# Best Security Orchestration, Automation, and Response (SOAR) Software - Page 4

## How Many Security Orchestration, Automation, and Response (SOAR) Software Products Does G2 Track?

**Total Products under this Category:** 81

### Category Stats (Jul 2026)

- **Average Rating:** 4.53/5 (↑0.02 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+23.8%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: July 27, 2026_

## How Does G2 Rank Security Orchestration, Automation, and Response (SOAR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,400+ Authentic Reviews
- 81+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software
 ![G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.png?focus%5B%5D=98376&focus%5B%5D=120746&focus%5B%5D=139264&focus%5B%5D=164907&focus%5B%5D=55254&focus%5B%5D=122123&focus%5B%5D=30500&focus%5B%5D=58203)

Highlighted products: Tines, n8n, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, ServiceNow Security Operations, Microsoft Sentinel, Google Security Operations, and Check Point Infinity Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.json?focus%5B%5D=tines&focus%5B%5D=n8n&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=servicenow-security-operations&focus%5B%5D=microsoft-sentinel&focus%5B%5D=google-security-operations&focus%5B%5D=check-point-infinity-platform)

**Sponsored**

### Datadog

Datadog is the monitoring, security and analytics platform for developers, IT operations teams, security engineers and business users in the cloud age. The SaaS platform integrates and automates infrastructure monitoring, application performance monitoring and log management to provide unified, real-time observability of our customers' entire technology stack. Datadog is used by organizations of all sizes and across a wide range of industries to enable digital transformation and cloud migration, drive collaboration among development, operations, security and business teams, accelerate time to market for applications, reduce time to problem resolution, secure applications and infrastructure, understand user behavior and track key business metrics.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=2178&secure%5Bchosen_at%5D=2026-07-29T00%3A11%3A51Z&secure%5Bdisplayable_resource_id%5D=1081&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1081&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=3824&secure%5Bresource_id%5D=2178&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-orchestration-automation-and-response-soar%3Fpage%3D4&secure%5Btoken%5D=f9583b11dc096e6950525a51e3f8c803b23eb66c19986936e77c085933d9ad91&secure%5Burl%5D=https%3A%2F%2Fwww.datadoghq.com%2Fdg%2Fmonitor%2Ffree-trial-g2%2F%3Futm_source%3Dg2crowd%26utm_medium%3Dreview-site%26utm_campaign%3Ddg-coreplatform-multi-ww-en-g2&secure%5Burl_type%5D=custom_url)

[
Forescout Platform
](https://www.g2.com/products/forescout-platform/reviews)

By [Forescout Technologies](https://www.g2.com/sellers/forescout-technologies)

[

4.5/5(17)

](https://www.g2.com/products/forescout-platform/reviews)

What do users say?

Users consistently praise the Forescout Platform for its complete visibility of network devices and effective policy-based controls, which enhance security and compliance. Many appreciate its ability

Pros and Cons

[
Security (4)
](https://www.g2.com/products/forescout-platform/reviews?qs=pros-and-cons)[
Complex Implementation (2)
](https://www.g2.com/products/forescout-platform/reviews?qs=pros-and-cons)

### [Forescout Platform](https://www.g2.com/products/forescout-platform/reviews)

As AI-driven vulnerability and exploitation accelerate attack velocity to machine speed, Forescout is a foundational cyber defense layer that allows organizations to segment and isolate compromised systems, block lateral movement, and automate response across IT, OT, IoT, and IoMT environments. The Forescout Vistaro™ platform, powered by agentic AI and enhanced with Vedere Labs threat intelligence, delivers a Universal Zero Trust Network Access (UZTNA) architecture that integrates seamlessly with 180+ security and IT products. With Forescout Vistaro, organizations get comprehensive inventory and classification of both managed and unmanaged assets, continuous exposure management, and real-time protection including dynamic network segmentation and automated threat response.

**Average Rating:** 4.5/5.0

**Total Reviews:** 16

#### How Do G2 Users Rate Forescout Platform?

- **Quality of Support:** 8.2/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.6/10)

#### Who Is the Company Behind Forescout Platform?

- **Seller:** [Forescout Technologies](https://www.g2.com/sellers/forescout-technologies)
- **Year Founded:** 2000
- **HQ Location:** San Jose, CA
- **Twitter:** @ForeScout  
23,057 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6f1e942ab80d0bedc6197ed48bdc23b36c4e3541aeed93812a834e58f906c458&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fforescout-technologies&secure%5Burl_type%5D=linkedin_company_website)  
1,328 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 53% Large, 29% Medium

#### What Do G2 Reviewers Say About Forescout Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **comprehensive security features** of Forescout Platform, effectively protecting sensitive information and resources.
- Users value the **instant discovery and classification** of endpoints, enhancing network security and resource access.
- Users appreciate the **instant discovery and classification** of IP-based endpoints, enhancing network visibility and security management.
- Users value the **instant discovery and comprehensive visibility** provided by Forescout, enhancing endpoint management across diverse environments.
- Users benefit from the **customization options** in Forescout, enhancing flexibility and control over network security policies.

##### Cons

- Users find the **implementation complex** , facing challenges with integration and inadequate support during the process.
- Users face significant **dependency issues** with Forescout Platform, affecting implementation and integration processes across the system.
- Users face significant **integration issues** with Forescout Platform, complicating implementation and increasing dependency on various systems.
- Users experience significant **performance issues** with Forescout Platform, including slow TAC support and complex implementation processes.
- Users are frustrated by the **poor customer support** from TAC, leading to slow problem resolution and dissatisfaction.

