SOAR
Security Orchestration, Automation and Response (SOAR) is a platform that ingests alerts from SIEM, EDR and other sources. It executes standardised enrichment and response playbooks and automatically triggers actions in connected systems (identity, firewall, ticketing).
Context
SOAR is the automation layer: alerts from SIEM or EDR flow into playbooks. These enrich alerts with WHOIS, threat intelligence and user context, then trigger responses such as isolation, password resets and tickets. Value depends on two conditions: precise underlying detection and response actions that align with the customer's change process. Without both, SOAR automates wrong decisions faster. See SOC as a Service Switzerland for the framework and how these components work together in SOC operations.
How this compares to neighbouring topics
SOAR is not SIEM and not a replacement for a SOC. SIEM detects, SOAR reacts by playbook, and the SOC team decides where automation ends and humans begin. Without clean detection, SOAR automates noise; without a team, exceptions lack context. See SOC as a Service Switzerland for the framework and how these components work together.