# Best Security Orchestration, Automation, and Response (SOAR) Software - Page 2

## How Many Security Orchestration, Automation, and Response (SOAR) Software Products Does G2 Track?

**Total Products under this Category:** 81

### Category Stats (Jul 2026)

- **Average Rating:** 4.53/5 (↑0.02 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+23.8%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: July 27, 2026_

## How Does G2 Rank Security Orchestration, Automation, and Response (SOAR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,500+ Authentic Reviews
- 81+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software
 ![G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.png?focus%5B%5D=98376&focus%5B%5D=120746&focus%5B%5D=139264&focus%5B%5D=164907&focus%5B%5D=55254&focus%5B%5D=122123&focus%5B%5D=30500&focus%5B%5D=58203)

Highlighted products: Tines, n8n, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, ServiceNow Security Operations, Microsoft Sentinel, Google Security Operations, and Check Point Infinity Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.json?focus%5B%5D=tines&focus%5B%5D=n8n&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=servicenow-security-operations&focus%5B%5D=microsoft-sentinel&focus%5B%5D=google-security-operations&focus%5B%5D=check-point-infinity-platform)

**Sponsored**

### NetWatch OPS

Netwatch OPS, Secure OPS, and AI Ops are three flagship products from netwatch.ai, designed to provide a unified and intelligent platform for managing and securing your entire IT environment. Each product serves a specific purpose, collectively enhancing the efficiency and security of IT operations. Netwatch OPS is a comprehensive monitoring solution that focuses on server, network, and application performance. It delivers real-time insights into hardware performance, network traffic, and application load, consolidating data across your infrastructure. This level of visibility ensures that systems operate at peak efficiency, allowing IT teams to identify and address issues before they escalate into significant problems. The tool is particularly beneficial for organizations that rely on complex IT infrastructures, enabling them to maintain optimal performance and minimize downtime. Secure OPS builds upon the foundational monitoring capabilities of Netwatch OPS by integrating advanced security features. This product continuously analyzes the IT environment for vulnerabilities, threats, and anomalies, providing proactive security insights. By identifying potential breaches before they occur, Secure OPS helps organizations safeguard their sensitive data and maintain compliance with industry regulations. This is especially crucial for businesses operating in sectors where data security is paramount, such as finance and healthcare. AI Ops leverages artificial intelligence and machine learning to automate the detection, analysis, and response to complex cybersecurity incidents. By synthesizing data from multiple sources, AI Ops prioritizes alerts based on severity and predicts potential issues, enabling rapid and effective responses. This automation not only reduces the burden on IT teams but also enhances the overall security posture of the organization. AI Ops is particularly useful for organizations facing a high volume of alerts, as it helps streamline incident management and ensures that critical threats are addressed promptly. The platform also features multi-channel alerting, delivering notifications via email, SMS, or integrations with collaboration tools like Slack and Microsoft Teams. Alerts are categorized by severity—Critical, Warning, or Information—allowing teams to prioritize their responses effectively. Additionally, incident escalation policies are embedded within the system, automating escalation procedures to ensure that critical issues receive prompt attention from the appropriate stakeholders. Together, Netwatch OPS, Secure OPS, and AI Ops form a comprehensive ecosystem that not only monitors and manages IT systems but also enhances security through intelligent automation and real-time analytics. This integrated approach positions netwatch.ai as a leader in innovative cybersecurity and IT operations management, providing organizations with the tools they need to navigate the complexities of modern IT environments.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=2178&secure%5Bchosen_at%5D=2026-07-29T04%3A00%3A59Z&secure%5Bdisplayable_resource_id%5D=1081&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1081&secure%5Bplacement_resource_ids%5D%5B%5D=1011413&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1424823&secure%5Bresource_id%5D=2178&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-orchestration-automation-and-response-soar%3Fpage%3D2&secure%5Btoken%5D=a2bf46c467079282d8dc72f310f6cdca4fa58e8ad86380403e136aea8c3a0777&secure%5Burl%5D=https%3A%2F%2Fnetwatch.ai%2Fcontact&secure%5Burl_type%5D=book_demo)

[
Sumo Logic
](https://www.g2.com/products/sumo-logic/reviews)

By [Sumo Logic](https://www.g2.com/sellers/sumo-logic)

[

4.3/5(404)

](https://www.g2.com/products/sumo-logic/reviews)

What do users say?

Users consistently praise the ease of use and real-time insights provided by Sumo Logic, which significantly enhances their ability to monitor and analyze logs efficiently. The platform's robust query

Pros and Cons

[
Ease of Use (54)
](https://www.g2.com/products/sumo-logic/reviews?qs=pros-and-cons)[
Expensive (18)
](https://www.g2.com/products/sumo-logic/reviews?qs=pros-and-cons)

### [Sumo Logic](https://www.g2.com/products/sumo-logic/reviews)

Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM

**Average Rating:** 4.3/5.0

**Total Reviews:** 392

#### How Do G2 Users Rate Sumo Logic?

- **Automated Remediation:** 8.8/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.4/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Sumo Logic?

- **Seller:** [Sumo Logic](https://www.g2.com/sellers/sumo-logic)
- **Company Website:** www.sumologic.com
- **Year Founded:** 2010
- **HQ Location:** Redwood City, CA
- **Twitter:** @SumoLogic  
6,542 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=405f2514b57035d31a9696f673d9692138c137173787398caeba6974c512d779&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1037816%2F&secure%5Burl_type%5D=linkedin_company_website)  
838 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 48% Medium, 37% Large

#### What Do G2 Reviewers Say About Sumo Logic?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Sumo Logic, finding it simple to learn and configure effectively.
- Users appreciate the **ease of searching and configuring logs** , enhancing their monitoring and tracing capabilities effortlessly.
- Users value the **Continuous Intelligence feature** of Sumo Logic for its quick and actionable insights from diverse data.
- Users commend **Sumo Logic's visual power and flexibility** , enhancing KPI display and minimizing log-related workload.
- Users value the **real-time insights** offered by Sumo Logic, enhancing monitoring and analytics for better decision-making.

##### Cons

- Users find Sumo Logic to be **expensive** , often questioning if its value justifies the high pricing.
- Users find the **difficult learning** curve of Sumo Logic hampers quick proficiency in using its features effectively.
- Users find Sumo Logic's **steep learning curve** challenging, especially when mastering complex queries and setup processes.
- Users find the **steep learning curve** of Sumo Logic challenging, requiring significant time to gain proficiency.
- Users experience **slow performance** due to a clunky UI and delayed alerting, impacting efficiency and response times.

#### What Are Recent G2 Reviews of Sumo Logic?

**["Centralized Logging with Intuitive Dashboards"](https://www.g2.com/survey_responses/sumo-logic-review-12948839)**

**Rating:** 4.5/5.0 stars

_— Sudarshan B._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-12948839)

**["Secure, Privacy-First AI Logging That Helps Reduce Data Breach Risk"](https://www.g2.com/survey_responses/sumo-logic-review-13156334)**

**Rating:** 5.0/5.0 stars

_— Aiyappa Baleyada B._

[Read full review](https://www.g2.com/survey_responses/sumo-logic-review-13156334)

#### What Are G2 Users Discussing About Sumo Logic?

- [What is Cloud SOAR used for?](https://www.g2.com/discussions/what-is-cloud-soar-used-for) - 1 comment, 1 upvote
- [Is Sumo Logic a SIEM?](https://www.g2.com/discussions/is-sumo-logic-a-siem)
- [What is Sumo Logic used for?](https://www.g2.com/discussions/what-is-sumo-logic-used-for)
- [Who are Sumo Logic competitors?](https://www.g2.com/discussions/who-are-sumo-logic-competitors) - 1 comment
- [How much does Sumo Logic cost?](https://www.g2.com/discussions/how-much-does-sumo-logic-cost)

[
Demisto
](https://www.g2.com/products/demisto/reviews)

By [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)

[

4.5/5(15)

](https://www.g2.com/products/demisto/reviews)

What do users say?

Users consistently praise the product for its automation capabilities and security alerts, which help teams respond quickly to potential threats. The intuitive interface and extensive integration opti

### [Demisto](https://www.g2.com/products/demisto/reviews)

Demisto is a platform that provides automated and collaborative security solutions.