#### What Are Recent G2 Reviews of Forescout Platform?

**["Complete Device Visibility with Powerful Automation and Integrations"](https://www.g2.com/survey_responses/forescout-platform-review-10795997)**

**Rating:** 4.5/5.0 stars

_— Sumit B._

[Read full review](https://www.g2.com/survey_responses/forescout-platform-review-10795997)

**["Flexible Platform That Simplifies Monitoring and Integration with your actual tools"](https://www.g2.com/survey_responses/forescout-platform-review-12806544)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/forescout-platform-review-12806544)

#### What Are G2 Users Discussing About Forescout Platform?

- [What is Forescout Platform used for?](https://www.g2.com/discussions/what-is-forescout-platform-used-for)

[
IBM Cloud Pack for Security
](https://www.g2.com/products/ibm-cloud-pack-for-security/reviews)

By [IBM](https://www.g2.com/sellers/ibm)

[

4/5(1)

](https://www.g2.com/products/ibm-cloud-pack-for-security/reviews)

Product Description

IBM Cloud Pak for Security is a comprehensive, containerized software platform designed to help organizations integrate their existing security tools, providing deeper insights into threats across hyb

### [IBM Cloud Pack for Security](https://www.g2.com/products/ibm-cloud-pack-for-security/reviews)

IBM Cloud Pak for Security is a comprehensive, containerized software platform designed to help organizations integrate their existing security tools, providing deeper insights into threats across hybrid and multicloud environments. Built on Red Hat OpenShift, it enables security teams to detect, investigate, and respond to threats efficiently without the need to move data from its original location. Key Features and Functionality: - Federated Search: Conducts unified searches across diverse data sources, offering a comprehensive view of security environments without relocating data. - Threat Intelligence: Delivers actionable insights by integrating multiple threat intelligence feeds, aiding in the identification and prioritization of potential threats. - Orchestration and Automation: Automates response workflows and orchestrates actions across various security tools, enhancing the efficiency of incident management. - Data Security: Provides visibility into data activity and compliance across hybrid cloud environments, facilitating effective data protection strategies. - Risk Management: Aggregates and contextualizes risk insights from multiple vectors, presenting them in a unified dashboard to prioritize and remediate security risks. Primary Value and Problem Solved: IBM Cloud Pak for Security addresses the complexity of managing disparate security tools and data sources in hybrid and multicloud environments. By providing a unified platform that integrates existing security infrastructure, it enables organizations to uncover hidden threats, make informed risk-based decisions, and respond to incidents more swiftly. This approach not only enhances security posture but also reduces the time and cost associated with data movement and manual processes, allowing security teams to focus on strategic initiatives.

**Average Rating:** 4.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate IBM Cloud Pack for Security?

- **Automated Remediation:** 6.7/10 (Category avg: 8.7/10)
- **Quality of Support:** 5.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 5.0/10 (Category avg: 8.6/10)
- **Workflow Automation:** 6.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind IBM Cloud Pack for Security?

- **Seller:** [IBM](https://www.g2.com/sellers/ibm)
- **Year Founded:** 1911
- **HQ Location:** Armonk, New York, United States
- **Twitter:** @IBMSecurity  
74,660 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=14b544adaece4fdbc987f1d7f7028048c22259946811200cc751263825586af9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1009%2F&secure%5Burl_type%5D=linkedin_company_website)  
328,202 employees on LinkedIn®
- **Ownership:** SWX:IBM

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of IBM Cloud Pack for Security?

**["IBM cloud Pack"](https://www.g2.com/survey_responses/ibm-cloud-pack-for-security-review-9640363)**

**Rating:** 4.0/5.0 stars

_— Siddharth S._

[Read full review](https://www.g2.com/survey_responses/ibm-cloud-pack-for-security-review-9640363)

#### What Are G2 Users Discussing About IBM Cloud Pack for Security?

- [What is IBM Cloud Pack for Security used for?](https://www.g2.com/discussions/what-is-ibm-cloud-pack-for-security-used-for)

[
Radiant
](https://www.g2.com/products/radiant-security-radiant/reviews)

By [Radiant Security](https://www.g2.com/sellers/radiant-security)

[

5/5(2)

](https://www.g2.com/products/radiant-security-radiant/reviews)

Product Description

Radiant Security delivers a centralized AI SOC platform that unifies agentic AI triage, integrated response, and log management in a single solution. The platform provides 100% alert triage coverage a

Pros and Cons

[
Alerting System (2)
](https://www.g2.com/products/radiant-security-radiant/reviews?qs=pros-and-cons)[
Insufficient Information (1)
](https://www.g2.com/products/radiant-security-radiant/reviews?qs=pros-and-cons)

### [Radiant](https://www.g2.com/products/radiant-security-radiant/reviews)

Radiant Security delivers a centralized AI SOC platform that unifies agentic AI triage, integrated response, and log management in a single solution. The platform provides 100% alert triage coverage across all security cases, escalating only real threats and applying analyst-level reasoning with full transparency. SOC teams maintain influence over the AI through guardrails, policies, and exclusions. Response is accelerated with 1-click action plans that can be executed manually or automated for the future. With unlimited log ingestion, real-time search, and affordable retention, Radiant eliminates the complexity and cost barriers of traditional SIEMs. With Radiant, security teams cut through alert noise, respond faster to real threats, scale without adding headcount, and significantly reduce SIEM costs.

