# Best Security Orchestration, Automation, and Response (SOAR) Software

## How Many Security Orchestration, Automation, and Response (SOAR) Software Products Does G2 Track?

**Total Products under this Category:** 81

### Category Stats (Aug 2026)

- **Average Rating:** 4.53/5 (↑0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Singularity AI SIEM (+21.43%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

_Last updated: August 06, 2026_

## How Does G2 Rank Security Orchestration, Automation, and Response (SOAR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,500+ Authentic Reviews
- 81+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software
 ![G2 Grid® for Security Orchestration, Automation, and Response (SOAR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.png?focus%5B%5D=98376&focus%5B%5D=120746&focus%5B%5D=164907&focus%5B%5D=139264&focus%5B%5D=30500&focus%5B%5D=55254&focus%5B%5D=122123&focus%5B%5D=58203)

Highlighted products: Tines, n8n, Torq AI SOC Platform, KnowBe4 PhishER/PhishER Plus, Google Security Operations, ServiceNow Security Operations, Microsoft Sentinel, and Check Point Infinity Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-orchestration-automation-and-response-soar/grids.json?focus%5B%5D=tines&focus%5B%5D=n8n&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=google-security-operations&focus%5B%5D=servicenow-security-operations&focus%5B%5D=microsoft-sentinel&focus%5B%5D=check-point-infinity-platform)

**Sponsored**

### TriNet

TriNet has been a trusted leader in the Professional Employer Organization (PEO) industry for over 30 years, providing comprehensive HR solutions tailored specifically for small and midsize businesses. This longevity in the market reflects deep expertise and a proven track record of helping companies streamline their human resources functions, mitigate risks, and enhance employee satisfaction. TriNet helps simplify complex HR challenges by offering a unified platform that integrates payroll processing, benefits administration, risk mitigation, and compliance support. This consolidates the need for multiple vendors, reducing administrative burden and allows business leaders to focus on growth and strategic priorities. Key areas of service include industry-specific HR expertise, access to premium employee benefits through national and regional carriers or ability to sponsor your own benefits, and advanced proprietary technology. The TriNet platform delivers an intuitive user experience with capabilities spanning payroll, benefits administration, time tracking, performance management, learning and development, and workforce analytics. This comprehensive platform empowers clients with real-time insights and streamlined processes. TriNet’s dedicated service model combines personalized support from assigned HR professionals and relationship managers with access to specialized HR experts via multiple communication channels. This helps deliver timely, expert best practices guidance tailored to each client’s unique needs. TriNet also provides instructor-led trainings and expert consultations to help clients build HR processes in key areas, like performance management, hiring/onboarding, and compensation.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2178&secure%5Bchosen_at%5D=2026-08-06T20%3A55%3A25Z&secure%5Bdisplayable_resource_id%5D=1380&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=4062&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=4062&secure%5Bresource_id%5D=2178&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsecurity-orchestration-automation-and-response-soar%3Fopen_modal_url%3D%252Fproducts%252Ftines%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fsecurity-orchestration-automation-and-response-soar%2526source%253Dcategory&secure%5Btoken%5D=218e754f5a808e3a3edd3aa2e0109d476a15228742f7ec21cb3f50d600beca11&secure%5Burl%5D=https%3A%2F%2Fwww.trinet.com%2Flp%2Fcompare%3Futm_source%3Dg2%26utm_medium%3Dcpc%26utm_campaign%3D26-3Party-PPC-Review-G2-aigeo26%26campaign_id%3D701Nr00000qElh5IAC&secure%5Burl_type%5D=book_demo)

### [Tines](https://www.g2.com/de/products/tines/reviews)

Tines ist die intelligente Workflow-Plattform, der die fortschrittlichsten Organisationen der Welt vertrauen. Unternehmen wie Coinbase, Databricks, Mars, Reddit und SAP nutzen Tines, um ihre wichtigsten Workflows zu betreiben. Mit Tines haben sie eine sichere, flexible Grundlage geschaffen, um KI-Agenten und intelligente Workflows zu operationalisieren, Produktivität freizusetzen, schneller zu agieren und die Zukunft der Arbeitsweise zu sichern. Du kannst sofort mit dem Aufbau beginnen, indem du dich für unsere immer kostenlose Community Edition anmeldest und einen unserer vorgefertigten Workflows aus der Bibliothek importierst.

**Average Rating:** 4.7/5.0

**Total Reviews:** 399

#### How Do G2 Users Rate Tines?

- **Automatisierte Problembehebung:** 9.3/10 (Category avg: 8.7/10)
- **Support-Qualität:** 9.6/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 9.2/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Tines?