**Average Rating:** 4.5/5.0

**Total Reviews:** 15

#### How Do G2 Users Rate Demisto?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Demisto?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®
- **Ownership:** NYSE: PANW

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 53% Medium, 40% Small

#### What Are Recent G2 Reviews of Demisto?

**["great tool for a SOC center"](https://www.g2.com/survey_responses/demisto-review-4499570)**

**Rating:** 5.0/5.0 stars

_— Parth P._

[Read full review](https://www.g2.com/survey_responses/demisto-review-4499570)

**["Great Product for SOC Team"](https://www.g2.com/survey_responses/demisto-review-8594931)**

**Rating:** 5.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/demisto-review-8594931)

[
SIRP
](https://www.g2.com/products/sirp/reviews)

By [SIRP](https://www.g2.com/sellers/sirp)

[

4.7/5(27)

](https://www.g2.com/products/sirp/reviews)

What do users say?

Users consistently praise SIRP for its ease of use and excellent support, which significantly enhance their security operations. The platform's comprehensive features allow for effective incident mana

Pros and Cons

[
Automation (1)
](https://www.g2.com/products/sirp/reviews?qs=pros-and-cons)

### [SIRP](https://www.g2.com/products/sirp/reviews)

SIRP is an AI-native Autonomous SOC platform designed to evolve traditional Security Orchestration, Automation, and Response (SOAR) into governed, decision-driven security operations. Unlike legacy SOAR tools that rely on static playbooks and workflow automation, SIRP enables intelligent AI agents to analyze alerts, compute risk, execute response actions, and continuously learn from outcomes within defined policy boundaries. The platform combines contextual reasoning, real-time intelligence, and adaptive learning to reduce manual triage, minimize alert fatigue, and accelerate incident response while maintaining governance, auditability, and control. SIRP supports enterprise SOC teams and MSSPs seeking to operate at machine speed without sacrificing human oversight for high-impact decisions.

**Average Rating:** 4.7/5.0

**Total Reviews:** 22

#### How Do G2 Users Rate SIRP?

- **Automated Remediation:** 9.2/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.8/10 (Category avg: 9.0/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind SIRP?

- **Seller:** [SIRP](https://www.g2.com/sellers/sirp)
- **Year Founded:** 2017
- **HQ Location:** Bethesda, Maryland
- **Twitter:** @sirp\_io  
74 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2049fa9b2953866d04f7ed23349b11af84e22ba6249541bc03e9737de2b9a196&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F13684515%2F&secure%5Burl_type%5D=linkedin_company_website)  
57 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 41% Small, 37% Medium

#### What Do G2 Reviewers Say About SIRP?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation capabilities** of SIRP, appreciating its comprehensive tools for security orchestration and incident management.
- Users value the **excellent customer support** from SIRP, enhancing their experience with the tool's capabilities.
- Users find SIRP's **ease of use** enhances their experience with efficient security management tools and support.
- Users value the **easy integrations** with SIRP, facilitating seamless connectivity and enhancing overall security automation.
- Users commend SIRP for its **ease of use and excellent support** , enhancing security automation and incident management seamlessly.

#### What Are Recent G2 Reviews of SIRP?

**["SIRP increased our SOC capabilities by 10x. Amazing automation with even better support team"](https://www.g2.com/survey_responses/sirp-review-7612417)**

**Rating:** 5.0/5.0 stars

_— Mushtaq Ahmed K._

[Read full review](https://www.g2.com/survey_responses/sirp-review-7612417)

**["Data Aggregation, Ease of Access and Quick Reporting"](https://www.g2.com/survey_responses/sirp-review-4217597)**

**Rating:** 4.5/5.0 stars

_— Iqra Z._

[Read full review](https://www.g2.com/survey_responses/sirp-review-4217597)

[
Exabeam
](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews)

By [Exabeam](https://www.g2.com/sellers/exabeam)

[

4.6/5(14)

](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews)

What do users say?

Users consistently praise the product for its user-friendly interface and ease of integration with existing systems, making it accessible for security teams. The platform's ability to provide detailed

Pros and Cons

[
Ease of Use (5)
](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews?qs=pros-and-cons)[
Complexity (2)
](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews?qs=pros-and-cons)

### [Exabeam New-Scale Platform](https://www.g2.com/products/exabeam-exabeam-new-scale-platform/reviews)

The Exabeam New-Scale Security Operations Platform is built to help organizations detect, investigate, and respond to insider threats tied to both human users and non-human identities. It brings together behavioral analytics, automation, and AI-driven workflows to help security operations teams reduce risk and maintain operational integrity. The platform supports AI agent-powered threat detection, investigation, and response (TDIR) by automating high-friction tasks and applying behavioral context to every signal. By combining proactive risk identification with fast, guided response, the New-Scale Platform helps teams move from alert handling to informed decision-making. Designed for enterprise security operations teams, the New-Scale Platform supports organizations that need consistent visibility into internal risk without adding operational overhead. Analysts use behavioral analytics to understand what is normal for a user or agent, then quickly spot meaningful deviations. This approach is especially valuable in data-sensitive industries such as finance, healthcare, and technology, where internal misuse, compromised credentials, or agent misuse can create immediate business impact. At the core of the New-Scale Platform is advanced behavioral analytics. The platform analyzes activity patterns across identities, devices, and services to establish baselines of normal behavior. When activity deviates from those baselines, dynamic risk scoring helps security teams focus on the activity most likely to indicate misuse or compromise. This reduces alert noise and shortens the time it takes to understand what is happening and why. The New-Scale Platform also extends user and entity behavior analytics (UEBA) to non-human identities through Agent Behavior Analytics (ABA). ABA applies the same behavior-based approach as UEBA to service accounts, APIs, automation tools, and AI agents. By monitoring how agents typically interact with data and systems, the platform helps teams detect misuse, drift, or compromise that traditional controls often miss. Automation plays a central role in improving day-to-day operations. The New-Scale Platform automates investigation steps, enrichment, and response actions within TDIR workflows, allowing analysts to spend less time on repetitive tasks and more time validating risk and containing incidents. Behavioral context and AI-driven prioritization help teams address the most relevant threats first, improving response consistency without increasing workload. With the Exabeam New-Scale Platform, security teams can benchmark and prove the value of their security program against peers and measurable outcomes. Outcomes Navigator translates raw security data into business-relevant insights to demonstrate progress against the most strategic use cases, MITRE ATT&CK TTPs, and compliance initiatives. Together, user and entity behavior analytics (UEBA), Agent Behavior Analytics (ABA), and agent-powered automated TDIR workflows help security operations teams detect insider risk earlier, investigate faster, and respond with greater precision. The New-Scale Platform gives organizations a practical way to manage insider threats tied to people and agents, accelerate security operations, and prove security impact over time.

**Average Rating:** 4.6/5.0

**Total Reviews:** 14

#### How Do G2 Users Rate Exabeam New-Scale Platform?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Exabeam New-Scale Platform?

- **Seller:** [Exabeam](https://www.g2.com/sellers/exabeam)
- **Company Website:** www.exabeam.com
- **Year Founded:** 2013
- **HQ Location:** Broomfield, CO
- **Twitter:** @exabeam  
5,374 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8269dcd878e7968524f3962a9164ef59bc027b3288cea78560785eb6feaa457e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fexabeam&secure%5Burl_type%5D=linkedin_company_website)  
793 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 57% Large, 29% Medium

#### What Do G2 Reviewers Say About Exabeam New-Scale Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Exabeam New-Scale Platform, enhancing integration and streamlining security processes.
- Users value the **high detection accuracy** of Exabeam New-Scale Platform, enhancing threat identification and response efficiency.
- Users value the **granular integration and robust features** of Exabeam's New-Scale Platform, enhancing security and visibility.
- Users value the **world-class security features** of Exabeam New-Scale Platform, ensuring clarity and reliability in monitoring.
- Users appreciate the **automation capabilities** of Exabeam New-Scale Platform, enhancing response efficiency and reducing manual effort.

##### Cons

- Users find the **complexity** of Exabeam's platform challenging, making setup and management more difficult.
- Users often find the **complex setup** of Exabeam New-Scale Platform challenging, requiring expertise and manual configurations.
- Users find the **difficult setup** of Exabeam New-Scale Platform to be complex, requiring significant expertise to manage effectively.
- Users find **parsing issues** in Exabeam New-Scale Platform hinder usability and complicate data management efforts.
- Users find the **software complexity** can be challenging, requiring significant expertise for effective management and setup.

