overturned on review. An automation that saves time but is often overturned is a liability, so overturn rate is tracked as closely as speed.
In most cases, yes. Playbooks are built on the APIs of the SIEM, EDR, identity and ticketing tools already in place, including Microsoft Sentinel, Splunk, Elastic and common service desk platforms. Where a managed SOC is also in scope, the same playbooks serve both teams. The Autonomous SOC Analyst is our own product work in this area.
Often alongside
