2026· SINTEZA· pp. 117-122· 0 citations· 11 references
TL;DR
This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability, as well as automation risks that are often not covered in vendor manuals.
Abstract
: In every SOC team, a shift starts with hundreds, sometimes thousands, of alerts, and with even more during cyber incidents. In traditional SOC environments, most of these alerts need manual analysis and verification before action is taken. We live in the age of automation and AI, which SOC teams and attackers alike can use. When an attack is conducted with AI tools and automation, this can lead to a shorter response time [1]. Nowadays, there is a lack of IT personnel everywhere, especially those with adequate knowledge. SOC teams face the same personnel issue. The situation is even worse in 24/7 environments [2]. Night shifts are the hardest: false positives come up, people are tired because they normally sleep at these hours, and real threats sometimes go unnoticed. Traditional tools, such as SIEM, IPS/IDS, and EDR, are still part of every SOC and continue to detect threats, but cyber analysts must still perform most response steps by hand [3]. To overcome the problem where analysts have to work manually, SOAR platforms come into play. SOAR platforms connect to traditional SOC tools and leverage their data to automate repetitive tasks (such as IP reputation checks, WHOIS lookups, and hash verifications). In addition, SOAR introduces structure into incident response processes. In this way, security analysts have more time to do other work. This paper will examine the advantages and consequences of adopting SOAR in SOC, including process efficiency, process standardization, and expand-ability. This paper also discusses automation risks that are often not covered in vendor manuals [4]. Using SOAR can greatly reduce response time, sometimes by nearly half. Initial deployment typically takes several months (typically 3-6). The most important benefit for analysts is that they lose less time on repetitive tasks. The size of this benefit depends mostly on how well traditional SOC tools were prepared for integration with the SOAR platform and how well the integration went.
An AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting is focused on.
Bhumika A R, Jhanavi H N, Prof. Thejaswini M N· International Journal of Adv...· 0 citations
Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along wi...
Ebtesam S. Alqahtani, Mohammad Hammoudeh· 0 citations
The promise of automated compliance is falling short of its real-world potential. Although extensive research has proposed many automated compliance solutions, real-world adoption shows that only 18% of organizations have implemented them. This implementation gap is especially critical in Internet of Things (IoT) env...
O. Briliyant, Amir Javed, Yulia Cherdantseva· Journal of Cybersecurity· 0 citations
The findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.
This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.
Jonas Thurner, Nadine Jost, Stefan Albert Horstmann et al.· 0 citations
A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in dig...
Enrique Castellares Cuya, José Rengifo Espinal· International Journal of Com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.