**Average Rating:** 5.0/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate Radiant?

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)

#### Who Is the Company Behind Radiant?

- **Seller:** [Radiant Security](https://www.g2.com/sellers/radiant-security)
- **Year Founded:** 2021
- **HQ Location:** Milpitas, California, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=155a32653a1721bacd66938e195c933d9802c7e4a6e184c5e505109d4b0f3bde&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fradiantsecurity-ai&secure%5Burl_type%5D=linkedin_company_website)  
71 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Medium, 50% Small

#### What Do G2 Reviewers Say About Radiant?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **transparency and efficiency** of Radiant's alerting system, enhancing incident management with clear reasoning.
- Users commend Radiant for its **exceptional detection accuracy** , drastically reducing false positives and enhancing alert management efficiency.
- Users praise Radiant's **transparent AI triage engine** , enhancing alert handling and significantly reducing false positives.
- Users value the **transparency and efficiency** of Radiant's AI triage engine for handling alerts effectively.
- Users appreciate the **automated response capability** of Radiant, efficiently triaging alerts and reducing false positives significantly.

##### Cons

- Users note **insufficient information** regarding case management capabilities, indicating room for improvement in the platform.
- Users note some **limitations in case management capabilities** , suggesting room for improvements in Radiant’s features.
- Users find that **navigation issues** arise with a less intuitive UI and more steps needed for custom queries.
- Users find the **navigation non-intuitive** , with excessive steps needed for investigation views and custom queries.
- Users find the **poor interface design** hinders usability, making navigation and query building more complex than it should be.

#### What Are Recent G2 Reviews of Radiant?

**["Noisy alerts are no longer a problem for our SOC"](https://www.g2.com/survey_responses/radiant-review-12217506)**

**Rating:** 5.0/5.0 stars

_— Felipe D._

[Read full review](https://www.g2.com/survey_responses/radiant-review-12217506)

**["AI SOC automation exactly where we needed it"](https://www.g2.com/survey_responses/radiant-review-11697116)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/radiant-review-11697116)

[
RiskIQ Illuminate
](https://www.g2.com/products/riskiq-illuminate/reviews)

By [RiskIQ](https://www.g2.com/sellers/riskiq)

[

5/5(1)

](https://www.g2.com/products/riskiq-illuminate/reviews)

Product Description

RiskIQ is the digital threat management, providing the most comprehensive discovery, intelligence and mitigation of threats associated with an organization’s digital presence

### [RiskIQ Illuminate](https://www.g2.com/products/riskiq-illuminate/reviews)

RiskIQ is the digital threat management, providing the most comprehensive discovery, intelligence and mitigation of threats associated with an organization’s digital presence

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate RiskIQ Illuminate?

- **Automated Remediation:** 8.3/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Ease of Admin:** 6.7/10 (Category avg: 8.6/10)
- **Workflow Automation:** 5.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind RiskIQ Illuminate?

- **Seller:** [RiskIQ](https://www.g2.com/sellers/riskiq)
- **Year Founded:** 2009
- **HQ Location:** San Francisco, US
- **Twitter:** @RiskIQ  
10,963 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e958b5b99763deedd138782320a62b7139aeb0534e36e5658e9ca61b2cdeb7f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Friskiq_2&secure%5Burl_type%5D=linkedin_company_website)  
33 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of RiskIQ Illuminate?

**["Good product"](https://www.g2.com/survey_responses/riskiq-illuminate-review-8721574)**

**Rating:** 5.0/5.0 stars

_— Yamini S._

[Read full review](https://www.g2.com/survey_responses/riskiq-illuminate-review-8721574)

[
Splunk Security Essentials
](https://www.g2.com/products/splunk-security-essentials/reviews)

By [Cisco](https://www.g2.com/sellers/cisco)

[

5/5(1)

](https://www.g2.com/products/splunk-security-essentials/reviews)

Product Description

Splunk Security Essentials (SSE) provides customers with prescriptive security detections, analytic stories, and data onboarding recommendations to guide any organization through their security maturi

### [Splunk Security Essentials](https://www.g2.com/products/splunk-security-essentials/reviews)

Splunk Security Essentials (SSE) provides customers with prescriptive security detections, analytic stories, and data onboarding recommendations to guide any organization through their security maturity journey. SSE enables customers to operationalize industry frameworks like MITRE ATT&CK and Cyber Kill Chain to further enrich and provide context to their security detections.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind Splunk Security Essentials?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of Splunk Security Essentials?

**["Best SIEM tool"](https://www.g2.com/survey_responses/splunk-security-essentials-review-7235425)**

**Rating:** 5.0/5.0 stars

_— Aman P._

[Read full review](https://www.g2.com/survey_responses/splunk-security-essentials-review-7235425)

[
StegoSOC
](https://www.g2.com/products/stegosoc/reviews)

By [StegoSOC](https://www.g2.com/sellers/stegosoc)

[

5/5(1)

](https://www.g2.com/products/stegosoc/reviews)

Product Description

cloud-based threat detection and management

Pros and Cons

[
Detection Accuracy (1)
](https://www.g2.com/products/stegosoc/reviews?qs=pros-and-cons)

### [StegoSOC](https://www.g2.com/products/stegosoc/reviews)

cloud-based threat detection and management

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate StegoSOC?

