# Best Security Orchestration, Automation, and Response (SOAR) Software - Page 3

## How Many Security Orchestration, Automation, and Response (SOAR) Software Products Does G2 Track?

**Total Products under this Category:** 81

### Category Stats (Jul 2026)

- **Average Rating:** 4.53/5 (↑0.02 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+23.8%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: July 27, 2026_

## How Does G2 Rank Security Orchestration, Automation, and Response (SOAR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,500+ Authentic Reviews
- 81+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software
 ![G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.png?focus%5B%5D=98376&focus%5B%5D=120746&focus%5B%5D=139264&focus%5B%5D=164907&focus%5B%5D=30500&focus%5B%5D=55254&focus%5B%5D=122123&focus%5B%5D=58203)

Highlighted products: Tines, n8n, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, Google Security Operations, ServiceNow Security Operations, Microsoft Sentinel, and Check Point Infinity Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.json?focus%5B%5D=tines&focus%5B%5D=n8n&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=google-security-operations&focus%5B%5D=servicenow-security-operations&focus%5B%5D=microsoft-sentinel&focus%5B%5D=check-point-infinity-platform)

**Sponsored**

### Datadog

Datadog is the monitoring, security and analytics platform for developers, IT operations teams, security engineers and business users in the cloud age. The SaaS platform integrates and automates infrastructure monitoring, application performance monitoring and log management to provide unified, real-time observability of our customers' entire technology stack. Datadog is used by organizations of all sizes and across a wide range of industries to enable digital transformation and cloud migration, drive collaboration among development, operations, security and business teams, accelerate time to market for applications, reduce time to problem resolution, secure applications and infrastructure, understand user behavior and track key business metrics.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=2178&secure%5Bchosen_at%5D=2026-07-29T19%3A35%3A42Z&secure%5Bdisplayable_resource_id%5D=1081&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1081&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=3824&secure%5Bresource_id%5D=2178&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-orchestration-automation-and-response-soar%3Fpage%3D3&secure%5Btoken%5D=6a3e950c86d8cc51b6b8911b35869106df5c113a52e97b613e17d609827b599e&secure%5Burl%5D=https%3A%2F%2Fwww.datadoghq.com%2Fdg%2Fmonitor%2Ffree-trial-g2%2F%3Futm_source%3Dg2crowd%26utm_medium%3Dreview-site%26utm_campaign%3Ddg-coreplatform-multi-ww-en-g2&secure%5Burl_type%5D=custom_url)

### [Trellix Helix](https://www.g2.com/products/trellix-helix/reviews)

Trellix Helix integrates your security tools and augments them with next-generation security information and event management (SIEM), orchestration, and threat intelligence capabilities to capture the untapped potential of security investments.

**Average Rating:** 4.3/5.0

**Total Reviews:** 11

#### How Do G2 Users Rate Trellix Helix?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Trellix Helix?

- **Seller:** [Trellix](https://www.g2.com/sellers/trellix)
- **Year Founded:** 2004
- **HQ Location:** Plano, TX
- **Twitter:** @Trellix  
241,168 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2a20995935f09ce70fd0458482e13ea06f9d2c9b21705f1247b0f08ca591dcf9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftrellixsecurity%2Fabout%2F&secure%5Burl_type%5D=linkedin_company_website)  
751 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 64% Large, 18% Medium

#### What Do G2 Reviewers Say About Trellix Helix?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **real-time threat detection** capabilities of Trellix Helix, enhancing their security operations with AI-driven insights.
- Users appreciate the **automated response capabilities** of Trellix Helix, enhancing efficiency and threat management seamlessly.
- Users value the **automation capabilities** of Trellix Helix, enhancing real-time response and simplifying threat management.
- Users value the **flexible and scalable architecture** of Trellix Helix, facilitating seamless integration and ease of implementation.
- Users value the **real-time threat detection** and seamless integration capabilities of Trellix Helix for enhanced cybersecurity.

#### What Are Recent G2 Reviews of Trellix Helix?

**["Fireeye Helix "New Generation SIEM""](https://www.g2.com/survey_responses/trellix-helix-review-9347343)**

**Rating:** 4.5/5.0 stars

_— Rahul R._

[Read full review](https://www.g2.com/survey_responses/trellix-helix-review-9347343)

**["An effective Unified SOC !!!"](https://www.g2.com/survey_responses/trellix-helix-review-10283899)**

**Rating:** 5.0/5.0 stars

_— Ankit A._

[Read full review](https://www.g2.com/survey_responses/trellix-helix-review-10283899)

### [DNIF HYPERCLOUD](https://www.g2.com/products/dnif-hypercloud/reviews)

DNIF HYPERCLOUD is a cloud native platform that brings the functionality of SIEM, UEBA and SOAR into a single continuous workflow to solve cybersecurity challenges at scale. DNIF HYPERCLOUD is the flagship SaaS platform from NETMONASTERY that delivers key detection functionality using big data analytics and machine learning. NETMONASTERY aims to deliver a platform that helps customers in ingesting machine data and automatically identify anomalies in these data streams using machine learning and outlier detection algorithms. The objective is to make it easy for untrained engineers and analysts to use the platform and extract benefit reliably and efficiently.