#### What Are Recent G2 Reviews of Exabeam New-Scale Platform?

**["Gives Security Teams Their Time Back with Smart Threat Visibility"](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-9889355)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-9889355)

**["The perfect SIEM"](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-10644742)**

**Rating:** 5.0/5.0 stars

_— Jorge T._

[Read full review](https://www.g2.com/survey_responses/exabeam-new-scale-platform-review-10644742)

#### What Are G2 Users Discussing About Exabeam New-Scale Platform?

- [What are the components of SIEM?](https://www.g2.com/discussions/what-are-the-components-of-siem) - 1 comment
- [What are three characteristics of SIEM?](https://www.g2.com/discussions/what-are-three-characteristics-of-siem) - 1 comment

[
Swimlane
](https://www.g2.com/products/swimlane/reviews)

By [Swimlane](https://www.g2.com/sellers/swimlane)

[

4.5/5(45)

](https://www.g2.com/products/swimlane/reviews)

What do users say?

Users consistently praise Swimlane for its robust automation and customizable workflows, which streamline incident response and enhance operational efficiency. The platform's ability to integrate with

Pros and Cons

[
Ease of Use (6)
](https://www.g2.com/products/swimlane/reviews?qs=pros-and-cons)[
Complexity (2)
](https://www.g2.com/products/swimlane/reviews?qs=pros-and-cons)

### [Swimlane](https://www.g2.com/products/swimlane/reviews)

Swimlane automates the work security teams hate. As the leader in agentic AI security automation, Swimlane unifies operations across the SOC and beyond with its platform, Swimlane Turbine. The problem is real: over three million SecOps roles sit unfilled, and analysts drown in alerts while juggling 30+ disconnected tools, each with its own schema and quirks. Meanwhile, the average breach now costs $4.5 million. Swimlane closes that gap. Swimlane Hero AI, embedded within the Turbine platform, turns natural-language prompts into automated investigations and responses, cutting MTTR by 75%. Analysts trigger remediation with one click, backed by NIST-aligned case management. Turbine Canvas lets teams build playbooks and agents with no, low, or full code, so automation doesn't wait on a developer's calendar. The Swimlane Marketplace adds a growing library of agents, integrations, and playbooks, built on demand at no cost, ending vendor lock-in for good. Under the hood, Swimlane's Active Sensing Fabric ingests data at scale, pushing capability beyond traditional SOAR. Cloud-native architecture backs it up: one customer runs 25 million automated actions a day at 75,000 actions per minute. That's not a demo number. That's production. Analysts get customizable dashboards and AI-augmented reporting that turn raw activity into KPIs executives actually read, proving ROI without a translation layer. The market has taken notice. Independent evaluations against 15+ competitors all point the same direction: Swimlane leads. Inc. named it Best in Business. Customers at Northern Power, Toshiba, Weedmaps, and InComm Payments back that up, citing customizable playbooks, dashboards, and a professional services team that shows up when it counts. Swimlane doesn't just orchestrate security tasks. It gives every security function, from vulnerability management to compliance to business continuity, a way to move faster than the threats they're chasing.

**Average Rating:** 4.5/5.0

**Total Reviews:** 45

#### How Do G2 Users Rate Swimlane?

- **Automated Remediation:** 9.2/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.5/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Swimlane?

- **Seller:** [Swimlane](https://www.g2.com/sellers/swimlane)
- **Year Founded:** 2014
- **HQ Location:** Boulder, US
- **Twitter:** @swimlane  
1,628 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=54abf460b3230463ad45bfc2ec36495d4bda03575d4a4a071cbb1404dcee6c54&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F4807837%2F&secure%5Burl_type%5D=linkedin_company_website)  
266 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 60% Medium, 31% Small

#### What Do G2 Reviewers Say About Swimlane?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Swimlane, enabling seamless integration and efficient automation across security tools.
- Users value the **easy integrations** of Swimlane, enhancing security operations effortlessly across various tools.
- Users value Swimlane's **versatile workflows** , benefiting from a comprehensive solution and supportive customer success team.
- Users appreciate the **seamless integration capabilities** of Swimlane, enhancing security monitoring and workflow efficiency.
- Users value the **low-code automation** of Swimlane, enabling endless possibilities for enhancing security and operational efficiency.

##### Cons

- Users find Swimlane **complex to set up and maintain** , requiring time and skills to navigate effectively.
- Users note a steep **learning curve** with Swimlane, requiring time and possibly development skills for effective setup.
- Users face **limited resources** for support and documentation, complicating the initial setup and ongoing maintenance of Swimlane.
- Users experience **poor customer support** , with slow responses and issues requiring engineering assistance for upgrades.
- Users find the **poor interface design** of Swimlane cluttered and difficult to navigate, affecting overall usability.

#### What Are Recent G2 Reviews of Swimlane?

**["Powerful Automation with Swimlane"](https://www.g2.com/survey_responses/swimlane-review-8782607)**

**Rating:** 4.5/5.0 stars

_— Verified User in Financial Services_

[Read full review](https://www.g2.com/survey_responses/swimlane-review-8782607)

**["I have used swimlane as an analyst and have had a little experience working with the backend."](https://www.g2.com/survey_responses/swimlane-review-8789592)**

**Rating:** 4.5/5.0 stars

_— Maguire S._

[Read full review](https://www.g2.com/survey_responses/swimlane-review-8789592)

#### What Are G2 Users Discussing About Swimlane?

- [What is Swimlane used for?](https://www.g2.com/discussions/what-is-swimlane-used-for)

[
Blumira Automated Detection...
](https://www.g2.com/products/blumira-automated-detection-response/reviews)

By [Blumira](https://www.g2.com/sellers/blumira)

[

4.6/5(124)

](https://www.g2.com/products/blumira-automated-detection-response/reviews)

What do users say?

Users consistently praise the product for its ease of use and quick setup, allowing organizations to integrate and monitor their security environments with minimal effort. The automated alerts and act

Pros and Cons

[
Ease of Use (34)
](https://www.g2.com/products/blumira-automated-detection-response/reviews?qs=pros-and-cons)[
Limited Customization (11)
](https://www.g2.com/products/blumira-automated-detection-response/reviews?qs=pros-and-cons)

### [Blumira Automated Detection & Response](https://www.g2.com/products/blumira-automated-detection-response/reviews)

Blumira is an integrated security operations platform built for growing teams and the partners supporting them to gain complete visibility into their environment, identify and address risk faster, and deliver advanced security and compliance. The platform includes: - Managed Detections for automated threat hunting to identify attacks early - AI Investigation with 98.5% accurate, human-in-the-loop triage validated against real cases - Rapid Response with automation and 1-click actions to contain and block threats immediately - One Year of Data Retention with unlimited log ingestion to satisfy compliance requirements - Advanced Reporting and dashboards for forensics and easy investigation - Endpoint & Identity Protection (EDR/ITDR) for real-time remediation across devices and users - 24/7 Security Operations support for critical priority issues

**Average Rating:** 4.6/5.0

**Total Reviews:** 122

#### How Do G2 Users Rate Blumira Automated Detection & Response?

- **Automated Remediation:** 7.5/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Blumira Automated Detection & Response?

- **Seller:** [Blumira](https://www.g2.com/sellers/blumira)
- **Company Website:** www.blumira.com
- **Year Founded:** 2018
- **HQ Location:** Ann Arbor, Michigan
- **Twitter:** @blumira  
1 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2a04d201c0abee0744509c17e4beed4ccbdbde532e5d35f04981851a7ee48cfa&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblumira%2F&secure%5Burl_type%5D=linkedin_company_website)  
67 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** IT Manager
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Medium, 36% Small

#### What Do G2 Reviewers Say About Blumira Automated Detection & Response?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Blumira, noting the quick setup and responsive support team.
- Users value the **responsive and personalized support** from Blumira's SOC team, enhancing their overall experience significantly.
- Users find the **setup process incredibly easy** , with intuitive integration and immediate alert functionalities boosting security management.
- Users value the **reliable real-time alerting** of Blumira, enhancing their experience without overwhelming them with unnecessary notifications.
- Users value the **reliable real-time alerting** of Blumira, appreciating its clarity and ease of management.