- **Automated Remediation:** 10.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Workflow Automation:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind StegoSOC?

- **Seller:** [StegoSOC](https://www.g2.com/sellers/stegosoc)
- **Year Founded:** 2016
- **HQ Location:** Durham, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c4fc85062fd4db696fc6b563f2fe5c9e11a90781e49aa3b7cc7b32801818765a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F13353911&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Do G2 Reviewers Say About StegoSOC?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **high detection accuracy** of StegoSOC, finding it invaluable for uncovering hidden data effectively.
- Users appreciate the **intuitive interface** of StegoSOC, making navigation and data detection effortlessly straightforward.
- Users value the **intuitive interface and robust algorithms** of StegoSOC, which enhance its effectiveness in digital forensics.
- Users praise the **reliability** of StegoSOC for its effective detection of hidden data and robust reporting features.
- Users value the **comprehensive reporting features** of StegoSOC, enhancing their digital investigation efficiency and effectiveness.

#### What Are Recent G2 Reviews of StegoSOC?

**["good software"](https://www.g2.com/survey_responses/stegosoc-review-10318073)**

**Rating:** 5.0/5.0 stars

_— Alka K._

[Read full review](https://www.g2.com/survey_responses/stegosoc-review-10318073)

[
ThreatQ
](https://www.g2.com/products/threatq/reviews)

By [ThreatQuotient](https://www.g2.com/sellers/threatquotient)

[

3.5/5(2)

](https://www.g2.com/products/threatq/reviews)

Product Description

ThreatQuotient improves security operations by fusing together disparate data sources, tools and teams to accelerate threat detection and response. ThreatQuotient’s data-driven security operations pla

### [ThreatQ](https://www.g2.com/products/threatq/reviews)

ThreatQuotient improves security operations by fusing together disparate data sources, tools and teams to accelerate threat detection and response. ThreatQuotient’s data-driven security operations platform helps teams prioritize, automate and collaborate on security incidents; enables more focused decision making; and maximizes limited resources by integrating existing processes and technologies into a unified workspace. The result is reduced noise, clear priority threats, and the ability to automate processes with high fidelity data. ThreatQuotient’s industry leading data management, orchestration and automation capabilities support multiple use cases including incident response, threat hunting, spear phishing, alert triage and vulnerability prioritization, and can also serve as a threat intelligence platform. ThreatQuotient is headquartered in Northern Virginia with international operations based out of Europe, MENA and APAC. For more information, visit www.threatquotient.com.

**Average Rating:** 3.5/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate ThreatQ?

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)

#### Who Is the Company Behind ThreatQ?

- **Seller:** [ThreatQuotient](https://www.g2.com/sellers/threatquotient)
- **Year Founded:** 2013
- **HQ Location:** Ashburn, US
- **Twitter:** @ThreatQuotient  
2,276 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=65f65f12518d468f24f3b105b89a806b78ab7f89c658a99e503fedc4cbc227c2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fthreatquotient%2F&secure%5Burl_type%5D=linkedin_company_website)  
59 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Medium, 50% Small

#### What Are Recent G2 Reviews of ThreatQ?

**["User-friendly with many options to customize"](https://www.g2.com/survey_responses/threatq-review-4954000)**

**Rating:** 4.5/5.0 stars

_— Verified User in Human Resources_

[Read full review](https://www.g2.com/survey_responses/threatq-review-4954000)

#### What Are G2 Users Discussing About ThreatQ?

- [What is ThreatQ used for?](https://www.g2.com/discussions/what-is-threatq-used-for) - 1 comment

[
Anomali Security Analytics
](https://www.g2.com/products/anomali-security-analytics/reviews)

By [ANOMALI](https://www.g2.com/sellers/anomali)

[

0/5(1)

](https://www.g2.com/products/anomali-security-analytics/reviews)

Product Description

Anomali is the ultra-modern SIEM, fusing the key capabilities of ETL, SIEM, Next-Gen SIEM, XDR, UEBA, SOAR, and TIP into a single, high-speed data lake — with 7+ years of always-hot storage for instan

### [Anomali Security Analytics](https://www.g2.com/products/anomali-security-analytics/reviews)

Anomali is the ultra-modern SIEM, fusing the key capabilities of ETL, SIEM, Next-Gen SIEM, XDR, UEBA, SOAR, and TIP into a single, high-speed data lake — with 7+ years of always-hot storage for instant access to historical data. A system of action, Anomali weaves AI throughout every workflow, driving smarter ingestion, enrichment, detection, investigation, and response at massive scale. By connecting native threat intelligence with security data, Anomali delivers total visibility, real-time contextual insight, and the clarity to act fast.

#### Who Is the Company Behind Anomali Security Analytics?

- **Seller:** [ANOMALI](https://www.g2.com/sellers/anomali)
- **Year Founded:** 2013
- **HQ Location:** Redwood City, California, United States
- **Twitter:** @Anomali  
8,773 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2b626d91a108ac860ce879c957a9004992f62aa5443796308bb7e7018f5df0dd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fanomali&secure%5Burl_type%5D=linkedin_company_website)  
314 employees on LinkedIn®
- **Phone:** (844) 484-7328

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of Anomali Security Analytics?