**Average Rating:** 4.2/5.0

**Total Reviews:** 10

#### How Do G2 Users Rate DNIF HYPERCLOUD?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind DNIF HYPERCLOUD?

- **Seller:** [DNIF](https://www.g2.com/sellers/dnif)
- **Year Founded:** 2002
- **HQ Location:** Mountain View, California
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=501077541c686b5bc87176f1fce00136dba26004d42e12a28179da24a1f5b1a3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdnif%2F&secure%5Burl_type%5D=linkedin_company_website)  
59 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 45% Medium, 36% Large

#### What Are Recent G2 Reviews of DNIF HYPERCLOUD?

**["Excellent security system"](https://www.g2.com/survey_responses/dnif-hypercloud-review-6936355)**

**Rating:** 5.0/5.0 stars

_— Yairlyn F._

[Read full review](https://www.g2.com/survey_responses/dnif-hypercloud-review-6936355)

**["Intuitive Cyber Threats Detection Platform."](https://www.g2.com/survey_responses/dnif-hypercloud-review-7014258)**

**Rating:** 4.5/5.0 stars

_— Veronica D._

[Read full review](https://www.g2.com/survey_responses/dnif-hypercloud-review-7014258)

### [Fixure](https://www.g2.com/products/fixure/reviews)

Security tools don’t fail because they miss things. They fail because none of them can explain what to do next. Fixure is the missing intelligence layer above the security stack. We don’t scan, alert, or prioritize findings. We build a system-level model of reality that reconciles conflicting tool opinions and reasons about consequences before action is taken. In a world of thousands of “critical” issues, Fixure explains which decisions actually matter. Not by severity. Not by volume. By understanding impact, blast radius, and outcomes across the entire system. That’s why Fixure isn’t another security platform—it’s the layer that finally makes security decisions make sense.

**Average Rating:** 5.0/5.0

**Total Reviews:** 6

#### Who Is the Company Behind Fixure?

- **Seller:** [Fixure](https://www.g2.com/sellers/fixure)
- **Year Founded:** 2025
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7c8cdbe350fcadf4bd9ef9b134ceb1bad5f82fa3d36d3857f47ae85e65c45da2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ffixure%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Medium, 33% Small

#### What Are Recent G2 Reviews of Fixure?

**["Pioneering Security Solution That Cuts Through Noise"](https://www.g2.com/survey_responses/fixure-review-12601855)**

**Rating:** 5.0/5.0 stars

_— Jessica S._

[Read full review](https://www.g2.com/survey_responses/fixure-review-12601855)

**["Comprehensive Security with Excellent Reporting"](https://www.g2.com/survey_responses/fixure-review-12706950)**

**Rating:** 5.0/5.0 stars

_— Alexis R._

[Read full review](https://www.g2.com/survey_responses/fixure-review-12706950)

### [NOVA AI](https://www.g2.com/products/nova-ai/reviews)

NOVA AI by NMT Security is an AI-native cyber risk management platform unifying external attack surface management, third-party risk management, vulnerability management, cloud security posture, GRC, compliance, and AI governance in one continuously scored view. Full product description: NOVA AI is a unified cyber risk intelligence platform built for security and compliance teams that need one view of risk instead of eight disconnected tools. Most organizations run separate products for external attack surface management, vendor risk assessment, vulnerability management, cloud security posture management, and compliance automation. Each is accurate on its own. None of them talk to each other, and the risk that causes incidents usually sits in the gap between them. NOVA AI closes that gap with the Dynamic Risk Intelligence Model (DRIM), which correlates findings across every domain into a single continuous risk score. An exposed asset, an expired vendor certificate, and a cloud misconfiguration move the same number. Modules: 1. External Attack Surface Management (EASM) and brand risk intelligence, including domain and subdomain discovery, exposed services, dark web credential monitoring, and typosquat detection. 2. Third-Party Cyber Risk Management (TPCRM) with autonomous evidence collection, continuous vendor monitoring, security questionnaire automation, and vendor risk scoring, replacing spreadsheet-based TPRM and manual follow-ups. 3. Vulnerability management with risk-based prioritization. 4. Cloud security posture management (CSPM) across AWS, Azure, and GCP configuration drift. 5. Asset inventory and discovery. 6. GRC and compliance automation across 14 frameworks, including ISO 27001, SOC 2, PCI DSS, NIST CSF, DPDP Act, GDPR, HIPAA, RBI cyber security framework, SEBI CSCRF, and CERT-In directions, with continuous control monitoring and audit-ready evidence. 7. AI governance and responsible AI risk management aligned to ISO 42001 and the NIST AI Risk Management Framework. Who uses it CISOs, security leaders, GRC and compliance teams, IT risk managers, NBFC and financial services, insurance, fintech, healthcare, manufacturing, IT services, and global capability centers. Built for mid-market and enterprise teams that need enterprise-grade coverage without enterprise-grade tool sprawl. Why teams choose NOVA AI One platform instead of five vendors and five contracts. Continuous monitoring rather than point-in-time assessment. Deep regulatory coverage for Indian financial services (RBI, SEBI, CERT-In, DPDP) alongside global frameworks. Cross-domain correlation instead of dashboard integration. ISO 27001 and SOC 2 certified. NVIDIA Inception and MeitY-DSCI NCoE incubated. Recognized at RSAC 2026 (Okta Ventures AI Cybersecurity Buyer Pitch, 2nd of 300+). Every Risk. One Platform.

**Average Rating:** 4.9/5.0

**Total Reviews:** 6

#### How Do G2 Users Rate NOVA AI?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 9.6/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind NOVA AI?

- **Seller:** [NOVA AI by NMT Security](https://www.g2.com/sellers/nova-ai-by-nmt-security)
- **HQ Location:** India
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®
- **Ownership:** Nikunj Mathur
- **Phone:** +91 9517888222

#### Who Uses This Product?

- **Company Size:** 43% Medium, 43% Small

#### What Do G2 Reviewers Say About NOVA AI?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **unique combination of compliance support and real-time security insights** , enhancing brand protection and reassurance.
- Users value the **real-time monitoring** of NOVA, finding it reassuring for security and compliance insights.
- Users value the **real-time security insights** and compliance support provided by NOVA, enhancing their overall security posture.