##### Cons

- Users find the **limited customization** in detection filters a drawback, despite helpful support for creating custom detections.
- Users face issues with **false positives** from alerts, which can disrupt business functions and waste valuable time.
- Users find the **pricing model inflexible and expensive** , making it difficult to meet their budgetary needs.
- Users face challenges with **false positives** in Blumira, leading to frustration and wasted time on repetitive alerts.
- Users note the **insufficient information** available on data intake, making search and usability challenging.

#### What Are Recent G2 Reviews of Blumira Automated Detection & Response?

**["Breeze From Sales to Onboarding With an Intuitive, Easy-to-Configure UI"](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)**

**Rating:** 5.0/5.0 stars

_— Blake C._

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)

**["A well-rounded detection system with fantastic support"](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)**

**Rating:** 5.0/5.0 stars

_— Jeremy A._

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)

#### What Are G2 Users Discussing About Blumira Automated Detection & Response?

- [What are the benefits and drawbacks of using Blumira for threat detection?](https://www.g2.com/discussions/what-are-the-benefits-and-drawbacks-of-using-blumira-for-threat-detection)
- [What is cloud SIEM?](https://www.g2.com/discussions/what-is-cloud-siem)
- [What does the term Siem stand for?](https://www.g2.com/discussions/what-does-the-term-siem-stand-for)
- [What does Blumira do?](https://www.g2.com/discussions/what-does-blumira-do)
- [What is Blumira automated detection & response?](https://www.g2.com/discussions/what-is-blumira-automated-detection-response)

[
CrowdSec
](https://www.g2.com/products/crowdsec/reviews)

By [CrowdSec](https://www.g2.com/sellers/crowdsec)

[

4.7/5(88)

](https://www.g2.com/products/crowdsec/reviews)

What do users say?

Users consistently praise the product for its ease of use and effective threat detection, highlighting its ability to block malicious IPs through a community-driven database. Many appreciate the open-

### [CrowdSec](https://www.g2.com/products/crowdsec/reviews)

CrowdSec is an open-source security stack that detects aggressive behaviors and prevents them from accessing your systems. Its user-friendly design and ease of integration into your current security infrastructure offer a low technical entry barrier and a high-security gain. Once an unwanted behavior is detected, it is automatically blocked. The aggressive IP, scenario triggered and the timestamp is sent for curation, to avoid poisoning & false positives. If verified, this IP is then redistributed to all CrowdSec users running the same scenario. By sharing the threat they faced, all users are protecting each other.

**Average Rating:** 4.7/5.0

**Total Reviews:** 85

#### How Do G2 Users Rate CrowdSec?

- **Automated Remediation:** 9.1/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.6/10)
- **Workflow Automation:** 7.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind CrowdSec?

- **Seller:** [CrowdSec](https://www.g2.com/sellers/crowdsec)
- **Year Founded:** 2020
- **HQ Location:** Paris, FR
- **Twitter:** @Crowd\_Security  
19,491 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=238a2dc675f271083f55d292782de9a0fd0d3d7b188bf6de40ee7f4a3b264b37&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcrowdsec%2F%3ForiginalSubdomain%3Dfr&secure%5Burl_type%5D=linkedin_company_website)  
30 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 69% Small, 20% Medium

#### What Are Recent G2 Reviews of CrowdSec?

**["It's a real life-saver in terms of hosting stuff"](https://www.g2.com/survey_responses/crowdsec-review-8191423)**

**Rating:** 5.0/5.0 stars

_— Rei B._

[Read full review](https://www.g2.com/survey_responses/crowdsec-review-8191423)

**["Crowdsec best endpoint in SMB"](https://www.g2.com/survey_responses/crowdsec-review-11691179)**

**Rating:** 5.0/5.0 stars

_— Pramod s._

[Read full review](https://www.g2.com/survey_responses/crowdsec-review-11691179)

#### What Are G2 Users Discussing About CrowdSec?

- [What are the benefits and drawbacks of using CrowdSec for cybersecurity, and what do you recommend for improvement?](https://www.g2.com/discussions/what-are-the-benefits-and-drawbacks-of-using-crowdsec-for-cybersecurity-and-what-do-you-recommend-for-improvement)
- [What is CrowdSec used for?](https://www.g2.com/discussions/what-is-crowdsec-used-for) - 1 comment

[
Shuffle
](https://www.g2.com/products/shuffle/reviews)

By [Shuffle AS](https://www.g2.com/sellers/shuffle-as)

[

4.8/5(15)

](https://www.g2.com/products/shuffle/reviews)

What do users say?

Users consistently praise the ease of use and integration capabilities of this software, highlighting its effectiveness in creating automated workflows with minimal learning curve. Many appreciate the

### [Shuffle](https://www.g2.com/products/shuffle/reviews)

Shuffle is an open source automation platform for security professionals (SOAR). Run it locally: https://github.com/frikky/shuffle Try it out here: https://shuffler.io/register Join the community: https://discord.gg/B2CBzUm

**Average Rating:** 4.8/5.0

**Total Reviews:** 15

#### How Do G2 Users Rate Shuffle?

- **Automated Remediation:** 9.5/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.4/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.4/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Shuffle?

- **Seller:** [Shuffle AS](https://www.g2.com/sellers/shuffle-as)
- **HQ Location:** San Francisco, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=479ad5921f7211dd811f8bbc9041507d3551951c69218e73704aa4b54a9c15b0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgetshuffleapp%2F&secure%5Burl_type%5D=linkedin_company_website)  
7 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 67% Medium, 33% Small

#### What Are Recent G2 Reviews of Shuffle?

**["Shuffle Open-Source SOAR"](https://www.g2.com/survey_responses/shuffle-review-8284361)**

**Rating:** 5.0/5.0 stars

_— Rohan G._

[Read full review](https://www.g2.com/survey_responses/shuffle-review-8284361)

**["Perfect automation tool for your soc"](https://www.g2.com/survey_responses/shuffle-review-10067052)**

**Rating:** 5.0/5.0 stars

_— Ayush G._

[Read full review](https://www.g2.com/survey_responses/shuffle-review-10067052)

#### What Are G2 Users Discussing About Shuffle?

- [What is Shuffle used for?](https://www.g2.com/discussions/what-is-shuffle-used-for) - 2 comments

[
guardsix
](https://www.g2.com/products/guardsix/reviews)

By [guardsix](https://www.g2.com/sellers/guardsix)

[

4.3/5(108)

](https://www.g2.com/products/guardsix/reviews)

What do users say?

Users consistently praise the product for its ease of use and intuitive interface, which simplifies navigating complex security data. Many appreciate the comprehensive support and the ability to quick

Pros and Cons

[
Ease of Use (8)
](https://www.g2.com/products/guardsix/reviews?qs=pros-and-cons)[
Poor Interface Design (3)
](https://www.g2.com/products/guardsix/reviews?qs=pros-and-cons)

### [Guardsix](https://www.g2.com/products/guardsix/reviews)

Guardsix is the sovereign security platform for lean European teams, bringing log management and audit-ready compliance to regulated industries, critical national infrastructure operators, and the Managed Security Service Providers (MSSPs) that serve them throughout Europe and beyond. Headquartered in Copenhagen, Denmark, Guardsix delivers sovereign-by-design security for organisations that carry real operational responsibility. The company employs several hundred cyber security specialists and keeps every organisation it serves in full control of their data, deployment, and operations. Guardsix provides a unified Command Centre platform combining: • Security Information and Event Management (SIEM) • Network Detection and Response (NDR) • Security Orchestration, Automation and Response (SOAR) • Fleet for enabling multi-tenant management • Governance for Healthcare internal risk compliance monitoring The platform is built to support European data sovereignty, regulatory compliance and operational control, with predictable node-based pricing and deployment options spanning on-premises, air-gapped, hybrid and cloud environments. Guardsix solutions help organisations: • Simplify audit readiness for regulations such as NIS2, DORA, and GDPR. • Support lean security teams with efficient log management and simplified workflows. • Scale security operations without increased complexity or ingestion-led pricing surprises. • Keep security data under European jurisdiction and control — where it lives, who operates it, and under whose laws. • Deploy on their own terms, on-prem and in infrastructure they control, keeping migration a real option at every renewal. • See clearly across their whole environment, with SIEM, NDR, SOAR, Fleet, and Governance in one sovereign platform rather than a stack of point tools. Guardsix maintains SOC 2 Type II attestation and designs its solutions in accordance with European data protection requirements. With a strong partner-first model, Guardsix works closely with regional MSSPs and service providers, combining sovereign-by-design security technology with European integrity and deployment flexibility.