**["Vendor Agnostic largest Threat Intel Database"](https://www.g2.com/survey_responses/anomali-security-analytics-review-5050997)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/anomali-security-analytics-review-5050997)

#### What Are G2 Users Discussing About Anomali Security Analytics?

- [What is Anomali used for?](https://www.g2.com/discussions/anomali-what-is-anomali-used-for)
- [What is Anomali used for?](https://www.g2.com/discussions/what-is-anomali-used-for)

[
Arcanna.AI
](https://www.g2.com/products/arcanna-ai/reviews)

By [Arcanna.AI](https://www.g2.com/sellers/arcanna-ai)

[

0/5(0)

](https://www.g2.com/products/arcanna-ai/reviews)

Product Description

Arcanna.AI is an AI Platform focused on augmenting human decisions in the SOC, agnostic to the tools and processes utilized by the analyst team. Reduce the risk of human error and increase efficiency

### [Arcanna.AI](https://www.g2.com/products/arcanna-ai/reviews)

Arcanna.AI is an AI Platform focused on augmenting human decisions in the SOC, agnostic to the tools and processes utilized by the analyst team. Reduce the risk of human error and increase efficiency in decision-making Your data. Your models. Your network. Your tools. Your processes. Empowering SOC Analysts with Superior Decisions; Seamless Integration; Data Privacy And Security

#### Who Is the Company Behind Arcanna.AI?

- **Seller:** [Arcanna.AI](https://www.g2.com/sellers/arcanna-ai)
- **Year Founded:** 2019
- **HQ Location:** New York, US
- **Twitter:** @ArcannaAi  
82 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1ca1c5d535d54bfb28ef52547c15937f58a221b9f6382b37e12564611fe44240&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Farcannaai&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

[
Argus By Genix
](https://www.g2.com/products/argus-by-genix/reviews)

By [Genix Cyber](https://www.g2.com/sellers/genix-cyber)

[

0/5(0)

](https://www.g2.com/products/argus-by-genix/reviews)

Product Description

Argus by Genix Cyber is a powerful Extended Detection and Response (XDR) platform designed to simplify cybersecurity across cloud, hybrid, and on-premise environments. It integrates advanced threat de

### [Argus By Genix](https://www.g2.com/products/argus-by-genix/reviews)

Argus by Genix Cyber is a powerful Extended Detection and Response (XDR) platform designed to simplify cybersecurity across cloud, hybrid, and on-premise environments. It integrates advanced threat detection, identity access governance, and continuous compliance into one centralized system. With real-time insights, AI-enhanced analytics, and automated incident response, Argus helps reduce security risks while ensuring regulatory alignment. Ideal for enterprises and MSPs, it delivers flexible protection that scales with your infrastructure.

#### Who Is the Company Behind Argus By Genix?

- **Seller:** [Genix Cyber](https://www.g2.com/sellers/genix-cyber)
- **Year Founded:** 2018
- **HQ Location:** Atlanta, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6acacc40cd7b3e1e9d4d5fb12532ae96a1d0e400cb0208ec575ef619e4b39263&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgenix-cyber&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

[
BIMA
](https://www.g2.com/products/bima/reviews)

By [Peris.ai](https://www.g2.com/sellers/peris-ai)

[

0/5(0)

](https://www.g2.com/products/bima/reviews)

Product Description

BIMA by Perisai: Redefining Cybersecurity with a Symphony of EDR, NDR, XDR, and SIEM. Experience digital freedom like never before, where every click is safe, and every innovation is secure. Bima - wh

### [BIMA](https://www.g2.com/products/bima/reviews)

BIMA by Perisai: Redefining Cybersecurity with a Symphony of EDR, NDR, XDR, and SIEM. Experience digital freedom like never before, where every click is safe, and every innovation is secure. Bima - where peace of mind meets the cutting edge.

#### Who Is the Company Behind BIMA?

- **Seller:** [Peris.ai](https://www.g2.com/sellers/peris-ai)
- **Year Founded:** 2022
- **HQ Location:** Jakarta, ID
- **Twitter:** @peris\_ai  
155 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=578f2b883c33bba49198c04a60a3f842d3eaec3ed7b4e074ebce55bef3cee0c7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fperisai-cybersecurity&secure%5Burl_type%5D=linkedin_company_website)  
25 employees on LinkedIn®

[
Cisco Hypershield
](https://www.g2.com/products/cisco-hypershield/reviews)

By [Cisco](https://www.g2.com/sellers/cisco)

[

0/5(0)

](https://www.g2.com/products/cisco-hypershield/reviews)

Product Description

Bringing the power of hyperscaler technology to the enterprise, Cisco Hypershield is a groundbreaking security architecture designed to defend modern, AI-scale data centers.

### [Cisco Hypershield](https://www.g2.com/products/cisco-hypershield/reviews)

Bringing the power of hyperscaler technology to the enterprise, Cisco Hypershield is a groundbreaking security architecture designed to defend modern, AI-scale data centers.