- **Verkäufer:** [Tines](https://www.g2.com/de/sellers/tines)
- **Unternehmenswebsite:** www.tines.com
- **Gründungsjahr:** 2018
- **Hauptsitz:** Dublin, IE
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4fc971f982798d83e47683f1503ab5657fee83ad46901a0ba9319f85a0d8adbf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftines-io%2F&secure%5Burl_type%5D=linkedin_company_website)  
568 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Sicherheitsingenieur, Software-Ingenieur
- **Top Industries:** Computer- und Netzwerksicherheit, Informationstechnologie und Dienstleistungen
- **Company Size:** 39% Medium, 36% Large

#### What Do G2 Reviewers Say About Tines?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Benutzerfreundlichkeit** von Tines, die eine effiziente Automatisierung ermöglicht, ohne umfangreiche technische Kenntnisse zu erfordern.
- Benutzer finden, dass Tines **Automatisierung mühelos** macht, was eine einfache Aufgabenbewältigung ohne Programmierkenntnisse ermöglicht.
- Benutzer loben Tines für ihren **außergewöhnlichen Kundensupport** , der jederzeit schnelle, freundliche und effektive Unterstützung bietet, wenn sie benötigt wird.
- Benutzer schätzen die **einfachen Integrationen** von Tines, die eine schnelle und effektive Automatisierung ohne Programmierkenntnisse ermöglichen.
- Benutzer loben Tines für seine **nahtlosen Integrationen** und den robusten Support, die eine effiziente Workflow-Automatisierung mit Leichtigkeit ermöglichen.

##### Cons

- Benutzer finden, dass Tines wesentliche Funktionen fehlen, insbesondere eine robuste **IDE und Code-Review-Fähigkeiten** , was die Effizienz des Workflows beeinträchtigt.
- Benutzer erleben eine **steile Lernkurve** mit Tines, die ein tiefes Verständnis für effektive Automatisierung und Anpassung erfordert.
- Benutzer finden, dass der **Mangel an erweiterten Funktionen** in Tines ihre Fähigkeit, komplexe Workflows effektiv zu erstellen, beeinträchtigt.
- Benutzer finden Tines **teuer** , insbesondere für kleinere Teams, aufgrund seines starren Preismodells und der begrenzten Ticketing-Funktionen.
- Benutzer finden die **Lernkurve und Komplexität** herausfordernd, was es schwierig macht, die Fähigkeiten von Tines vollständig zu nutzen.

#### What Are Recent G2 Reviews of Tines?

**["Leistungsstarke No-Code-Automatisierung mit einer flexiblen, sicheren visuellen Schnittstelle."](https://www.g2.com/de/survey_responses/tines-review-13218331)**

**Rating:** 4.5/5.0 stars

_— Anil B._

[Read full review](https://www.g2.com/de/survey_responses/tines-review-13218331)

**["Intuitive No-Code-Automatisierung mit starker KI und Integrationen"](https://www.g2.com/de/survey_responses/tines-review-13208088)**

**Rating:** 4.5/5.0 stars

_— Harsh C._

[Read full review](https://www.g2.com/de/survey_responses/tines-review-13208088)

#### What Are G2 Users Discussing About Tines?

- [How do you use Tines?](https://www.g2.com/de/discussions/how-do-you-use-tines)
- [Sind Zinken ein Schmerz?](https://www.g2.com/de/discussions/is-tines-a-soar) - 1 comment
- [What does Tines do?](https://www.g2.com/de/discussions/what-does-tines-do) - 1 comment
- [Was ist Tines-Automatisierung?](https://www.g2.com/de/discussions/what-is-tines-automation) - 2 comments

### [n8n](https://www.g2.com/products/n8n/reviews)

n8n is a workflow automation platform built for technical teams operationalizing AI. Built for technical teams, it offers 500+ integrations, custom code flexibility, and self-hosting options. With 180k+ Github Stars and a thriving community, n8n enables teams to build production-ready automation workflows that bridge AI with real business processes.

**Average Rating:** 4.7/5.0

**Total Reviews:** 291

#### How Do G2 Users Rate n8n?

- **Automated Remediation:** 8.2/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.1/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.4/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind n8n?

- **Seller:** [n8n GmbH](https://www.g2.com/sellers/n8n-gmbh)
- **Company Website:** n8n.io
- **Year Founded:** 2019
- **HQ Location:** Berlin, Berlin
- **Twitter:** @n8n\_io  
81,824 Twitter followers
- **LinkedIn® Page:** [linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7f38ddf929a710526e334bba2637a0b913b862c7e0ad923e4f487878bac84912&secure%5Burl%5D=https%3A%2F%2Flinkedin.com%2Fcompany%2Fn8n&secure%5Burl_type%5D=linkedin_company_website)  
999 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CEO, Founder
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 77% Small, 19% Medium

#### What Do G2 Reviewers Say About n8n?

_AI-generated summary from verified user reviews_

##### Pros

- Users find n8n's **ease of use** essential for creating efficient workflows, complemented by a powerful visual editor.
- Users praise n8n for its **flexible automation capabilities** , enabling effortless integration and efficiency in workflows.
- Users love the **growing library of integrations** in n8n, enabling seamless connections across various tools for automation.
- Users love n8n for its **intuitive visual editor** and extensive integrations, revolutionizing their workflow automation.
- Users value the **flexibility and ease of the workflow builder** in n8n, enhancing productivity and customization.

