2026· SINTEZA· pp. 117-122· 0 citations· 11 references
TL;DR
This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability, as well as automation risks that are often not covered in vendor manuals.
Abstract
: In every SOC team, a shift starts with hundreds, sometimes thousands, of alerts, and with even more during cyber incidents. In traditional SOC environments, most of these alerts need manual analysis and verification before action is taken. We live in the age of automation and AI, which SOC teams and attackers alike can use. When an attack is conducted with AI tools and automation, this can lead to a shorter response time [1]. Nowadays, there is a lack of IT personnel everywhere, especially those with adequate knowledge. SOC teams face the same personnel issue. The situation is even worse in 24/7 environments [2]. Night shifts are the hardest: false positives come up, people are tired because they normally sleep at these hours, and real threats sometimes go unnoticed. Traditional tools, such as SIEM, IPS/IDS, and EDR, are still part of every SOC and continue to detect threats, but cyber analysts must still perform most response steps by hand [3]. To overcome the problem where analysts have to work manually, SOAR platforms come into play. SOAR platforms connect to traditional SOC tools and leverage their data to automate repetitive tasks (such as IP reputation checks, WHOIS lookups, and hash verifications). In addition, SOAR introduces structure into incident response processes. In this way, security analysts have more time to do other work. This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability. This paper also discusses automation risks that are often not covered in vendor manuals [4]. Using SOAR can greatly reduce response time, sometimes by nearly half. Initial deployment typically takes several months (typically 3-6). The most important benefit for analysts is that they lose less time on repetitive tasks. The size of this benefit depends mostly on how well traditional SOC tools were prepared for integration with the SOAR platform and how well the integration went.
An AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting is focused on.
Bhumika A R, Jhanavi H N, Prof. Thejaswini M N· International Journal of Adv...· 0 citations
The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins, and provide the identification of research gaps and recommendations on creation of new tools.
Ebtesam S. Alqahtani, Mohammad Hammoudeh· 0 citations
This study seeks to understand why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds, and introduces a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting...
O. Briliyant, Amir Javed, Yulia Cherdantseva· Journal of Cybersecurity· 0 citations
The findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.
This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.
Jonas Thurner, Nadine Jost, Stefan Albert Horstmann et al.· 0 citations
A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in dig...
Enrique Castellares Cuya, José Rengifo Espinal· International Journal of Com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.