#### Who Is the Company Behind Cisco Hypershield?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

[
Cortex AgentiX
](https://www.g2.com/products/cortex-agentix/reviews)

By [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)

[

0/5(0)

](https://www.g2.com/products/cortex-agentix/reviews)

Product Description

The next generation of Cortex XSOAR® is the industry’s most secure platform to build, deploy and govern the AI agent workforce of the future. Elevate Your Team’s Impact Agents act as intelligent team

### [Cortex AgentiX](https://www.g2.com/products/cortex-agentix/reviews)

The next generation of Cortex XSOAR® is the industry’s most secure platform to build, deploy and govern the AI agent workforce of the future. Elevate Your Team’s Impact Agents act as intelligent teammates, available 24/7 to plan and carry out complex workflows, guided by 1.2 billion real-world playbook executions. Choose from a comprehensive library of ready-to-use agents or build custom, no-code versions that fit your exact security needs. Autonomy with Guardrails You’re in control of when agents should be supervised or have the autonomy to act on their own. They’re bound by the same robust access control and permissions management as analysts with human-in-the-loop approval for impactful actions. No Black Box. Full Transparency. Gain full transparency into every aspect of an agent: how it interprets your request, the actions it takes and the results it delivers. Everything is traceable to meet the strictest audit and compliance requirements.

#### Who Is the Company Behind Cortex AgentiX?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®
- **Ownership:** NYSE: PANW

[
CounterCraft The Platform
](https://www.g2.com/products/countercraft-the-platform/reviews)

By [CounterCraft](https://www.g2.com/sellers/countercraft)

[

0/5(0)

](https://www.g2.com/products/countercraft-the-platform/reviews)

Product Description

CounterCraft The Platform™ is the highest-quality platform for active defense powered by deception technology. It allows organizations to identify unknown risks and threats tailored to their external

### [CounterCraft The Platform](https://www.g2.com/products/countercraft-the-platform/reviews)

CounterCraft The Platform™ is the highest-quality platform for active defense powered by deception technology. It allows organizations to identify unknown risks and threats tailored to their external and internal attack surface and delivers detailed telemetry. This pioneering deception technology offers full visibility into adversaries’ tactics, techniques, and procedures. CounterCraft enables organizations to detect threats early, collect specific, actionable threat intelligence, stop threats before a breach occurs and defend their valuable data in real time. Our software is seamlessly deployed in the Cloud or on customers’ infrastructure and is a crucial component of the detection and response, XDR and EDR categories. CounterCraft + EDR/XDR/SIEM = together to stop breaches. When combined with EDR, SIEM and XDR products, deception fulfills SOC visibility triad on-premises and cloud, and eliminates blind spots left by these solutions. Thus, our impact goes beyond these strategies, allowing for ongoing active defense and providing contextual threat intel. Everything, everywhere all at once: - Can be deployed on all environments (on prem, in cloud, hybrid) while monitoring and analyzing all the malicious activity on the same screen. - Attack path design and incident analysis on the same attack tree interface view Ease of deployment - On prem environment deployment is 10x times faster than other solutions - Cloud environment deployment is 100x times faster than other solutions: 4-5 click cloud server installation (AWS, Azure etc.) - No direct connection with real production environment, evading business disruption High automation with endless possibilities - 40 different use case templates ready to be deployed under one-click installation (lateral movement, SWIFT servers, VPNs, SCADA etc.) Credibility - ActiveSense Environments uses real systems in realistic ways to give your adversaries what they’re expecting to find - Unlike honeypots, we deploy automated moving target defense and sophisticated detection and response. - Integrated ActiveBehaviorTM functionality simulates real user hands-on activity, making the digital twin environment unrecognizable even to employees and needing less monitoring and analysis time for SOC teams.

#### Who Is the Company Behind CounterCraft The Platform?

- **Seller:** [CounterCraft](https://www.g2.com/sellers/countercraft)
- **Year Founded:** 2015
- **HQ Location:** New York, US
- **Twitter:** @countercraftsec  
1,306 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f0bf58fdf450eaf974bd6ea9822291dbc663ac5402c5a2c827ecd0cbb5ad86cf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcountercraft&secure%5Burl_type%5D=linkedin_company_website)  
42 employees on LinkedIn®

[
CybernetIQ
](https://www.g2.com/products/cybernetiq/reviews)

By [CybernetIQ](https://www.g2.com/sellers/cybernetiq)

[

0/5(0)

](https://www.g2.com/products/cybernetiq/reviews)

Product Description

CybernetIQ’s CLAW is a military-grade attack surface analysis (ASA) platform that consolidates protection, detection, and remediation capabilities in a single frame to deliver what most SIEM and SOAR

### [CybernetIQ](https://www.g2.com/products/cybernetiq/reviews)

CybernetIQ’s CLAW is a military-grade attack surface analysis (ASA) platform that consolidates protection, detection, and remediation capabilities in a single frame to deliver what most SIEM and SOAR tools only promise – a truly holistic view of your network. The Ultimate Network Vulnerability Detection Workstation: Threat Hunting CLAW searches your network to find, isolate and contextualize threats so your analysts can deploy countermeasures quickly to reduce exposure, and mitigate defensive weaknesses before a threat becomes a breach. Incident Response CLAW puts everything into actionable context for your cyber operators: the nature of the incident, the devices involved, the zones affected and data exfiltration routes, so your SecOps team can prioritize and accelerate the response. Vulnerability Scanning CLAW simplifies and accelerates vulnerability scanning by issuing commands to your cybersecurity tools and combining the results with more than 130 data and information sources to create a comprehensive view of the risks to your network.