**Average Rating:** 4.3/5.0

**Total Reviews:** 105

#### How Do G2 Users Rate Guardsix?

- **Automated Remediation:** 8.5/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Guardsix?

- **Seller:** [guardsix](https://www.g2.com/sellers/guardsix)
- **Company Website:** guardsix.com
- **Year Founded:** 2001
- **HQ Location:** Copenhagen, Capital Region
- **LinkedIn® Page:** [linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=92bf20089a2ec7456b77a9cafe8277355b36f5113b6cae2b0f9df3a0cfc82f20&secure%5Burl%5D=https%3A%2F%2Flinkedin.com%2Fcompany%2Fguardsix&secure%5Burl_type%5D=linkedin_company_website)  
162 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 44% Medium, 31% Small

#### What Do G2 Reviewers Say About Guardsix?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Guardsix, making administration and navigation simple and efficient.
- Users appreciate the **effortless integration and usability** of Logpoint, enhancing efficiency in managing diverse log data.
- Users appreciate the **excellent customer support** provided by Logpoint, enhancing their experience and satisfaction with the product.
- Users appreciate the **easy integrations** of Guardsix, allowing seamless compatibility with their tech ecosystem for enhanced functionality.
- Users appreciate the **efficiency** of Guardsix in managing incidents and integrating with existing tools seamlessly.

##### Cons

- Users criticize the **poor interface design** of Guardsix, finding it difficult to understand and navigate effectively.
- Users find the **poor log presentation** and overall interface slow, hindering their experience with Guardsix.
- Users find the **interface complexity** challenging, but hope for improvements in the near future.
- Users find the **confusing interface** of Guardsix difficult to navigate and slow to respond.
- Users find there is an **information deficiency** regarding appliance design and resource requirements for new devices.

#### What Are Recent G2 Reviews of Guardsix?

**["Context-Driven SIEM That Enhances Incident Response"](https://www.g2.com/survey_responses/guardsix-review-11985484)**

**Rating:** 4.5/5.0 stars

_— Simon A._

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11985484)

**["Review"](https://www.g2.com/survey_responses/guardsix-review-11378057)**

**Rating:** 4.0/5.0 stars

_— Ronny K._

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11378057)

#### What Are G2 Users Discussing About Guardsix?

- [What is your experience with Logpoint for SIEM, and what do you recommend for new users?](https://www.g2.com/discussions/what-is-your-experience-with-logpoint-for-siem-and-what-do-you-recommend-for-new-users)
- [What is LogPoint used for?](https://www.g2.com/discussions/what-is-logpoint-used-for)

[
Intezer
](https://www.g2.com/products/intezer-intezer/reviews)

By [Intezer](https://www.g2.com/sellers/intezer)

[

4.5/5(193)

](https://www.g2.com/products/intezer-intezer/reviews)

What do users say?

Users consistently praise the ease of use and detailed analysis provided by Intezer, making it a valuable tool for malware detection and threat intelligence. The intuitive interface and fast integrati

Pros and Cons

[
Security (3)
](https://www.g2.com/products/intezer-intezer/reviews?qs=pros-and-cons)[
Access Control (1)
](https://www.g2.com/products/intezer-intezer/reviews?qs=pros-and-cons)

### [Intezer](https://www.g2.com/products/intezer-intezer/reviews)

Intezer automates the entire alert triage process, like an extension of your team handling Tier 1 SOC tasks for every alert at machine-speed. Intezer monitors incoming incidents from endpoint, reported phishing pipelines, or SIEM tools, then autonomously collects evidence, investigates, makes triage decisions, and escalates only the serious threats to your team for human intervention. Power your SOC with artificial intelligence that makes sure every alert is deeply analyzed (including every single artifact like files, URLs, endpoint memory, etc.), detecting malicious code in memory and other evasive threats. Fast set up and integrations with your SOC team's workflows (EDR, SOAR, SIEM, etc.) means Intezer's AI can immediately start filtering out false positives, giving you detailed analysis about every threat, and speeding up your incident response time. With Intezer: • Reduce Tier 1 escalation, sending only 4% of alerts on average to your team for immediate action. • Identify up to 97% of false positive alerts without taking any time from your analysts. • Reduce average triage time to 5 minutes or less, while giving your analysts deep context about every alert to prioritize critical treats and respond faster.

**Average Rating:** 4.5/5.0

**Total Reviews:** 187

#### How Do G2 Users Rate Intezer?

- **Automated Remediation:** 9.2/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Intezer?

- **Seller:** [Intezer](https://www.g2.com/sellers/intezer)
- **Year Founded:** 2015
- **HQ Location:** New York
- **Twitter:** @IntezerLabs  
10,170 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2bb3f434ddd03b2eadc1dca940a470eceb4074073fc162fe6fda3c58b709625e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10656303%2F&secure%5Burl_type%5D=linkedin_company_website)  
88 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Student
- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 54% Small, 23% Medium

#### What Do G2 Reviewers Say About Intezer?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **strong security features** of Intezer, ensuring timely detection and blocking of malware.
- Users value Intezer for its **effective malware detection and security features** that enhance overall system protection.
- Users value the **ease of malware detection and blocking** with Intezer, enhancing overall cybersecurity effectiveness.
- Users value the **high detection accuracy** of Intezer, ensuring timely malware detection and enhanced system security.
- Users appreciate the **ease of use** of Intezer, making malware detection and security integration straightforward and efficient.

##### Cons

- Users find the **lack of access control** to file visibility a downside, though it facilitates peer review benefits.
- Users express frustration with the **complex interface** of Intezer, finding it difficult to navigate and use effectively.
- Users find the **lack of control over file visibility** a downside, despite potential benefits for peer review.
- Users find the **difficult navigation** in Intezer frustrating due to a poorly designed UI and small text size.
- Users find the **expensive pricing** of Intezer limiting, particularly due to the capping of the free tier.

#### What Are Recent G2 Reviews of Intezer?

**["CTI coordinator"](https://www.g2.com/survey_responses/intezer-review-5353729)**

**Rating:** 4.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/intezer-review-5353729)

**["Effortless Malware Detection and Robust Endpoint Security With Intezer"](https://www.g2.com/survey_responses/intezer-review-12060113)**

**Rating:** 4.5/5.0 stars

_— Franck P._

[Read full review](https://www.g2.com/survey_responses/intezer-review-12060113)

#### What Are G2 Users Discussing About Intezer?

- [What is genetic malware analysis?](https://www.g2.com/discussions/what-is-genetic-malware-analysis) - 1 comment
- [Is Intezer good?](https://www.g2.com/discussions/is-intezer-good) - 1 comment
- [What does Intezer do?](https://www.g2.com/discussions/what-does-intezer-do) - 1 comment
- [What is Intezer analyze?](https://www.g2.com/discussions/what-is-intezer-analyze) - 2 comments

[
D3 Security
](https://www.g2.com/products/d3-security/reviews)

By [D3 Security Management Systems](https://www.g2.com/sellers/d3-security-management-systems)

[

4.2/5(69)

](https://www.g2.com/products/d3-security/reviews)

What do users say?

Users consistently praise the user interface and customer support of D3 Security, highlighting its ease of use and responsiveness. Many appreciate its ability to streamline incident management and enh

### [D3 Security](https://www.g2.com/products/d3-security/reviews)

D3 stands at the forefront of AI-powered security, providing real-time, autonomous SOC solutions that help organizations stay ahead of cyber threats. By merging autonomous investigation and triage with AI-guided remediation, D3 is delivering AI-powered, human-led cyber security solutions. Morpheus is D3 Security’s fully autonomous SOC solution that triages, investigates, and responds to every alert, 24/7. Morpheus covers 100% of your alerts — no exceptions — so your team never has to choose between chasing false positives or risking a breach. It triages 95% of alerts in under two minutes, integrating seamlessly with any SIEM, XDR, or security stack. Unlike traditional SOAR platforms, Morpheus doesn’t need endless playbook tuning; it can build response workflows on the fly, specific to your security stack. The result? Zero alert fatigue, fewer missed threats, and a dramatic boost in SOC efficiency, powered by a data privacy-friendly and SecOps-focused AI model.