##### Cons

- Users find n8n's **learning curve steep** , particularly for non-developers managing complex workflows and technical aspects.
- Users find the **difficult learning** curve of n8n overwhelming, especially for those without technical backgrounds.
- Users find n8n lacking **cost-control features** , leading to unexpected expenses during testing and learning phases.
- Users find the **limitations in handling large records and complex workflows** can hinder their productivity and efficiency.
- Users express frustration with the **poor interface design** of n8n, hindering productivity and usability in workflows.

#### What Are Recent G2 Reviews of n8n?

**["Intuitive Workflow Automation with Powerful Integrations"](https://www.g2.com/survey_responses/n8n-review-13204128)**

**Rating:** 4.5/5.0 stars

_— Maria S._

[Read full review](https://www.g2.com/survey_responses/n8n-review-13204128)

**["Unmatched Versatility"](https://www.g2.com/survey_responses/n8n-review-13220391)**

**Rating:** 5.0/5.0 stars

_— Pedro S._

[Read full review](https://www.g2.com/survey_responses/n8n-review-13220391)

#### What Are G2 Users Discussing About n8n?

- [How do you use N8N?](https://www.g2.com/discussions/how-do-you-use-n8n)
- [Who uses n8n?](https://www.g2.com/discussions/who-uses-n8n)
- [Is n8n open source?](https://www.g2.com/discussions/is-n8n-open-source)
- [What does n8n do?](https://www.g2.com/discussions/what-does-n8n-do) - 4 comments

### [KnowBe4 PhishER/PhishER Plus](https://www.g2.com/es/products/knowbe4-phisher-phisher-plus/reviews)

KnowBe4 PhishER Plus ofrece una respuesta automatizada a incidentes para eliminar el ruido del SOC y remediar correos electrónicos maliciosos en toda su organización simultáneamente. Aprovecha la IA para categorizar los mensajes reportados a través del correo electrónico y Microsoft Teams, respondiendo automáticamente a los reporteros, marcando mensajes de alto riesgo y eliminando amenazas en todos los buzones. Los equipos de SOC incluso pueden convertir mensajes maliciosos en simulaciones de entrenamiento para ver quién habría sido víctima. Los clientes informan que ahorran más del 99% del tiempo de triaje, alabando altamente la interfaz intuitiva y fácil de usar de la plataforma que transforma flujos de trabajo manuales abrumadores en acciones rápidas y consistentes. Esta capa de defensa revisa las amenazas que pasan por otras capas de seguridad, ofreciendo una vista única con integraciones líderes de terceros como CrowdStrike, Webroot y VirusTotal. PhishER Plus convierte el triaje manual de correos electrónicos en una postura de seguridad proactiva y automatizada.

**Average Rating:** 4.5/5.0

**Total Reviews:** 567

#### How Do G2 Users Rate KnowBe4 PhishER/PhishER Plus?

- **Corrección automatizada:** 8.7/10 (Category avg: 8.7/10)
- **Calidad del soporte:** 9.2/10 (Category avg: 9.0/10)
- **Facilidad de administración:** 8.9/10 (Category avg: 8.6/10)
- **Automatización del flujo de trabajo:** 8.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind KnowBe4 PhishER/PhishER Plus?

- **Vendedor:** [KnowBe4, Inc.](https://www.g2.com/es/sellers/knowbe4-inc)
- **Sitio web de la empresa:** www.knowbe4.com
- **Año de fundación:** 2010
- **Ubicación de la sede:** Clearwater, FL
- **Twitter:** @KnowBe4  
16,161 seguidores en Twitter
- **Página de LinkedIn®:** [www.linkedin.com](https://www.g2.com/es/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e1f02b116441fecaeae5d1901607d74fbe2669c6c4acd16c69c0270cc92ed5f0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2225282%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,636 empleados en LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Gerente de TI, Director de TI
- **Top Industries:** Servicios Financieros, Educación Primaria/Secundaria
- **Company Size:** 75% Medium, 13% Large

#### What Do G2 Reviewers Say About KnowBe4 PhishER/PhishER Plus?

_AI-generated summary from verified user reviews_

##### Pros

- Los usuarios aprecian las **pruebas de phishing efectivas** y las funciones de monitoreo de KnowBe4 PhishER, mejorando la conciencia de seguridad en general.
- Los usuarios aprecian las **funciones de seguridad de correo electrónico** de KnowBe4 PhishER para gestionar proactivamente las amenazas de correo electrónico de manera efectiva.
- Los usuarios valoran la **automatización de la clasificación de correos electrónicos** , mejorando la eficiencia en la identificación y gestión de amenazas de phishing de manera efectiva.
- Los usuarios valoran la **facilidad de uso** de KnowBe4 PhishER, mejorando la eficiencia del triaje y reporte de correos electrónicos de spam.
- Los usuarios valoran las **funciones de seguridad** de KnowBe4 PhishER, mejorando la seguridad mientras se minimiza la carga administrativa.