#### What Are Recent G2 Reviews of NOVA AI?

**["NOVA Unifies Cybersecurity, Risk, and Compliance with Actionable AI Insights"](https://www.g2.com/survey_responses/nova-ai-review-13174409)**

**Rating:** 5.0/5.0 stars

_— Nirmal D._

[Read full review](https://www.g2.com/survey_responses/nova-ai-review-13174409)

**["NMT Security’s NOVA AI Streamlined TPRM and Compliance in One Place"](https://www.g2.com/survey_responses/nova-ai-review-13148178)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/nova-ai-review-13148178)

### [Securonix Security Operations and Analytics Platform](https://www.g2.com/products/securonix-security-operations-and-analytics-platform/reviews)

Securonix is working to radically transform all areas of data security with actionable security intelligence.

**Average Rating:** 4.0/5.0

**Total Reviews:** 14

#### How Do G2 Users Rate Securonix Security Operations and Analytics Platform?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.3/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Securonix Security Operations and Analytics Platform?

- **Seller:** [Securonix](https://www.g2.com/sellers/securonix)
- **Year Founded:** 2008
- **HQ Location:** Addison, US
- **Twitter:** @Securonix  
4,275 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a175a774faa00dbb9e5e2c2d28668c9b7bc21d93ffd9a220702c3e0ffc8c30e1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F759889&secure%5Burl_type%5D=linkedin_company_website)  
667 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 50% Large, 36% Small

#### What Do G2 Reviewers Say About Securonix Security Operations and Analytics Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **efficient alert correlation** of Securonix, making analysis straightforward and minimizing false positives.
- Users value the **automatic correlation of alerts** in Securonix, enhancing analysis and minimizing false positives.
- Users value the **automatically correlated alerts** which enhance analysis and minimize false positives effectively.
- Users value the **pre-correlated alerts** , which enhance analysis, minimize false positives, and simplify alert management.
- Users appreciate the **ease of alert analysis** with Securonix, highlighting its effective correlation and reduced false positives.

##### Cons

- Users find the **complex setup** of Securonix challenging, especially with difficult integration and troubleshooting errors.
- Users struggle with **information deficiency** in Securonix, finding analysis and troubleshooting challenging.
- Users find the **insufficient detail** in Securonix limits their analysis and complicates troubleshooting integration errors.
- Users face **integration challenges** with Securonix, complicating analysis and troubleshooting processes significantly.
- Users find the **limited features** of Securonix hindered their analysis and troubleshooting capabilities.

#### What Are Recent G2 Reviews of Securonix Security Operations and Analytics Platform?

**["Modern SIEM Tool with good features and Support"](https://www.g2.com/survey_responses/securonix-security-operations-and-analytics-platform-review-9514109)**

**Rating:** 5.0/5.0 stars

_— Pritam M._

[Read full review](https://www.g2.com/survey_responses/securonix-security-operations-and-analytics-platform-review-9514109)

**["Correlated Alerts Made Easy, with Fewer False Positives"](https://www.g2.com/survey_responses/securonix-security-operations-and-analytics-platform-review-12366950)**

**Rating:** 5.0/5.0 stars

_— Saikumar M._

[Read full review](https://www.g2.com/survey_responses/securonix-security-operations-and-analytics-platform-review-12366950)

#### What Are G2 Users Discussing About Securonix Security Operations and Analytics Platform?

- [What is Securonix Security Operations and Analytics Platform used for?](https://www.g2.com/discussions/what-is-securonix-security-operations-and-analytics-platform-used-for) - 1 comment, 1 upvote

### [InsightConnect](https://www.g2.com/products/insightconnect/reviews)

Orchestration and automation to accelerate your teams and tools

**Average Rating:** 4.0/5.0

**Total Reviews:** 5

#### How Do G2 Users Rate InsightConnect?

- **Automated Remediation:** 3.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 3.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 2.5/10 (Category avg: 8.6/10)
- **Workflow Automation:** 7.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind InsightConnect?

- **Seller:** [Rapid7](https://www.g2.com/sellers/rapid7)
- **Year Founded:** 2000
- **HQ Location:** Boston, MA
- **Twitter:** @rapid7  
124,405 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=04bdb542ee8372d372b62e305f57e5c7aefbd59efac3d6831f78fcc71f4f819c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F39624%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,274 employees on LinkedIn®
- **Ownership:** NASDAQ:RPD

#### Who Uses This Product?

- **Company Size:** 80% Large, 20% Medium

#### What Are Recent G2 Reviews of InsightConnect?

**["Great Fit for a Large Organization"](https://www.g2.com/survey_responses/insightconnect-review-6544504)**

**Rating:** 4.5/5.0 stars

_— Robert M._

[Read full review](https://www.g2.com/survey_responses/insightconnect-review-6544504)

**["Automation at its best !! Simple And Powerful Automation Platform."](https://www.g2.com/survey_responses/insightconnect-review-6734537)**

**Rating:** 4.5/5.0 stars

_— Aditya M._

[Read full review](https://www.g2.com/survey_responses/insightconnect-review-6734537)

#### What Are G2 Users Discussing About InsightConnect?

- [What is InsightConnect used for?](https://www.g2.com/discussions/what-is-insightconnect-used-for)

### [ReliaQuest GreyMatter](https://www.g2.com/products/reliaquest-greymatter/reviews)

ReliaQuest’s agentic AI security operations platform, GreyMatter, allows security teams to detect threats at the source, contain them in under 5 minutes, and eliminate Tier 1 and Tier 2 work for faster investigation and response. GreyMatter orchestrates 6 agentic AI personas with 200+ agent skills and 400+ AI tools to exponentially scale security operations and help organizations predict what's next.

**Average Rating:** 4.5/5.0

**Total Reviews:** 13

#### How Do G2 Users Rate ReliaQuest GreyMatter?

- **Automated Remediation:** 6.7/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.6/10)
- **Workflow Automation:** 6.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ReliaQuest GreyMatter?