#### Who Is the Company Behind CybernetIQ?

- **Seller:** [CybernetIQ](https://www.g2.com/sellers/cybernetiq)
- **Year Founded:** 2018
- **HQ Location:** Columbia, Maryland, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=09697b8f9022625d243518456aae8c52aea40fb150bb3dc426e7611afc52937d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftechnologyadvancementcenter&secure%5Burl_type%5D=linkedin_company_website)  
74 employees on LinkedIn®

- [&lsaquo; Prev‹ Prev](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=3#product-list)
- [1](/categories/security-orchestration-automation-and-response-soar?order=g2_score#product-list)
- [2](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=2#product-list)
- [3](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=3#product-list)
- 4
- [5](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=5#product-list)
- [6](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=6#product-list)
- [Next &rsaquo;Next ›](/categories/security-orchestration-automation-and-response-soar?order=g2_score&page=5#product-list)

Spotlight Categories

[Lead Intelligence Software](https://www.g2.com/categories/lead-intelligence)

[Social Media Management Tools](https://www.g2.com/categories/social-media-mgmt)

[Expense Management Software](https://www.g2.com/categories/expense-management)

[User Research Tools](https://www.g2.com/categories/user-research)

[Managed Detection and Response (MDR) Software](https://www.g2.com/categories/managed-detection-and-response-mdr)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)

- [Deception Technology](/categories/deception-technology)
- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)

- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)
- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)

[Browse Security Orchestration, Automation, and Response (SOAR) Themes](/categories/security-orchestration-automation-and-response-soar/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Security orchestration, automation, and response (SOAR) software products are tools used to help integrate security technologies and automate incident-related tasks. These tools integrate with a company’s existing security solutions to help users build and automate workflows, simplifying the incident response process and reducing the amount of human intervention necessary to handle security incidents. Companies use these tools to create a centralized system complete with visibility into a company’s security software and operational processes. These tools also reduce the time it takes to respond to incidents, as well as the potential for human error in remediating security threats and vulnerabilities.

SOAR platforms combine aspects of [vulnerability management](https://www.g2.com/categories/vulnerability-management), [incident response](https://www.g2.com/categories/incident-response), and [security information and event management (SIEM)](https://www.g2.com/categories/security-information-and-event-management-siem) solutions. SOAR products are designed to provide some of each tool’s respective functionality or integrate with third-party tools. Once integrated, processes can be designed to identify incidents and automate remediation tasks.

To qualify for inclusion in the Security Orchestration, Automation, and Response (SOAR) category, a product must:

- Integrate security information and incident response tools
- Allow security professionals to build response workflows
- Automate incident management and response tasks within workflows
- Provide formalized incident, workflow, and performance reports

Show More

* * *

## How Do You Choose the Right Security Orchestration, Automation, and Response (SOAR) Software?

### What You Should Know About Security, Orchestration, Automation, and Response (SOAR) Software

### What is Security, Orchestration, Automation, and Response (SOAR) Software?

Security orchestration, automation, and response (SOAR) software helps coordinate, execute, and automate tasks between various IT workers and tools. SOAR tools allow organizations to respond quickly to cybersecurity attacks and observe, understand, and prevent future incidents.

SOAR software gives organizations a comprehensive view of their existing security systems while centralizing the security data. By automating security responses and reducing manual tasks, SOAR helps to generate a faster and more accurate response to security attacks. It also helps better coordinate and route incident response to the most appropriate IT worker in real time.

**What Does SOAR Stand For?**

SOAR stands for security orchestration, automation, and response. SOAR software significantly contributes to identifying potential future security threats.

### What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?

Usually, a SOAR software offering operates under three primary software capabilities:

**Threat and vulnerability management:** Threat and vulnerability management examines key assets and prioritizes efforts to reduce risk. Working with other security teams, threat and vulnerability management helps prevent attacks by threat actors.

**Security incident response:** Security incident response addresses and manages the aftermath of a security breach, cyberattack, computer incident, or security incident. Security incident response is to handle the aftermath of a security breach in a way that limits damage, reduces recovery time, and reduces cost.

**Security operations automation:** Security operations automation is the technology that enables the automation and orchestration of security tasks. This can include both administrative duties and incident detection and response.

### What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?

The benefits of using a SOAR tool are that it lessens the impact of security incidents and reduces the risk of legal liability. SOAR software helps companies’ security teams by enabling them to:

**Maintain a central view:** One of the benefits of SOAR software is that it gives security staff a central view and enables control of existing security systems while centralizing data collection to improve a company's security posture, operational efficiency, and productivity.&nbsp;

**Automate manual tasks:** As with most software today, users are looking for help in terms of automation. SOAR software helps to manage and automate all aspects of a security incident lifecycle. This removes manual tasks, gives security staff more time to be productive, and allows them to focus on more mission-critical security tasks that do not require manual tasks.

**Define incident and response procedures:** SOAR software helps security systems define incident and response procedures. This helps to route security incidents to the correct security staff. SOAR can also prioritize and standardize the security response processes in a consistent, transparent, and documented way.&nbsp;

**Optimize incident response** : Because SOAR software helps security staff define incident and response procedures, incident response is more accurate. This accuracy enables security systems and staff to have improved responses where they may have to contain, eradicate, or recover crucial data.&nbsp;

**Identify and assign incident severity levels:** SOAR software helps to identify and assign incident severity levels. Severity levels in cybersecurity measure how severely a security incident impacts various parts of the organization. SOAR software automatically identifies and assigns severity levels, enabling the right security system and staff to respond appropriately. This means both can respond immediately to security incidents that may negatively affect an organization, such as networks, software, employee or customer data, etc.