##### Cons

- Los usuarios experimentan problemas con la **gestión de correos electrónicos** , ya que los correos a menudo terminan en carpetas de correo no deseado o carecen de claridad en la resolución de problemas.
- Los usuarios experimentan frecuentes **falsos positivos** , lo que complica la automatización y exige una revisión manual continua para mejorar la precisión.
- Los usuarios notan **seguridad de correo electrónico ineficaz** , ya que los correos electrónicos de phishing a menudo pasan por alto la bandeja de entrada y permanecen en las carpetas de correo no deseado, complicando la gestión.
- Los usuarios encuentran la **automatización ineficiente** problemática, requiriendo intervención manual y careciendo de detección consistente para campañas de phishing.
- Los usuarios encuentran la **configuración difícil** , requiriendo tiempo y una comprensión cuidadosa antes de utilizar completamente PhishER/PhishER Plus.

#### What Are Recent G2 Reviews of KnowBe4 PhishER/PhishER Plus?

**["PhishER simplifica la revisión de phishing y detiene las amenazas en toda la organización."](https://www.g2.com/es/survey_responses/knowbe4-phisher-phisher-plus-review-13078008)**

**Rating:** 5.0/5.0 stars

_— Weston G._

[Read full review](https://www.g2.com/es/survey_responses/knowbe4-phisher-phisher-plus-review-13078008)

**["Quita la carga de los hombros de TI"](https://www.g2.com/es/survey_responses/knowbe4-phisher-phisher-plus-review-5095561)**

**Rating:** 5.0/5.0 stars

_— Thad E._

[Read full review](https://www.g2.com/es/survey_responses/knowbe4-phisher-phisher-plus-review-5095561)

#### What Are G2 Users Discussing About KnowBe4 PhishER/PhishER Plus?

- [What is phishing explain with example?](https://www.g2.com/es/discussions/what-is-phishing-explain-with-example)
- [Is KnowBe4 com legit?](https://www.g2.com/es/discussions/is-knowbe4-com-legit) - 2 comments
- [¿Qué es KnowBe4 Phish?](https://www.g2.com/es/discussions/what-is-knowbe4-phish) - 1 comment
- [¿Qué es una herramienta de PhishER?](https://www.g2.com/es/discussions/what-is-a-phisher-s-tool) - 4 comments

### [Torq AI SOC Platform](https://www.g2.com/de/products/torq-ai-soc-platform/reviews)

Torq transformiert die Cybersicherheit mit seiner AI-ersten, unternehmensgerechten Hyperautomatisierungsplattform. Durch die Verbindung des gesamten Sicherheitsinfrastruktur-Stacks ermöglicht Torq Organisationen, Sicherheitsereignisse sofort und präzise zu beheben und komplexe Sicherheitsprozesse in großem Maßstab zu orchestrieren. Fortune-500-Unternehmen, einschließlich der weltweit größten Finanz-, Technologie-, Konsumgüter-, Mode-, Gastgewerbe- und Sportbekleidungsunternehmen, erleben außergewöhnliche Ergebnisse mit Torq.

**Average Rating:** 4.8/5.0

**Total Reviews:** 149

#### How Do G2 Users Rate Torq AI SOC Platform?

- **Automatisierte Problembehebung:** 9.2/10 (Category avg: 8.7/10)
- **Support-Qualität:** 9.6/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 9.5/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 9.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Torq AI SOC Platform?

- **Verkäufer:** [torq](https://www.g2.com/de/sellers/torq)
- **Unternehmenswebsite:** torq.io
- **Gründungsjahr:** 2020
- **Hauptsitz:** New York, US
- **Twitter:** @torq\_io  
1,944 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=800db8c967bd21fa299d64109857b8cba3527c19b32691a107e497db33356e88&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftorqio%2Fmycompany&secure%5Burl_type%5D=linkedin_company_website)  
441 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen, Computer- und Netzwerksicherheit
- **Company Size:** 50% Medium, 29% Small

#### What Do G2 Reviewers Say About Torq AI SOC Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Benutzerfreundlichkeit** der Torq AI SOC-Plattform, die mit minimalem Training für alle Fähigkeitsstufen zugänglich ist.
- Benutzer schätzen die **effizienten Netzwerk-Schwachstellenprüfungen** , die die Sicherheit durch Automatisierung und schnelle Behebungsmaßnahmen verbessern.
- Benutzer schätzen die **Automatisierungsfähigkeiten** der Torq AI SOC-Plattform, die Effizienz steigern und Netzwerke effektiv sichern.
- Benutzer heben die **No-Code-Automatisierungsfähigkeiten** von Torq hervor, die Sicherheitsabläufe vereinfachen und die Betriebseffizienz steigern.
- Benutzer schätzen Torqs **effektive Bedrohungserkennung** , die nahtlos in ihre Schwachstellenverwaltung und Netzwerksicherheitsprozesse übergeht und diese verbessert.