- **Seller:** [ReliaQuest](https://www.g2.com/sellers/reliaquest)
- **Company Website:** www.ReliaQuest.com
- **Year Founded:** 2007
- **HQ Location:** Tampa, Florida, United States
- **Twitter:** @ReliaQuest  
2,577 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b61949df7d95fd596e32ee1ad8978028297e007986220b612658a0662ade858e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freliaquest%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,066 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 38% Medium, 31% Large

#### What Do G2 Reviewers Say About ReliaQuest GreyMatter?

_AI-generated summary from verified user reviews_

##### Pros

- Users applaud the **exceptional visibility** and seamless integration of ReliaQuest GreyMatter across diverse security environments.
- Users value the **centralized management** offered by ReliaQuest GreyMatter, streamlining security operations across multiple systems effectively.
- Users commend the **exceptional customer support** of ReliaQuest GreyMatter, enhancing their overall experience and satisfaction.
- Users find ReliaQuest GreyMatter's **ease of use** invaluable for streamlining security operations and facilitating quick investigations.
- Users value the **seamless integrations** of ReliaQuest GreyMatter, enhancing security operations through unified workflows and capabilities.

##### Cons

- Users experience **slow report loading and clunky UI** on ReliaQuest GreyMatter, noting a need for enhancements, especially on Android.
- Users find the **complexity of configurations** time-consuming, often requiring additional effort to fine-tune automated rules.
- Users experience **inefficient alerts** with delays and duplicates, complicating workflows and requiring additional adjustments to automation rules.
- Users experience a **challenging learning curve** with advanced automation workflows, though support helps alleviate difficulties eventually.
- Users find the **login issues** with the ReliaQuest GreyMatter app clunky, hindering a smooth sign-in experience.

#### What Are Recent G2 Reviews of ReliaQuest GreyMatter?

**["Effective Automation for MSSP with GreyMatter"](https://www.g2.com/survey_responses/reliaquest-greymatter-review-12596289)**

**Rating:** 4.5/5.0 stars

_— Pedro G._

[Read full review](https://www.g2.com/survey_responses/reliaquest-greymatter-review-12596289)

**["Saves Time with Seamless Integrations"](https://www.g2.com/survey_responses/reliaquest-greymatter-review-11947996)**

**Rating:** 4.5/5.0 stars

_— Ben B._

[Read full review](https://www.g2.com/survey_responses/reliaquest-greymatter-review-11947996)

### [FortiSOAR](https://www.g2.com/products/fortisoar/reviews)

FortiSOAR is a comprehensive Security Orchestration, Automation, and Response (SOAR platform designed to enhance the efficiency and effectiveness of security operations centers (SOCs. By centralizing incident management and automating routine analyst tasks, FortiSOAR enables IT and operational technology (OT security teams to swiftly detect, investigate, and respond to cyber threats. The platform integrates seamlessly with a wide array of security tools, offering extensive pre-built playbooks and flexible deployment options to meet diverse organizational needs. Key Features and Functionality: - Centralized Incident Management: Unifies alert triage, enrichment, investigation, collaboration, and response actions across IT and OT environments. - Extensive Integrations: Supports over 500 multi-vendor integrations and provides more than 800 pre-built playbooks to enhance operational efficiency. - AI-Driven Security Operations: Incorporates FortiAI and a machine learning-based recommendation engine to guide and automate analyst activities, including playbook creation and incident prioritization. - Built-In Threat Intelligence: Leverages FortiGuard Labs' global intelligence and public sources to enrich investigations and inform proactive security measures. - No/Low-Code Playbook Creation: Offers a patented design experience with visual drag-and-drop and rapid development modes for efficient playbook creation. - Flexible Deployment Options: Available as SaaS, on-premises, public cloud hosting, or through trusted Managed Security Service Providers (MSSPs, ensuring adaptability to various organizational requirements. Primary Value and Problem Solved: FortiSOAR addresses the challenges faced by security teams overwhelmed with numerous tools, excessive alerts, and manual, repetitive processes that hinder response times. By centralizing, standardizing, and automating security operations, FortiSOAR enforces best practices and allows analysts to focus on critical tasks, thereby improving overall security posture and operational efficiency. Its AI-driven capabilities and extensive integrations enable organizations to respond to threats more rapidly and effectively, reducing mean time to response (MTTR and enhancing productivity.

**Average Rating:** 4.9/5.0

**Total Reviews:** 4

#### How Do G2 Users Rate FortiSOAR?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 7.5/10 (Category avg: 8.6/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind FortiSOAR?

- **Seller:** [Fortinet](https://www.g2.com/sellers/fortinet)
- **Year Founded:** 2000
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @Fortinet  
151,422 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3d5f38bd4746b6501ce1c8f305fccf1b4a457b722a14dc3b74f43b2d5156111e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F6460%2F&secure%5Burl_type%5D=linkedin_company_website)  
16,279 employees on LinkedIn®
- **Ownership:** NASDAQ: FTNT

#### Who Uses This Product?

- **Company Size:** 75% Medium, 25% Small

#### What Do G2 Reviewers Say About FortiSOAR?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **seamless integrations** of FortiSOAR, which enhance their cyber security efforts effectively.
- Users benefit from the **enhanced security** capabilities of FortiSOAR, effectively preventing cyber attacks and integrating with SIEM.

##### Cons

- Users find the **complex coding** in FortiSOAR challenging, impacting their overall usability and experience.

#### What Are Recent G2 Reviews of FortiSOAR?

**["ForiSOAR Review"](https://www.g2.com/survey_responses/fortisoar-review-9841178)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/fortisoar-review-9841178)

**["Modular Soar Solution"](https://www.g2.com/survey_responses/fortisoar-review-8199362)**

**Rating:** 4.5/5.0 stars

_— Esat Yasar C._

[Read full review](https://www.g2.com/survey_responses/fortisoar-review-8199362)

#### What Are G2 Users Discussing About FortiSOAR?

- [What is FortiSOAR used for?](https://www.g2.com/discussions/what-is-fortisoar-used-for)

### [ORNA](https://www.g2.com/products/orna-orna/reviews)

ORNA is an end-to-end incident response automation platform for lean teams in midsize businesses that helps streamline or automate detection, response, and even prevention of cyberattacks on the organization's assets, all in a single tool with live 24/7 specialist support. The platform monitors cloud, on-premises, and hybrid assets (such as servers, network devices, workstations, IoT devices, and more) the organization is looking to protect around the clock, but also brings together overarching cyber incident response across all business functions, such as legal, HR, communications, and others; as well as automates evidence collection, communications, vulnerability management, and more.