**Average Rating:** 4.2/5.0

**Total Reviews:** 64

#### How Do G2 Users Rate D3 Security?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.6/10)
- **Workflow Automation:** 6.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind D3 Security?

- **Seller:** [D3 Security Management Systems](https://www.g2.com/sellers/d3-security-management-systems)
- **Year Founded:** 2012
- **HQ Location:** Vancouver, British Columbia
- **Twitter:** @D3Security  
1,118 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e5845965397adf4071b06f49eff850d4e9ab889560ddc9e82faade8524df1c6e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F342986%2F&secure%5Burl_type%5D=linkedin_company_website)  
162 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 49% Large, 41% Medium

#### What Are Recent G2 Reviews of D3 Security?

**["The best security operation platform"](https://www.g2.com/survey_responses/d3-security-review-3110773)**

**Rating:** 5.0/5.0 stars

_— George K._

[Read full review](https://www.g2.com/survey_responses/d3-security-review-3110773)

**["Next Generation SOAR Platform"](https://www.g2.com/survey_responses/d3-security-review-7793810)**

**Rating:** 4.5/5.0 stars

_— Kristian T._

[Read full review](https://www.g2.com/survey_responses/d3-security-review-7793810)

[
IBM Cloud Pak for Security
](https://www.g2.com/products/ibm-cloud-pak-for-security/reviews)

By [IBM](https://www.g2.com/sellers/ibm)

[

4.4/5(10)

](https://www.g2.com/products/ibm-cloud-pak-for-security/reviews)

What do users say?

Users consistently praise the product for its seamless integration with existing technologies and ease of implementation, which enhances security management across various environments. The AI capabil

### [IBM Cloud Pak for Security](https://www.g2.com/products/ibm-cloud-pak-for-security/reviews)

IBM Cloud Pak for Security is a platform that helps you uncover hidden threats, make more informed risk-based decisions and prioritize your team’s time

**Average Rating:** 4.4/5.0

**Total Reviews:** 9

#### How Do G2 Users Rate IBM Cloud Pak for Security?

- **Automated Remediation:** 8.9/10 (Category avg: 8.7/10)
- **Quality of Support:** 9.2/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind IBM Cloud Pak for Security?

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity  
74,660 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=14b544adaece4fdbc987f1d7f7028048c22259946811200cc751263825586af9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1009%2F&secure%5Burl_type%5D=linkedin_company_website)  
328,202 employees on LinkedIn®
- **Ownership:** SWX:IBM

#### Who Uses This Product?

- **Company Size:** 40% Large, 30% Medium

#### What Are Recent G2 Reviews of IBM Cloud Pak for Security?

**["IBM Cloud Pak Review"](https://www.g2.com/survey_responses/ibm-cloud-pak-for-security-review-9765692)**

**Rating:** 4.5/5.0 stars

_— Nitin G._

[Read full review](https://www.g2.com/survey_responses/ibm-cloud-pak-for-security-review-9765692)

**["Flexible cloud pak"](https://www.g2.com/survey_responses/ibm-cloud-pak-for-security-review-9755853)**

**Rating:** 5.0/5.0 stars

_— Anilkumar R._

[Read full review](https://www.g2.com/survey_responses/ibm-cloud-pak-for-security-review-9755853)

#### What Are G2 Users Discussing About IBM Cloud Pak for Security?

- [What are the 6 current cloud Paks offered by IBM?](https://www.g2.com/discussions/ibm-cloud-pak-for-security-what-are-the-6-current-cloud-paks-offered-by-ibm)
- [What are the features of IBM cloud?](https://www.g2.com/discussions/ibm-cloud-pak-for-security-what-are-the-features-of-ibm-cloud)
- [What is IBM Cloud Pak Security?](https://www.g2.com/discussions/what-is-ibm-cloud-pak-security)

[
Microsoft Security Copilot
](https://www.g2.com/products/microsoft-security-copilot/reviews)

By [Microsoft](https://www.g2.com/sellers/microsoft)

[

4.3/5(12)

](https://www.g2.com/products/microsoft-security-copilot/reviews)

What do users say?

Users consistently praise the AI-driven analysis and ease of use of Microsoft Security Copilot, highlighting its ability to quickly identify and respond to threats, which enhances overall security ope

Pros and Cons

[
Ease of Use (7)
](https://www.g2.com/products/microsoft-security-copilot/reviews?qs=pros-and-cons)[
Complexity (3)
](https://www.g2.com/products/microsoft-security-copilot/reviews?qs=pros-and-cons)

### [Microsoft Security Copilot](https://www.g2.com/products/microsoft-security-copilot/reviews)

Empower your defenders to detect hidden patterns, harden defenses, and respond to incidents faster with generative AI

**Average Rating:** 4.3/5.0

**Total Reviews:** 12

#### How Do G2 Users Rate Microsoft Security Copilot?

- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 7.8/10 (Category avg: 8.6/10)

#### Who Is the Company Behind Microsoft Security Copilot?

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 employees on LinkedIn®
- **Ownership:** MSFT

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 75% Large, 17% Medium

#### What Do G2 Reviewers Say About Microsoft Security Copilot?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Microsoft Security Copilot, thanks to its seamless integration and intuitive interface.
- Users value the **AI integration** in Microsoft Security Copilot for its enhanced threat detection and faster incident response.
- Users appreciate the **AI-driven threat detection** of Microsoft Security Copilot, enhancing security team's efficiency in identifying risks.
- Users value the **AI-driven threat detection** of Microsoft Security Copilot, significantly enhancing their security operations efficiency.
- Users value the **automation capabilities** of Microsoft Security Copilot, enhancing incident response and simplifying security management.

##### Cons

- Users find Microsoft Security Copilot's **complexity** challenging, especially for inexperienced team members adapting to AI-based solutions.
- Users feel the product is **expensive** , suggesting a need for more cost-effective options for broader accessibility.
- Users find the **difficult learning curve** of Microsoft Security Copilot challenging, particularly for inexperienced team members.
- Users find that **false positives** often lead to wasted time and necessitate additional verification, complicating their workflow.
- Users criticize the **limited access** to Microsoft Security Copilot, impacting its usability for all users.

#### What Are Recent G2 Reviews of Microsoft Security Copilot?

**["A Critical Analysis of AI in Cybersecurity"](https://www.g2.com/survey_responses/microsoft-security-copilot-review-9887878)**

**Rating:** 4.5/5.0 stars

_— Abhishek N._

[Read full review](https://www.g2.com/survey_responses/microsoft-security-copilot-review-9887878)

**["Co-pilot :A Dictionary of Guidance"](https://www.g2.com/survey_responses/microsoft-security-copilot-review-9999338)**

**Rating:** 5.0/5.0 stars

_— Viswanadh Gupta T._

[Read full review](https://www.g2.com/survey_responses/microsoft-security-copilot-review-9999338)

[
NetWitness Platform
](https://www.g2.com/products/netwitness-platform/reviews)

By [NetWitness](https://www.g2.com/sellers/netwitness)

[

3.9/5(24)

](https://www.g2.com/products/netwitness-platform/reviews)

What do users say?

Users consistently praise the platform for its powerful threat detection and ease of use, making it a valuable tool for security teams. The ability to capture full network packets enhances forensic in

Pros and Cons

[
Centralized Management (1)
](https://www.g2.com/products/netwitness-platform/reviews?qs=pros-and-cons)[
Complex Implementation (2)
](https://www.g2.com/products/netwitness-platform/reviews?qs=pros-and-cons)

### [NetWitness Platform](https://www.g2.com/products/netwitness-platform/reviews)

NetWitness is a comprehensive threat detection, investigation and response platform that combines visibility, analytics, insight, and automation into a single solution. It collects and analyzes data across all capture points (logs, packets, netflow, endpoint and IoT) and computing platforms (physical, virtual and cloud), enriching data with threat intelligence and business context.