##### Cons

- Benutzer stehen vor einer **schwierigen Lernkurve** mit der Torq AI SOC Plattform, die Zeit und Unterstützung für eine effektive Nutzung erfordert.
- Benutzer stehen vor einer erheblichen **Lernkurve** mit der Torq AI SOC-Plattform, die umfangreiche Schulung und Unterstützung für eine effektive Nutzung erfordert.
- Benutzer finden, dass die **fehlenden Funktionen** wie integrierte Playbooks und Widgets das volle Potenzial von Torq AI SOC behindern.
- Benutzer schlagen vor, dass **Verbesserungen bei der Gruppierung von Ergebnissen** und der Integration das Erlebnis der Torq AI SOC-Plattform erheblich verbessern könnten.
- Benutzer stehen vor Herausforderungen mit **schlechtem Schnittstellendesign** , einschließlich fehlerhafter Interaktionen und einer steilen Lernkurve für die Fehlersuche.

#### What Are Recent G2 Reviews of Torq AI SOC Platform?

**["Effiziente Automatisierung mit robusten Integrationen"](https://www.g2.com/de/survey_responses/torq-ai-soc-platform-review-12301239)**

**Rating:** 5.0/5.0 stars

_— Orlando M._

[Read full review](https://www.g2.com/de/survey_responses/torq-ai-soc-platform-review-12301239)

**["Zentralisiertes Vorfallmanagement, das die Erwartungen übertrifft"](https://www.g2.com/de/survey_responses/torq-ai-soc-platform-review-12121506)**

**Rating:** 5.0/5.0 stars

_— Octave P._

[Read full review](https://www.g2.com/de/survey_responses/torq-ai-soc-platform-review-12121506)

### [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)

Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.

**Average Rating:** 4.4/5.0

**Total Reviews:** 68

#### How Do G2 Users Rate Google Security Operations?

- **Automated Remediation:** 9.8/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.1/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Google Security Operations?

- **Seller:** [Google](https://www.g2.com/sellers/google)
- **Year Founded:** 1998
- **HQ Location:** Mountain View, CA
- **Twitter:** @google  
31,899,995 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fe4a5936665c9702418dd53c477fef5a7baea08078bb117ed67e966fc581b9ec&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1441%2F&secure%5Burl_type%5D=linkedin_company_website)  
341,888 employees on LinkedIn®
- **Ownership:** NASDAQ:GOOG

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Telecommunications
- **Company Size:** 41% Medium, 38% Large

#### What Do G2 Reviewers Say About Google Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **excellent cybersecurity features** of Google Security Operations, appreciating its ease of use and scalability.
- Users find Google Security Operations to be **very easy to use** , effectively detecting threats with seamless integration.
- Users appreciate the **efficient threat detection** capabilities of Google Security Operations, enhancing security and response times.
- Users value the **comprehensive security** features of Google Security Operations for effective threat detection and response.
- Users value the **easy integrations** of Google Security Operations, enhancing their overall security management experience.

##### Cons

- Users find Google Security Operations to be **costly and complex** , posing challenges for both setup and ongoing maintenance.
- Users report a **steep learning curve** with Google Security Operations, making effective utilization challenging for some organizations.
- Users find the **implementation complexity** of Google Security Operations challenging, requiring time and resources for effective use.
- Users find the **learning difficulty** of Google Security Operations to be a barrier due to complex features and configuration.
- Users find **limited customization** in Google Security Operations hinders adaptability and affects overall user experience.

#### What Are Recent G2 Reviews of Google Security Operations?

**["Unified Threat Detection and Investigation That Boosts Security Operations Efficiency"](https://www.g2.com/survey_responses/google-security-operations-review-13202286)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13202286)

**["A Reliable Platform for Detecting and Responding to Cyber Threats"](https://www.g2.com/survey_responses/google-security-operations-review-13186617)**

**Rating:** 4.0/5.0 stars

_— Jeni J._

[Read full review](https://www.g2.com/survey_responses/google-security-operations-review-13186617)