**Average Rating:** 4.7/5.0

**Total Reviews:** 7

#### How Do G2 Users Rate ORNA?

- **Automated Remediation:** 6.7/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 6.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ORNA?

- **Seller:** [ORNA](https://www.g2.com/sellers/orna)
- **Year Founded:** 2021
- **HQ Location:** Toronto, CA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4f609b13b841373c3d09fd154790d6a7b1953e2324713d5b73251e42248d7efc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Forna-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
42 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 71% Small, 14% Large

#### What Do G2 Reviewers Say About ORNA?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of automation** in ORNA, enhancing efficiency through streamlined incident response processes.
- Users value the **helpful customer support** from ORNA, ensuring efficient solutions and responsive feedback.
- Users commend ORNA for its **high detection accuracy** , ensuring effective monitoring and incident management across platforms.
- Users highlight the **ease of use** in ORNA for tagging and managing devices efficiently.
- Users commend the **helpful support team** and appreciate their openness to feedback and suggestions.

#### What Are Recent G2 Reviews of ORNA?

**["ORNA Cyber Incident Response Platform"](https://www.g2.com/survey_responses/orna-review-10406528)**

**Rating:** 4.5/5.0 stars

_— Robert M._

[Read full review](https://www.g2.com/survey_responses/orna-review-10406528)

**["User interface is Perfect"](https://www.g2.com/survey_responses/orna-review-10827471)**

**Rating:** 4.5/5.0 stars

_— Laia G._

[Read full review](https://www.g2.com/survey_responses/orna-review-10827471)

### [autobotAI](https://www.g2.com/products/autobotai/reviews)

autobotAI is a agentic security automation platform that streamlines and secures Security and IT operations. Leveraging generative AI, it automates workflows across multi-cloud environments, integrating seamlessly with security and observability tools, and enhancing operational efficiency with no-code, low-code, and full-code flexibility.

**Average Rating:** 5.0/5.0

**Total Reviews:** 3

#### How Do G2 Users Rate autobotAI?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Workflow Automation:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind autobotAI?

- **Seller:** [FusionGate](https://www.g2.com/sellers/fusiongate)
- **Year Founded:** 2018
- **HQ Location:** Bengaluru South, IN
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=69e38548e6fdfa4d282831bdea1310adfb056162ca0d5a81536485946be5598c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fshunyeka&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Small, 33% Medium

#### What Do G2 Reviewers Say About autobotAI?

_AI-generated summary from verified user reviews_

##### Pros

- Users love the **no-code automation** capabilities of autobotAI, significantly streamlining tasks and enhancing efficiency in ITOps.
- Users appreciate the **automation ease** offered by autobotAI, making workflow creation intuitive and efficient.
- Users praise the **excellent customer support** of autobotAI, noting their technical expertise and helpfulness in resolving issues.
- Users appreciate the **extensive integrations** of autobotAI, facilitating seamless automation across diverse platforms and tools.
- Users appreciate the **integration support** of autobotAI, streamlining automation and enhancing ITOps workflows effectively.

##### Cons

- Users feel the **insight feature lacks filter options** , which limits its effectiveness in monitoring compliance posture.
- Users note **slow performance** with NoCode node, but anticipate improvements in the next software release.

#### What Are Recent G2 Reviews of autobotAI?

**["Automated vulnerability Patching with Generative AI"](https://www.g2.com/survey_responses/autobotai-review-11101484)**

**Rating:** 5.0/5.0 stars

_— Anmol J._

[Read full review](https://www.g2.com/survey_responses/autobotai-review-11101484)

**["Agentic Workflows and MCP, it's a robust platform for automating DevOps, CloudOps, and SecOps"](https://www.g2.com/survey_responses/autobotai-review-11101411)**

**Rating:** 5.0/5.0 stars

_— Satish S._

[Read full review](https://www.g2.com/survey_responses/autobotai-review-11101411)

### [DTonomy](https://www.g2.com/products/dtonomy/reviews)

DTonomy’s AI Assisted Incident Response (AIR) platform manages alerts from multiple security tools and infrastructure and automates manual time-consuming and repetitive tasks. AIR is powered by DTonomy’s adaptive learning engine which continuously learns and provides contextual insights that are not easily discoverable. The platform uses the insights to make relevant recommendations and automated workflows to guide security teams through steps and procedures. DTonomy’s AIR platform resolves incidents up to 10 times quick which leads to decreased downtime and reduced alert fatigue for staff.

**Average Rating:** 5.0/5.0

**Total Reviews:** 3

#### How Do G2 Users Rate DTonomy?

- **Automated Remediation:** 9.4/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 6.7/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind DTonomy?

- **Seller:** [DTonomy](https://www.g2.com/sellers/dtonomy)
- **Year Founded:** 2018
- **HQ Location:** Cambridge, US
- **Twitter:** @Peter\_DTonomy  
328 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ef69f88d9e127cce87bf1331af0a3ea3ef53663a8318060078018adaa47e83b7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdtonomy%2F&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Are Recent G2 Reviews of DTonomy?

**["A more efficent approach to SOAR"](https://www.g2.com/survey_responses/dtonomy-review-9101067)**

**Rating:** 5.0/5.0 stars

_— Verified User in Legal Services_

[Read full review](https://www.g2.com/survey_responses/dtonomy-review-9101067)

**["Flexible automation environment that keeps getting better"](https://www.g2.com/survey_responses/dtonomy-review-4381414)**

**Rating:** 5.0/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/dtonomy-review-4381414)

#### What Are G2 Users Discussing About DTonomy?

- [What is DTonomy used for?](https://www.g2.com/discussions/what-is-dtonomy-used-for)

### [Security Orchestration, Automation & Response](https://www.g2.com/products/security-orchestration-automation-response/reviews)

A universal, security orchestration gateway for executing on-demand or event-triggered tasks across deployment environments at machine speeds.