**Average Rating:** 3.9/5.0

**Total Reviews:** 23

#### How Do G2 Users Rate NetWitness Platform?

- **Automated Remediation:** 9.2/10 (Category avg: 8.7/10)
- **Quality of Support:** 7.6/10 (Category avg: 9.0/10)
- **Ease of Admin:** 7.4/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind NetWitness Platform?

- **Seller:** [NetWitness](https://www.g2.com/sellers/netwitness)
- **Year Founded:** 1997
- **HQ Location:** Bedford, MA
- **Twitter:** @Netwitness  
1,621 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8ae249a18b34c6a0f632d7c0953c6bcf05c3692f1f32add16a5d89d58de98cdb&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnetwitness-platform%2F&secure%5Burl_type%5D=linkedin_company_website)  
194 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 54% Large, 33% Medium

#### What Do G2 Reviewers Say About NetWitness Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **centralized management** of NetWitness Platform for its comprehensive threat hunting capabilities across various data sources.
- Users appreciate the **converged capabilities** of NetWitness Platform, which streamline threat hunting and reduce tool sprawl.
- Users appreciate the **packet capture and replay capabilities** of NetWitness Platform, essential for thorough forensic investigations.
- Users appreciate the **ability to capture full network packets** , enhancing their deep forensic investigation capabilities.
- Users value the **centralized view** offered by the Management Console, enhancing efficiency in threat hunting across diverse environments.

##### Cons

- Users find the **complex implementation** of NetWitness Platform challenging, needing significant technical expertise for deployment and upgrades.
- Users find the **initial deployment and upgrades complicated** , often necessitating significant technical expertise and leading to instability.
- Users find the **initial setup complex** , often needing extensive technical expertise, and face challenges during upgrades.
- Users find the **deployment difficulties** of NetWitness Platform challenging, needing extensive expertise and facing upgrade instability.
- Users find the **expertise required** for initial deployment and upgrades complicates their experience with NetWitness Platform.

#### What Are Recent G2 Reviews of NetWitness Platform?

**["All-in-One Security Console for Centralized Threat Hunting"](https://www.g2.com/survey_responses/netwitness-platform-review-12381089)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Services_

[Read full review](https://www.g2.com/survey_responses/netwitness-platform-review-12381089)

**["A Powerhouse in Endpoint, Network, and SIEM Integration."](https://www.g2.com/survey_responses/netwitness-platform-review-11524038)**

**Rating:** 4.0/5.0 stars

_— pushpendra Y._

[Read full review](https://www.g2.com/survey_responses/netwitness-platform-review-11524038)

#### What Are G2 Users Discussing About NetWitness Platform?

- [What is one of the biggest differentiators for RSA NetWitness platform?](https://www.g2.com/discussions/what-is-one-of-the-biggest-differentiators-for-rsa-netwitness-platform)
- [What types of data can the RSA NetWitness platform capture and process?](https://www.g2.com/discussions/what-types-of-data-can-the-rsa-netwitness-platform-capture-and-process)
- [What is NetWitness used for?](https://www.g2.com/discussions/what-is-netwitness-used-for) - 1 comment
- [What does RSA NetWitness do?](https://www.g2.com/discussions/what-does-rsa-netwitness-do)

[
Exaforce
](https://www.g2.com/products/exaforce/reviews)

By [Exaforce](https://www.g2.com/sellers/exaforce)

[

4.9/5(7)

](https://www.g2.com/products/exaforce/reviews)

Product Description

At Exaforce, we are on a mission to 10x the productivity and efficacy of security and operations (SOC) teams using our transformative multi-model AI engine. Our Agentic SOC Platform combines AI agents

Pros and Cons

[
Security (3)
](https://www.g2.com/products/exaforce/reviews?qs=pros-and-cons)[
Query Issues (1)
](https://www.g2.com/products/exaforce/reviews?qs=pros-and-cons)

### [Exaforce](https://www.g2.com/products/exaforce/reviews)

At Exaforce, we are on a mission to 10x the productivity and efficacy of security and operations (SOC) teams using our transformative multi-model AI engine. Our Agentic SOC Platform combines AI agents (“Exabots”) with advanced data exploration to deliver real-time insights, proactive detection and response, in-depth investigations, and automated workflows. Backed by Khosla Ventures, Mayfield, Thomvest Ventures, Touring Capital, and others, Exaforce helps SOC teams respond to threats and breaches faster, with higher precision, greater consistency, and at lower total costs—redefining how SOC teams function.

**Average Rating:** 4.9/5.0

**Total Reviews:** 7

#### How Do G2 Users Rate Exaforce?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Exaforce?

- **Seller:** [Exaforce](https://www.g2.com/sellers/exaforce)
- **Company Website:** www.exaforce.com
- **Year Founded:** 2023
- **HQ Location:** San Jose, CA
- **Twitter:** @exaforceAI  
134 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=09afbe185279bc9b565f62d7bd1c9d8ad795028abe0fa32e510551d96142d3b8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fexaforce&secure%5Burl_type%5D=linkedin_company_website)  
60 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 57% Medium, 29% Large

#### What Do G2 Reviewers Say About Exaforce?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **enhanced security operations** of Exaforce, combining AI and human review for effective incident management.
- Users commend Exaforce's **fantastic customer support** , appreciating their responsiveness and assistance with feature requests.
- Users value the **effective alerting system** of Exaforce, enhancing focus and streamlining investigation processes significantly.
- Users praise Exaforce for its **fantastic customer support** , which greatly enhances troubleshooting and feature request processes.
- Users value the **ease of use** of Exaforce, significantly enhancing their workflow efficiency and focus on critical findings.

##### Cons

- Users experience **query issues** with Exaforce, including slow loading times and failures with complex datasets.
- Users experience **slow performance** with Exaforce, especially when loading complex queries and large datasets.
- Users often experience **slow interface loading** and issues with large datasets affecting usability and performance.

#### What Are Recent G2 Reviews of Exaforce?

**["Exaforce Cuts Security Alert Noise and Speeds Up Remediation"](https://www.g2.com/survey_responses/exaforce-review-12644503)**

**Rating:** 5.0/5.0 stars

_— Monde H._

[Read full review](https://www.g2.com/survey_responses/exaforce-review-12644503)

**["Collaborative, AI-Powered Security Operations"](https://www.g2.com/survey_responses/exaforce-review-12407665)**

**Rating:** 5.0/5.0 stars

_— Patrick M._

[Read full review](https://www.g2.com/survey_responses/exaforce-review-12407665)

- [&lsaquo; Prev‹ Prev](/categories/security-orchestration-automation-and-response-soar?order=g2_score#product-list)
- [1](/categories/security-orchestration-automation-and-response-soar?order=g2_score#product-list)
- 2
- [3](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=3#product-list)
- [4](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=4#product-list)
- [5](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=5#product-list)
- [6](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=6#product-list)
- [Next &rsaquo;Next ›](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=3#product-list)

Spotlight Categories

[SAP Store Software](https://www.g2.com/categories/sap-store)

[E-Signature Software](https://www.g2.com/categories/e-signature)

[Inbound Call Tracking Software](https://www.g2.com/categories/inbound-call-tracking)

[Compensation Management Software](https://www.g2.com/categories/compensation-management)

[Employee Intranet Software](https://www.g2.com/categories/employee-intranet)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)

- [Deception Technology](/categories/deception-technology)
- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)

- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)
- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)

[Browse Security Orchestration, Automation, and Response (SOAR) Themes](/categories/security-orchestration-automation-and-response-soar/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Security orchestration, automation, and response (SOAR) software products are tools used to help integrate security technologies and automate incident-related tasks. These tools integrate with a company’s existing security solutions to help users build and automate workflows, simplifying the incident response process and reducing the amount of human intervention necessary to handle security incidents. Companies use these tools to create a centralized system complete with visibility into a company’s security software and operational processes. These tools also reduce the time it takes to respond to incidents, as well as the potential for human error in remediating security threats and vulnerabilities.

SOAR platforms combine aspects of [vulnerability management](https://www.g2.com/categories/vulnerability-management), [incident response](https://www.g2.com/categories/incident-response), and [security information and event management (SIEM)](https://www.g2.com/categories/security-information-and-event-management-siem) solutions. SOAR products are designed to provide some of each tool’s respective functionality or integrate with third-party tools. Once integrated, processes can be designed to identify incidents and automate remediation tasks.