### [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews)

ServiceNow Security Operations is a sophisticated software solution designed to enhance threat and vulnerability management as well as incident response for organizations. By leveraging artificial intelligence, this platform empowers security teams to operate more efficiently and effectively, allowing for streamlined collaboration across IT, security, and risk management departments. The primary goal of ServiceNow Security Operations is to simplify complex security processes while minimizing risks associated with cybersecurity threats. Targeted at security teams within organizations of various sizes, ServiceNow Security Operations addresses the need for a cohesive approach to managing security incidents and vulnerabilities. It is particularly beneficial for organizations that utilize multiple security tools, as it integrates security and vulnerability data from these existing systems. This integration enables teams to respond to threats more rapidly by automating critical workflows and processes, thus reducing the manual effort traditionally required in incident response. The platform is suitable for both small businesses and large enterprises, making it a versatile choice for organizations looking to enhance their cybersecurity measures. Key features of ServiceNow Security Operations include intelligent workflows that automate routine tasks, allowing security professionals to focus on more strategic initiatives. The platform’s AI-driven capabilities facilitate the automatic correlation of threat intelligence from diverse sources, such as the MITRE ATT&CK framework. This feature enhances situational awareness and enables teams to prioritize threats effectively based on real-time data. Additionally, the ability to take action within other security or IT management tools from a centralized console streamlines operations, ensuring that teams can respond to incidents without unnecessary delays. This centralized approach not only improves efficiency but also fosters better communication among different departments involved in security management. Moreover, the use of digital security workflows and orchestration significantly accelerates tasks such as analysis, prioritization, and remediation. By automating these processes, organizations can improve their response times and enhance their overall cybersecurity posture. The integration of AI-driven automation within the ServiceNow AI Platform® further strengthens the platform's capabilities, enabling organizations to drive cyber resilience and reduce their exposure to potential threats. This proactive approach to cybersecurity ensures that organizations are not only reacting to incidents but are also prepared to prevent them. ServiceNow Security Operations stands out in the cybersecurity landscape by offering a comprehensive solution that addresses the complexities of modern cybersecurity challenges. By automating and simplifying threat and vulnerability management, it empowers security teams to respond more effectively, thereby enhancing the overall security framework of an organization. This makes it an essential tool for any organization looking to bolster its defenses against the ever-evolving landscape of cyber threats.

**Average Rating:** 4.3/5.0

**Total Reviews:** 79

#### How Do G2 Users Rate ServiceNow Security Operations?

- **Automated Remediation:** 9.0/10 (Category avg: 8.7/10)
- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.6/10)
- **Workflow Automation:** 9.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ServiceNow Security Operations?

- **Seller:** [ServiceNow](https://www.g2.com/sellers/servicenow)
- **Company Website:** www.servicenow.com
- **Year Founded:** 2004
- **HQ Location:** Santa Clara, CA
- **Twitter:** @servicenow  
55,548 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8f146dd2da6255ae21db2f89043b268912043fe250660dfee40ba3c0574bb1ba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F29352%2F&secure%5Burl_type%5D=linkedin_company_website)  
35,081 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 54% Large, 20% Medium

#### What Do G2 Reviewers Say About ServiceNow Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **integration capabilities** of ServiceNow Security Operations, enabling seamless connections with essential third-party tools.
- Users value the **remarkable integration capabilities** of ServiceNow Security Operations, enhancing incident management and data processing efficiency.
- Users appreciate the **ease of use** of ServiceNow Security Operations, enhancing productivity with seamless integration and setup.
- Users value the **robust integration capabilities** of ServiceNow Security Operations, enhancing workflow and incident management efficiency.
- Users appreciate the **end-to-end incident management** capabilities in ServiceNow, making it a comprehensive security solution.

##### Cons

- Users find the **difficult setup** of ServiceNow Security Operations a barrier, impacting overall usability and cost-effectiveness.
- Users face **integration issues** , struggling with field mapping, initial setup, and documentation, affecting overall usability.
- Users find the **restrictive licensing issues** limiting for playbooks, impacting remediation efficiency and security operations.
- Users face **complexity in building playbooks** within ServiceNow Security Operations, finding the process challenging and costly.
- Users find **difficult customization** in ServiceNow Security Operations hinders their ability to effectively build playbooks.

#### What Are Recent G2 Reviews of ServiceNow Security Operations?

**["Centralized Incident Management with Intuitive Dashboard"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)**

**Rating:** 4.0/5.0 stars

_— vignesh m._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)

**["All Security Tools in One Place with Fast, Automated Playbooks"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)**

**Rating:** 4.0/5.0 stars

_— Adam R._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)

#### What Are G2 Users Discussing About ServiceNow Security Operations?

- [What is ServiceNow sir?](https://www.g2.com/discussions/what-is-servicenow-sir)
- [What is service now in cyber security?](https://www.g2.com/discussions/what-is-service-now-in-cyber-security)
- [What are the typical functions of the Security Operations Center SOC analysts?](https://www.g2.com/discussions/what-are-the-typical-functions-of-the-security-operations-center-soc-analysts)
- [What can ServiceNow security operations do?](https://www.g2.com/discussions/what-can-servicenow-security-operations-do)