**Average Rating:** 4.3/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate Security Orchestration, Automation & Response?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.3/10 (Category avg: 9.0/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Security Orchestration, Automation & Response?

- **Seller:** [Cyware](https://www.g2.com/sellers/cyware)
- **Year Founded:** 2016
- **HQ Location:** Jersey City, New Jersey, United States
- **Twitter:** @CywareCo  
4,468 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=07ffe4563c9fb850b3b2cb5e73dc6d368a33eb1e8b43283b0ce795c171150ee3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcyware%2F&secure%5Burl_type%5D=linkedin_company_website)  
253 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of Security Orchestration, Automation & Response?

**["As SOAR used for both SIEM and CTIX"](https://www.g2.com/survey_responses/security-orchestration-automation-response-review-8912000)**

**Rating:** 5.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/security-orchestration-automation-response-review-8912000)

### [Singularity AI SIEM](https://www.g2.com/products/singularity-ai-siem/reviews)

Secure your entire organization with the industry's fastest AI-powered open platform for all your data and workflows—built on the SentinelOne Singularity™ Data Lake. Singularity AI SIEM is designed for the autonomous SOC, empowering your security operations center to operate at peak efficiency. By leveraging AI and automation, our SIEM solution enables you to: Detect and respond to threats faster Improve overall security posture Reduce false positives and noise Allocate resources more effectively

**Average Rating:** 4.3/5.0

**Total Reviews:** 3

#### How Do G2 Users Rate Singularity AI SIEM?

- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.6/10)

#### Who Is the Company Behind Singularity AI SIEM?

- **Seller:** [SentinelOne](https://www.g2.com/sellers/sentinelone)
- **Company Website:** www.sentinelone.com
- **Year Founded:** 2013
- **HQ Location:** Mountain View, CA
- **Twitter:** @SentinelOne  
57,863 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=74020d53a476ae0e483a0d2613eaf520ba6aa350af89839fdb2bae462d053ed2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2886771%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,174 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Medium, 40% Small

#### What Do G2 Reviewers Say About Singularity AI SIEM?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **advanced AI-powered capabilities** of Singularity AI SIEM, enhancing threat detection and response efficiency.
- Users commend the **attentive customer support** of Singularity AI SIEM, enhancing their overall experience and satisfaction.
- Users commend the **high detection accuracy** of Singularity AI SIEM, enabling rapid and effective threat response.
- Users value the **user-friendly interface** of Singularity AI SIEM, which enhances efficiency for all security team members.
- Users value the **efficiency** of Singularity AI SIEM, enabling rapid identification and resolution of security threats.

##### Cons

- Users struggle with the **complexity of initial setup** for Singularity AI SIEM, finding it challenging to implement effectively.
- Users report a **complex setup** process for Singularity AI SIEM, which can hinder initial implementation and use.
- Users express concern over the **high cost** of Singularity AI SIEM, making it less accessible for some organizations.
- Users express concerns about the **high cost and complex setup** of Singularity AI SIEM, impacting user experience.
- Users note the **limited features** of Singularity AI SIEM, which affects its competitiveness against established platforms.

#### What Are Recent G2 Reviews of Singularity AI SIEM?

**["Singularity AI SIEM Cuts Noise Fast"](https://www.g2.com/survey_responses/singularity-ai-siem-review-13156075)**

**Rating:** 5.0/5.0 stars

_— Adaku O._

[Read full review](https://www.g2.com/survey_responses/singularity-ai-siem-review-13156075)

**["Unified Visibility and AI-Assisted Investigations That Speed Up Response"](https://www.g2.com/survey_responses/singularity-ai-siem-review-13182802)**

**Rating:** 4.0/5.0 stars

_— Elizabeth E._

[Read full review](https://www.g2.com/survey_responses/singularity-ai-siem-review-13182802)

### [Devo](https://www.g2.com/products/devo/reviews)

Devo unlocks the full value of machine data for the world’s most instrumented enterprises by putting more data to work now. With Devo, IT executives finally realize the transformational promise of machine data to drive breakthrough projects that move the entire business forward. Born for today’s fully instrumented world, the Devo platform is purpose-built for both the sheer volume of data generated today, and the crushing demands of automation and the millions of algorithms that need to consume machine data. Our unique No-Compromise Architecture frees IT from the painful constraints of existing enterprise log management (ELM) systems, ingesting petabytes daily with blistering speed with no re-architecting required, even as data volumes explode. All machine data is unified, hot, and ready to use across multiple teams and use cases, from the moment of ingestion, for as long as you want to retain it – no limits. Only Devo combines real-time streams with historical data for fully contextual analytics, delivering 10x faster response times for tens of thousands of simultaneous queries. Devo powers the world’s most instrumented enterprises – Telefonica, Caixa Bank, Panda Security and 1000+ more worldwide – all realizing game-changing economics and compounding value from their machine data. Visit www.devo.com to learn more.

