Skip to content
Conference Open access

Advantages of SOAR in Comparison to Traditional Security Solutions

2026 · SINTEZA · pp. 117-122 · 0 citations · 11 references

TL;DR

This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability, as well as automation risks that are often not covered in vendor manuals.

Abstract

: In every SOC team, a shift starts with hundreds, sometimes thousands, of alerts, and with even more during cyber incidents. In traditional SOC environments, most of these alerts need manual analysis and verification before action is taken. We live in the age of automation and AI, which SOC teams and attackers alike can use. When an attack is conducted with AI tools and automation, this can lead to a shorter response time [1]. Nowadays, there is a lack of IT personnel everywhere, especially those with adequate knowledge. SOC teams face the same personnel issue. The situation is even worse in 24/7 environments [2]. Night shifts are the hardest: false positives come up, people are tired because they normally sleep at these hours, and real threats sometimes go unnoticed. Traditional tools, such as SIEM, IPS/IDS, and EDR, are still part of every SOC and continue to detect threats, but cyber analysts must still perform most response steps by hand [3]. To overcome the problem where analysts have to work manually, SOAR platforms come into play. SOAR platforms connect to traditional SOC tools and leverage their data to automate repetitive tasks (such as IP reputation checks, WHOIS lookups, and hash verifications). In addition, SOAR introduces structure into incident response processes. In this way, security analysts have more time to do other work. This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability. This paper also discusses automation risks that are often not covered in vendor manuals [4]. Using SOAR can greatly reduce response time, sometimes by nearly half. Initial deployment typically takes several months (typically 3-6). The most important benefit for analysts is that they lose less time on repetitive tasks. The size of this benefit depends mostly on how well traditional SOC tools were prepared for integration with the SOAR platform and how well the integration went.

Read PDF

Similar papers

Open access Jul 2026

SOAR Automation Platform for Cybersecurity Incident Response

An AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting is focused on.

Bhumika A R, Jhanavi H N, Prof. Thejaswini M N · 0 citations
Preprint Aug 2026

A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins, and provide the identification of research gaps and recommendations on creation of new tools.

Ebtesam S. Alqahtani, Mohammad Hammoudeh · 0 citations
Open access 2026

Systematization of human-centered continuous audit for IoT security compliance

This study seeks to understand why auditors struggle to use automated auditing tools and identifying the conditions under which adoption succeeds, and introduces a human-centered auditing framework that maps the research landscape to the three core stages of human auditor workflow: planning, verification, and reporting...

O. Briliyant, Amir Javed, Yulia Cherdantseva · 0 citations
Open access Jul 2026

Automated Cyberattack Response System: A Combination of AI and Human Control with Recommendations for Measurable Actions

The findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.

Febrian Sulistyo Budi, Bondan Wahyu Pamekas, A. Setiawan · 0 citations
Preprint Aug 2026

From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness

This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.

Jonas Thurner, Nadine Jost, Stefan Albert Horstmann et al. · 0 citations
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in dig...

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.