### [Microsoft Sentinel](https://www.g2.com/de/products/microsoft-sentinel/reviews)

Microsoft Sentinel ermöglicht es Ihnen, Bedrohungen zu erkennen und zu stoppen, bevor sie Schaden anrichten, mit SIEM, das für eine moderne Welt neu erfunden wurde. Microsoft Sentinel bietet Ihnen einen Überblick über das gesamte Unternehmen. Nutzen Sie die Cloud und die groß angelegte Intelligenz aus jahrzehntelanger Microsoft-Sicherheitserfahrung. Machen Sie Ihre Bedrohungserkennung und -reaktion intelligenter und schneller mit künstlicher Intelligenz (KI). Beseitigen Sie die Einrichtung und Wartung der Sicherheitsinfrastruktur und skalieren Sie elastisch, um Ihre Sicherheitsanforderungen zu erfüllen, während Sie die IT-Kosten senken. Mit Microsoft Sentinel können Sie: - Daten in Cloud-Maßstab sammeln – über alle Benutzer, Geräte, Anwendungen und Infrastrukturen hinweg, sowohl vor Ort als auch in mehreren Clouds - Zuvor unentdeckte Bedrohungen erkennen und Fehlalarme minimieren, indem Sie Analysen und unvergleichliche Bedrohungsinformationen von Microsoft nutzen - Bedrohungen mit KI untersuchen und verdächtige Aktivitäten in großem Maßstab aufspüren, indem Sie auf jahrzehntelange Cybersecurity-Arbeit bei Microsoft zurückgreifen

**Average Rating:** 4.4/5.0

**Total Reviews:** 273

#### How Do G2 Users Rate Microsoft Sentinel?

- **Automatisierte Problembehebung:** 8.7/10 (Category avg: 8.7/10)
- **Support-Qualität:** 8.5/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 8.3/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 8.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Microsoft Sentinel?

- **Verkäufer:** [Microsoft](https://www.g2.com/de/sellers/microsoft)
- **Gründungsjahr:** 1975
- **Hauptsitz:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** MSFT

#### Who Uses This Product?

- **Who Uses This:** Sicherheitsanalyst, Senior Software Engineer
- **Top Industries:** Informationstechnologie und Dienstleistungen, Computer- und Netzwerksicherheit
- **Company Size:** 42% Large, 31% Medium

#### What Do G2 Reviewers Say About Microsoft Sentinel?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Echtzeitüberwachung** von Microsoft Sentinel, da sie ihre Fähigkeit zur schnellen Reaktion auf Sicherheitsbedrohungen verbessert.
- Benutzer schätzen die **automatisierte Alarmreaktion** von Microsoft Sentinel, die durch zentrale Sicherheitsüberwachung für Beruhigung sorgt.
- Benutzer schätzen die **nahtlose Benutzerfreundlichkeit des Dashboards** von Microsoft Sentinel, die eine intuitive Sicherheitsverwaltung und umfassende Überwachung erleichtert.
- Benutzer schätzen die **schnelle und sichere Bedrohungsreaktion** von Microsoft Sentinel, die die allgemeine Sicherheit und das Risikomanagement verbessert.
- Benutzer profitieren von der **nahtlosen Datenverwaltung** von Microsoft Sentinel, die den Arbeitsablauf verbessert und umfassende Sicherheitsanalysen gewährleistet.

##### Cons

- Benutzer äußern Bedenken hinsichtlich der **Cloud-Abhängigkeit** , insbesondere in Bezug auf Verbindungsprobleme mit langsamen Internetverbindungen und kommerzielle Abhängigkeit.
- Benutzer finden die **komplexe Konfiguration** von Microsoft Sentinel herausfordernd, da sie fortgeschrittene technische Fähigkeiten für eine effektive Einrichtung und Nutzung erfordert.
- Benutzer stehen vor **Konfigurationsproblemen** mit Microsoft Sentinel, was technisches Fachwissen und Zeit für eine effektive Einrichtung erfordert.
- Benutzer finden die **schwierige Einrichtung** von Microsoft Sentinel herausfordernd ohne dedizierte Sicherheitsexperten und angemessene Schulung.
- Benutzer kämpfen mit dem **schlechten Schnittstellendesign** von Microsoft Sentinel, was die Navigation und das Verständnis der Funktionen erschwert.

#### What Are Recent G2 Reviews of Microsoft Sentinel?

**["Einfache Protokollaufnahme über Formate hinweg mit nahtlosen Sentinel-Integrationen"](https://www.g2.com/de/survey_responses/microsoft-sentinel-review-13073395)**

**Rating:** 4.5/5.0 stars

_— Sandip K._

[Read full review](https://www.g2.com/de/survey_responses/microsoft-sentinel-review-13073395)

**["Starke zentralisierte Sichtbarkeit und skalierbare Erkennung für schnellere SOC-Reaktion"](https://www.g2.com/de/survey_responses/microsoft-sentinel-review-12823175)**

**Rating:** 4.5/5.0 stars

_— Verifizierter Benutzer in Informationstechnologie und Dienstleistungen_

[Read full review](https://www.g2.com/de/survey_responses/microsoft-sentinel-review-12823175)