**Average Rating:** 4.3/5.0

**Total Reviews:** 5

#### How Do G2 Users Rate Devo?

- **Quality of Support:** 8.3/10 (Category avg: 9.0/10)

#### Who Is the Company Behind Devo?

- **Seller:** [Devo](https://www.g2.com/sellers/devo)
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts, United States
- **Twitter:** @devo\_Inc  
6,147 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5801f634973872dff7a9708ae43ddc89b374797ccb8c5431f32ae50aded4e924&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdevoinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
614 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Small, 40% Medium

#### What Are Recent G2 Reviews of Devo?

**["This is a great log management application, thats very helpfull for me in this busy world,"](https://www.g2.com/survey_responses/devo-review-5403587)**

**Rating:** 4.0/5.0 stars

_— Bibin A._

[Read full review](https://www.g2.com/survey_responses/devo-review-5403587)

**["Devo review"](https://www.g2.com/survey_responses/devo-review-6576255)**

**Rating:** 5.0/5.0 stars

_— SAJID S._

[Read full review](https://www.g2.com/survey_responses/devo-review-6576255)

#### What Are G2 Users Discussing About Devo?

- [What is Devo used for?](https://www.g2.com/discussions/what-is-devo-used-for)

### [Evolve Security Automation](https://www.g2.com/products/evolve-security-automation/reviews)

Evolve Security Automation is a modern approach to maximize your security budgets to achieve on-demand security capabilities with flexible pay-as-you-go pricing models. Automate your penetration testing and incident response, monitor for compromised accounts across thousands of security breaches, and orchestrate security infrastructure with automated cyber threat intelligence integration.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Evolve Security Automation?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Evolve Security Automation?

- **Seller:** [Threat Intelligence](https://www.g2.com/sellers/threat-intelligence)
- **HQ Location:** Sydney, AU
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f75342c4c614195a517507439de566765d9a0565bb089ee2bf6068ab0e8441dc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fthreat-intelligence-pty-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
23 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of Evolve Security Automation?

**["Evolve Secure service"](https://www.g2.com/survey_responses/evolve-security-automation-review-8724617)**

**Rating:** 5.0/5.0 stars

_— Vishnu S._

[Read full review](https://www.g2.com/survey_responses/evolve-security-automation-review-8724617)

- [&lsaquo; Prev‹ Prev](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=2#product-list)
- [1](/categories/security-orchestration-automation-and-response-soar?order=g2_score#product-list)
- [2](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=2#product-list)
- 3
- [4](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=4#product-list)
- [5](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=5#product-list)
- [6](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=6#product-list)
- [Next &rsaquo;Next ›](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=4#product-list)

Spotlight Categories

[Live Chat Software](https://www.g2.com/categories/live-chat)

[Event Management Platforms](https://www.g2.com/categories/event-management-platforms)

[Board Management Software](https://www.g2.com/categories/board-management)

[Attribution Software](https://www.g2.com/categories/attribution)

[Sales Performance Management Software](https://www.g2.com/categories/sales-performance-management)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)

- [Deception Technology](/categories/deception-technology)
- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)

- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)
- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)

[Browse Security Orchestration, Automation, and Response (SOAR) Themes](/categories/security-orchestration-automation-and-response-soar/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Security orchestration, automation, and response (SOAR) software products are tools used to help integrate security technologies and automate incident-related tasks. These tools integrate with a company’s existing security solutions to help users build and automate workflows, simplifying the incident response process and reducing the amount of human intervention necessary to handle security incidents. Companies use these tools to create a centralized system complete with visibility into a company’s security software and operational processes. These tools also reduce the time it takes to respond to incidents, as well as the potential for human error in remediating security threats and vulnerabilities.

SOAR platforms combine aspects of [vulnerability management](https://www.g2.com/categories/vulnerability-management), [incident response](https://www.g2.com/categories/incident-response), and [security information and event management (SIEM)](https://www.g2.com/categories/security-information-and-event-management-siem) solutions. SOAR products are designed to provide some of each tool’s respective functionality or integrate with third-party tools. Once integrated, processes can be designed to identify incidents and automate remediation tasks.

To qualify for inclusion in the Security Orchestration, Automation, and Response (SOAR) category, a product must:

- Integrate security information and incident response tools
- Allow security professionals to build response workflows
- Automate incident management and response tasks within workflows
- Provide formalized incident, workflow, and performance reports

Show More

* * *

## How Do You Choose the Right Security Orchestration, Automation, and Response (SOAR) Software?

### What You Should Know About Security, Orchestration, Automation, and Response (SOAR) Software

### What is Security, Orchestration, Automation, and Response (SOAR) Software?

Security orchestration, automation, and response (SOAR) software helps coordinate, execute, and automate tasks between various IT workers and tools. SOAR tools allow organizations to respond quickly to cybersecurity attacks and observe, understand, and prevent future incidents.

SOAR software gives organizations a comprehensive view of their existing security systems while centralizing the security data. By automating security responses and reducing manual tasks, SOAR helps to generate a faster and more accurate response to security attacks. It also helps better coordinate and route incident response to the most appropriate IT worker in real time.

**What Does SOAR Stand For?**

SOAR stands for security orchestration, automation, and response. SOAR software significantly contributes to identifying potential future security threats.

### What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?

Usually, a SOAR software offering operates under three primary software capabilities:

**Threat and vulnerability management:** Threat and vulnerability management examines key assets and prioritizes efforts to reduce risk. Working with other security teams, threat and vulnerability management helps prevent attacks by threat actors.

**Security incident response:** Security incident response addresses and manages the aftermath of a security breach, cyberattack, computer incident, or security incident. Security incident response is to handle the aftermath of a security breach in a way that limits damage, reduces recovery time, and reduces cost.

**Security operations automation:** Security operations automation is the technology that enables the automation and orchestration of security tasks. This can include both administrative duties and incident detection and response.

### What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?

The benefits of using a SOAR tool are that it lessens the impact of security incidents and reduces the risk of legal liability. SOAR software helps companies’ security teams by enabling them to:

**Maintain a central view:** One of the benefits of SOAR software is that it gives security staff a central view and enables control of existing security systems while centralizing data collection to improve a company's security posture, operational efficiency, and productivity.&nbsp;

**Automate manual tasks:** As with most software today, users are looking for help in terms of automation. SOAR software helps to manage and automate all aspects of a security incident lifecycle. This removes manual tasks, gives security staff more time to be productive, and allows them to focus on more mission-critical security tasks that do not require manual tasks.