To qualify for inclusion in the Security Orchestration, Automation, and Response (SOAR) category, a product must:

- Integrate security information and incident response tools
- Allow security professionals to build response workflows
- Automate incident management and response tasks within workflows
- Provide formalized incident, workflow, and performance reports

Show More

* * *

## How Do You Choose the Right Security Orchestration, Automation, and Response (SOAR) Software?

### What You Should Know About Security, Orchestration, Automation, and Response (SOAR) Software

### What is Security, Orchestration, Automation, and Response (SOAR) Software?

Security orchestration, automation, and response (SOAR) software helps coordinate, execute, and automate tasks between various IT workers and tools. SOAR tools allow organizations to respond quickly to cybersecurity attacks and observe, understand, and prevent future incidents.

SOAR software gives organizations a comprehensive view of their existing security systems while centralizing the security data. By automating security responses and reducing manual tasks, SOAR helps to generate a faster and more accurate response to security attacks. It also helps better coordinate and route incident response to the most appropriate IT worker in real time.

**What Does SOAR Stand For?**

SOAR stands for security orchestration, automation, and response. SOAR software significantly contributes to identifying potential future security threats.

### What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?

Usually, a SOAR software offering operates under three primary software capabilities:

**Threat and vulnerability management:** Threat and vulnerability management examines key assets and prioritizes efforts to reduce risk. Working with other security teams, threat and vulnerability management helps prevent attacks by threat actors.

**Security incident response:** Security incident response addresses and manages the aftermath of a security breach, cyberattack, computer incident, or security incident. Security incident response is to handle the aftermath of a security breach in a way that limits damage, reduces recovery time, and reduces cost.

**Security operations automation:** Security operations automation is the technology that enables the automation and orchestration of security tasks. This can include both administrative duties and incident detection and response.

### What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?

The benefits of using a SOAR tool are that it lessens the impact of security incidents and reduces the risk of legal liability. SOAR software helps companies’ security teams by enabling them to:

**Maintain a central view:** One of the benefits of SOAR software is that it gives security staff a central view and enables control of existing security systems while centralizing data collection to improve a company's security posture, operational efficiency, and productivity.&nbsp;

**Automate manual tasks:** As with most software today, users are looking for help in terms of automation. SOAR software helps to manage and automate all aspects of a security incident lifecycle. This removes manual tasks, gives security staff more time to be productive, and allows them to focus on more mission-critical security tasks that do not require manual tasks.

**Define incident and response procedures:** SOAR software helps security systems define incident and response procedures. This helps to route security incidents to the correct security staff. SOAR can also prioritize and standardize the security response processes in a consistent, transparent, and documented way.&nbsp;

**Optimize incident response** : Because SOAR software helps security staff define incident and response procedures, incident response is more accurate. This accuracy enables security systems and staff to have improved responses where they may have to contain, eradicate, or recover crucial data.&nbsp;

**Identify and assign incident severity levels:** SOAR software helps to identify and assign incident severity levels. Severity levels in cybersecurity measure how severely a security incident impacts various parts of the organization. SOAR software automatically identifies and assigns severity levels, enabling the right security system and staff to respond appropriately. This means both can respond immediately to security incidents that may negatively affect an organization, such as networks, software, employee or customer data, etc.

**Support collaboration and unstructured investigations:** SOAR software supports collaboration and unstructured investigations in real time, helping route each security incident to the security system and security staff best suited to respond. Collaboration with other IT teams for tasks such as remediation or other departments such as legal is possible.&nbsp;

**Streamline operations:** By using SOAR software, organizations can streamline security operations for threat and vulnerability management, security incident response, and security operations automation. SOAR software connects these security elements while integrating disparate security systems. SOAR software’s playbooks allow users to orchestrate, streamline and automate tasks. Playbooks also codify the process workflows that streamline the SOAR software functions.

### Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?

**IT and cybersecurity staff:** They use SOAR software to handle security alerts such as phishing, which includes looking for threat feed data from endpoints, failed user logins, logins from unusual locations, malicious VPN access attempts, and so on. It's also used to hunt for threats and respond to incidents from attached files for malware analysis, cloud-aware incident response, and automate data enrichment. Cybersecurity staff who assign incident severity and check other products for vulnerability scores also use SOAR platforms.

### Challenges with Security, Orchestration, Automation, and Response (SOAR) software

There are a number of challenges with SOAR software that IT teams can encounter.

**Skill gaps:** While there is the misconception that SOAR software could replace security staff, the tool is meant to augment security teams, allowing them to work efficiently and effectively but not replacing them. However, there still may be a skills gap as the security team must be able to create detailed workflows of their processes.

**Effective deployment:** Another challenge of SOAR software is that it must be deployed to the enterprise but also connected to the other applications and technologies, which can be very complicated. An organization must also have staff with enough skills to deploy and maintain the platform. The applications and technologies used by the enterprise must also be able to support or be integrated into the SOAR software. One of SOAR software’s greatest strengths is to connect and orchestrate other technologies; however, if each technology is unable to be integrated, it hampers the benefits of deploying SOAR software.

### How to Buy Security, Orchestration, Automation, and Response Software

#### Requirements Gathering (RFI/RFP) for Security, Orchestration, Automation, and Response (SOAR) Software

If an organization is just starting out and looking to purchase SOAR software, g2.com can help select the best one.

Most business pain points might be related to all of the manual work that must be completed. If the company is large and has a lot of networks, data, or devices in its organization, they may need to shop for a SOAR software that can grow with its organization. Users should think about the pain points in security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use the SOAR software and if they currently have the skills to administer it.&nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The checklist serves as a detailed guide that includes both necessary and nice-to-have features, including budget, features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the scope of the deployment, it might be helpful to produce an RFI, a one-page list with a few bullet points describing what is needed from SOAR software.

#### Compare Security, Orchestration, Automation, and Response (SOAR) Software

**Create a long list**

Vendor evaluations are an essential part of the software buying process from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow down the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list in hand, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure the comparison is comprehensive, the user should demo each solution on the shortlist with the same use cases. This will allow the business to evaluate like for like and see how each vendor stacks up against the competition.&nbsp;

#### Selection of Security, Orchestration, Automation, and Response (SOAR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the entire process, from identifying pain points to implementation, is crucial. The software selection team should consist of organization members with the right interest, skills, and time to participate in this process. A good starting point is to aim for three to five people who fill roles such as the main decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. In smaller companies, the vendor selection team may be smaller, with fewer participants multitasking and taking on more responsibilities.

**Compare notes**

The selection team should compare notes and facts and figures which they noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it's final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and well received, the buyer can be confident that the selection was correct. If not, it might be time to go back to the drawing board.

### What does Security, Orchestration, Automation, and Response (SOAR) Software cost?

SOAR is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization's specific requirements. Once a SOAR solution is purchased, deployed, and integrated into an organization’s security system, the cost could be high, which is why the evaluation stage of selecting SOAR software is so crucial. The notion of rip-and-replace cost can be high. The SOAR vendor chosen should continue to provide support for the SOAR solution with flexibility and open integration.

#### Return on Investment (ROI)

Organizations decide to purchase SOAR software with some type of return on investment (ROI). As they want to recoup the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency.

SOAR software saves security staff costs by eliminating manual tasks. For example, SOAR software automatically investigates the scenario of email phishing attacks which is very common, so this task can be very repetitive and consumes security staff time if it is done manually. A large enterprise used actual data from its SOAR software deployment and compared it to the cost of handling email phishing investigations automatically using SOAR software versus handling them manually. The enterprise found that the reduction in staff time required to handle phishing emails equated to savings of over $680,000 per year.

### Security, Orchestration, Automation, and Response (SOAR) Software Trends

**Enterprises:** Due to the requirements to maintain such large-scale IT and network infrastructure, organizations such as large enterprises tend to be more interested in purchasing SOAR software. Having such large networks and more complex IT makes such organizations more vulnerable to security threats which is another drive to purchase SOAR software. Also, larger organizations have more employees with more devices, which increases threats if they are accessing workplace applications on these devices.

**Retail and e-commerce:** These industries have increased interest in SOAR software due to the vulnerabilities in PoS)transactions and online purchases. It is the processing of these monetary transactions which creates a security risk, especially there personal and financial information of customers. Adopting technologies such as location-based marketing for these types of purchases also makes the retail industry more vulnerable to security threats.