**Support collaboration and unstructured investigations:** SOAR software supports collaboration and unstructured investigations in real time, helping route each security incident to the security system and security staff best suited to respond. Collaboration with other IT teams for tasks such as remediation or other departments such as legal is possible.&nbsp;

**Streamline operations:** By using SOAR software, organizations can streamline security operations for threat and vulnerability management, security incident response, and security operations automation. SOAR software connects these security elements while integrating disparate security systems. SOAR software’s playbooks allow users to orchestrate, streamline and automate tasks. Playbooks also codify the process workflows that streamline the SOAR software functions.

### Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?

**IT and cybersecurity staff:** They use SOAR software to handle security alerts such as phishing, which includes looking for threat feed data from endpoints, failed user logins, logins from unusual locations, malicious VPN access attempts, and so on. It's also used to hunt for threats and respond to incidents from attached files for malware analysis, cloud-aware incident response, and automate data enrichment. Cybersecurity staff who assign incident severity and check other products for vulnerability scores also use SOAR platforms.

### Challenges with Security, Orchestration, Automation, and Response (SOAR) software

There are a number of challenges with SOAR software that IT teams can encounter.

**Skill gaps:** While there is the misconception that SOAR software could replace security staff, the tool is meant to augment security teams, allowing them to work efficiently and effectively but not replacing them. However, there still may be a skills gap as the security team must be able to create detailed workflows of their processes.

**Effective deployment:** Another challenge of SOAR software is that it must be deployed to the enterprise but also connected to the other applications and technologies, which can be very complicated. An organization must also have staff with enough skills to deploy and maintain the platform. The applications and technologies used by the enterprise must also be able to support or be integrated into the SOAR software. One of SOAR software’s greatest strengths is to connect and orchestrate other technologies; however, if each technology is unable to be integrated, it hampers the benefits of deploying SOAR software.

### How to Buy Security, Orchestration, Automation, and Response Software

#### Requirements Gathering (RFI/RFP) for Security, Orchestration, Automation, and Response (SOAR) Software

If an organization is just starting out and looking to purchase SOAR software, g2.com can help select the best one.

Most business pain points might be related to all of the manual work that must be completed. If the company is large and has a lot of networks, data, or devices in its organization, they may need to shop for a SOAR software that can grow with its organization. Users should think about the pain points in security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use the SOAR software and if they currently have the skills to administer it.&nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The checklist serves as a detailed guide that includes both necessary and nice-to-have features, including budget, features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the scope of the deployment, it might be helpful to produce an RFI, a one-page list with a few bullet points describing what is needed from SOAR software.

#### Compare Security, Orchestration, Automation, and Response (SOAR) Software

**Create a long list**

Vendor evaluations are an essential part of the software buying process from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow down the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list in hand, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure the comparison is comprehensive, the user should demo each solution on the shortlist with the same use cases. This will allow the business to evaluate like for like and see how each vendor stacks up against the competition.&nbsp;

#### Selection of Security, Orchestration, Automation, and Response (SOAR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the entire process, from identifying pain points to implementation, is crucial. The software selection team should consist of organization members with the right interest, skills, and time to participate in this process. A good starting point is to aim for three to five people who fill roles such as the main decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. In smaller companies, the vendor selection team may be smaller, with fewer participants multitasking and taking on more responsibilities.

**Compare notes**

The selection team should compare notes and facts and figures which they noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it's final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and well received, the buyer can be confident that the selection was correct. If not, it might be time to go back to the drawing board.

### What does Security, Orchestration, Automation, and Response (SOAR) Software cost?

SOAR is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization's specific requirements. Once a SOAR solution is purchased, deployed, and integrated into an organization’s security system, the cost could be high, which is why the evaluation stage of selecting SOAR software is so crucial. The notion of rip-and-replace cost can be high. The SOAR vendor chosen should continue to provide support for the SOAR solution with flexibility and open integration.

#### Return on Investment (ROI)

Organizations decide to purchase SOAR software with some type of return on investment (ROI). As they want to recoup the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency.

SOAR software saves security staff costs by eliminating manual tasks. For example, SOAR software automatically investigates the scenario of email phishing attacks which is very common, so this task can be very repetitive and consumes security staff time if it is done manually. A large enterprise used actual data from its SOAR software deployment and compared it to the cost of handling email phishing investigations automatically using SOAR software versus handling them manually. The enterprise found that the reduction in staff time required to handle phishing emails equated to savings of over $680,000 per year.

### Security, Orchestration, Automation, and Response (SOAR) Software Trends

**Enterprises:** Due to the requirements to maintain such large-scale IT and network infrastructure, organizations such as large enterprises tend to be more interested in purchasing SOAR software. Having such large networks and more complex IT makes such organizations more vulnerable to security threats which is another drive to purchase SOAR software. Also, larger organizations have more employees with more devices, which increases threats if they are accessing workplace applications on these devices.

**Retail and e-commerce:** These industries have increased interest in SOAR software due to the vulnerabilities in PoS)transactions and online purchases. It is the processing of these monetary transactions which creates a security risk, especially there personal and financial information of customers. Adopting technologies such as location-based marketing for these types of purchases also makes the retail industry more vulnerable to security threats.