**Define incident and response procedures:** SOAR software helps security systems define incident and response procedures. This helps to route security incidents to the correct security staff. SOAR can also prioritize and standardize the security response processes in a consistent, transparent, and documented way.&nbsp;

**Optimize incident response** : Because SOAR software helps security staff define incident and response procedures, incident response is more accurate. This accuracy enables security systems and staff to have improved responses where they may have to contain, eradicate, or recover crucial data.&nbsp;

**Identify and assign incident severity levels:** SOAR software helps to identify and assign incident severity levels. Severity levels in cybersecurity measure how severely a security incident impacts various parts of the organization. SOAR software automatically identifies and assigns severity levels, enabling the right security system and staff to respond appropriately. This means both can respond immediately to security incidents that may negatively affect an organization, such as networks, software, employee or customer data, etc.

**Support collaboration and unstructured investigations:** SOAR software supports collaboration and unstructured investigations in real time, helping route each security incident to the security system and security staff best suited to respond. Collaboration with other IT teams for tasks such as remediation or other departments such as legal is possible.&nbsp;

**Streamline operations:** By using SOAR software, organizations can streamline security operations for threat and vulnerability management, security incident response, and security operations automation. SOAR software connects these security elements while integrating disparate security systems. SOAR software’s playbooks allow users to orchestrate, streamline and automate tasks. Playbooks also codify the process workflows that streamline the SOAR software functions.

### Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?

**IT and cybersecurity staff:** They use SOAR software to handle security alerts such as phishing, which includes looking for threat feed data from endpoints, failed user logins, logins from unusual locations, malicious VPN access attempts, and so on. It's also used to hunt for threats and respond to incidents from attached files for malware analysis, cloud-aware incident response, and automate data enrichment. Cybersecurity staff who assign incident severity and check other products for vulnerability scores also use SOAR platforms.

### Challenges with Security, Orchestration, Automation, and Response (SOAR) software

There are a number of challenges with SOAR software that IT teams can encounter.

**Skill gaps:** While there is the misconception that SOAR software could replace security staff, the tool is meant to augment security teams, allowing them to work efficiently and effectively but not replacing them. However, there still may be a skills gap as the security team must be able to create detailed workflows of their processes.

**Effective deployment:** Another challenge of SOAR software is that it must be deployed to the enterprise but also connected to the other applications and technologies, which can be very complicated. An organization must also have staff with enough skills to deploy and maintain the platform. The applications and technologies used by the enterprise must also be able to support or be integrated into the SOAR software. One of SOAR software’s greatest strengths is to connect and orchestrate other technologies; however, if each technology is unable to be integrated, it hampers the benefits of deploying SOAR software.

### How to Buy Security, Orchestration, Automation, and Response Software

#### Requirements Gathering (RFI/RFP) for Security, Orchestration, Automation, and Response (SOAR) Software

If an organization is just starting out and looking to purchase SOAR software, g2.com can help select the best one.

Most business pain points might be related to all of the manual work that must be completed. If the company is large and has a lot of networks, data, or devices in its organization, they may need to shop for a SOAR software that can grow with its organization. Users should think about the pain points in security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use the SOAR software and if they currently have the skills to administer it.&nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The checklist serves as a detailed guide that includes both necessary and nice-to-have features, including budget, features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the scope of the deployment, it might be helpful to produce an RFI, a one-page list with a few bullet points describing what is needed from SOAR software.

#### Compare Security, Orchestration, Automation, and Response (SOAR) Software

**Create a long list**

Vendor evaluations are an essential part of the software buying process from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow down the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list in hand, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure the comparison is comprehensive, the user should demo each solution on the shortlist with the same use cases. This will allow the business to evaluate like for like and see how each vendor stacks up against the competition.&nbsp;

#### Selection of Security, Orchestration, Automation, and Response (SOAR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the entire process, from identifying pain points to implementation, is crucial. The software selection team should consist of organization members with the right interest, skills, and time to participate in this process. A good starting point is to aim for three to five people who fill roles such as the main decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. In smaller companies, the vendor selection team may be smaller, with fewer participants multitasking and taking on more responsibilities.

**Compare notes**

The selection team should compare notes and facts and figures which they noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it's final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and well received, the buyer can be confident that the selection was correct. If not, it might be time to go back to the drawing board.

### What does Security, Orchestration, Automation, and Response (SOAR) Software cost?

SOAR is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization's specific requirements. Once a SOAR solution is purchased, deployed, and integrated into an organization’s security system, the cost could be high, which is why the evaluation stage of selecting SOAR software is so crucial. The notion of rip-and-replace cost can be high. The SOAR vendor chosen should continue to provide support for the SOAR solution with flexibility and open integration.

#### Return on Investment (ROI)

Organizations decide to purchase SOAR software with some type of return on investment (ROI). As they want to recoup the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency.

SOAR software saves security staff costs by eliminating manual tasks. For example, SOAR software automatically investigates the scenario of email phishing attacks which is very common, so this task can be very repetitive and consumes security staff time if it is done manually. A large enterprise used actual data from its SOAR software deployment and compared it to the cost of handling email phishing investigations automatically using SOAR software versus handling them manually. The enterprise found that the reduction in staff time required to handle phishing emails equated to savings of over $680,000 per year.

### Security, Orchestration, Automation, and Response (SOAR) Software Trends

**Enterprises:** Due to the requirements to maintain such large-scale IT and network infrastructure, organizations such as large enterprises tend to be more interested in purchasing SOAR software. Having such large networks and more complex IT makes such organizations more vulnerable to security threats which is another drive to purchase SOAR software. Also, larger organizations have more employees with more devices, which increases threats if they are accessing workplace applications on these devices.

**Retail and e-commerce:** These industries have increased interest in SOAR software due to the vulnerabilities in PoS)transactions and online purchases. It is the processing of these monetary transactions which creates a security risk, especially there personal and financial information of customers. Adopting technologies such as location-based marketing for these types of purchases also makes the retail industry more vulnerable to security threats.