#### What Are G2 Users Discussing About Microsoft Sentinel?

- [Wofür wird Microsoft Sentinel verwendet?](https://www.g2.com/de/discussions/what-is-microsoft-sentinel-used-for) - 3 comments, 2 upvotes
- [Warum sollte ich Azure Sentinel verwenden?](https://www.g2.com/de/discussions/why-should-i-use-azure-sentinel) - 1 comment
- [Which feature provides the extended detection and response capabilities of Azure Sentinel?](https://www.g2.com/de/discussions/which-feature-provides-the-extended-detection-and-response-capabilities-of-azure-sentinel)
- [What is the difference between Azure security Center and Azure Sentinel?](https://www.g2.com/de/discussions/what-is-the-difference-between-azure-security-center-and-azure-sentinel)
- [What does Azure Sentinel provide?](https://www.g2.com/de/discussions/what-does-azure-sentinel-provide)

### [Check Point Infinity Platform](https://www.g2.com/de/products/check-point-infinity-platform/reviews)

Check Point Infinity ist die einzige vollständig konsolidierte Cybersicherheitsarchitektur, die beispiellosen Schutz gegen Gen V Mega-Cyberangriffe sowie zukünftige Cyberbedrohungen über alle Netzwerke, Endpunkte, Cloud und Mobilgeräte bietet. Die Architektur ist darauf ausgelegt, die Komplexität wachsender Konnektivität und ineffizienter Sicherheit zu lösen.

**Average Rating:** 4.6/5.0

**Total Reviews:** 109

#### How Do G2 Users Rate Check Point Infinity Platform?

- **Support-Qualität:** 8.8/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 8.6/10 (Category avg: 8.6/10)

#### Who Is the Company Behind Check Point Infinity Platform?

- **Verkäufer:** [Check Point Software Technologies](https://www.g2.com/de/sellers/check-point-software-technologies)
- **Gründungsjahr:** 1993
- **Hauptsitz:** Redwood City, CA
- **Twitter:** @CheckPointSW  
70,955 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d885813f6605ba84238ae4a21d169e0c9ade054cf0c99ff53e72483b54a8b521&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheck-point-software-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,554 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NASDAQ:CHKP

#### Who Uses This Product?

- **Top Industries:** Computer- und Netzwerksicherheit, Informationstechnologie und Dienstleistungen
- **Company Size:** 44% Large, 37% Medium

#### What Do G2 Reviewers Say About Check Point Infinity Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **fortschrittlichen Sicherheitsfunktionen** der Check Point Infinity Plattform, die einen robusten Schutz gegen zukünftige Angriffe gewährleisten.
- Benutzer schätzen die **Cloud-Sicherheitsfunktionen** der Check Point Infinity Platform, die effiziente Sicherheitsprüfungen und Infrastrukturbewertungen gewährleisten.
- Benutzer schätzen die **proaktiven Bedrohungserkennungs** funktionen der Check Point Infinity Plattform, die die Sicherheit für Cloud-Anwendungen verbessern.
- Benutzer schätzen die **umfassenden Sicherheits** funktionen der Check Point Infinity Plattform, die einen robusten Schutz gegen Bedrohungen aus der Cloud gewährleisten.
- Benutzer schätzen die **fortschrittlichen Cloud-Sicherheitsfunktionen** der Check Point Infinity Plattform, die einen robusten Schutz gegen zukünftige Angriffe gewährleisten.

##### Cons

- Benutzer finden die **steile Lernkurve** herausfordernd aufgrund der komplexen Einrichtung und des Mangels an umfassender Dokumentation.
- Benutzer finden, dass die **Komplexität** der Einstellungen und Dokumentation der Check Point Infinity Platform die Benutzerfreundlichkeit und Effizienz beeinträchtigen kann.
- Benutzer finden, dass **Verbesserungen erforderlich sind** bei der Unterstützung und Sichtbarkeit von nativen Servern in Check Point-Protokollen.
- Benutzer finden **schlechte Supportdienste** schädlich und heben die Notwendigkeit für verbesserte Kundenunterstützung und Protokollsichtbarkeit hervor.
- Benutzer stehen **begrenzte Anpassungsmöglichkeiten** für Regelwerke und Metriken zur Verfügung, was detaillierte Bewertungen erschwert.

#### What Are Recent G2 Reviews of Check Point Infinity Platform?

**["Ausgezeichnete Option Harmony Platform für Sicherheitszentrale"](https://www.g2.com/de/survey_responses/check-point-infinity-platform-review-11868343)**

**Rating:** 4.5/5.0 stars

_— Tania V._

[Read full review](https://www.g2.com/de/survey_responses/check-point-infinity-platform-review-11868343)

**["Nahtlose hybride Sicherheitsintegration in allen Umgebungen"](https://www.g2.com/de/survey_responses/check-point-infinity-platform-review-11954684)**

**Rating:** 4.5/5.0 stars

_— Sonu S._

[Read full review](https://www.g2.com/de/survey_responses/check-point-infinity-platform-review-11954684)

#### What Are G2 Users Discussing About Check Point Infinity Platform?

- [How does Check Point Infinity help customers?](https://www.g2.com/de/discussions/how-does-check-point-infinity-help-customers)
- [What are the benefits of Check Point unified security architecture?](https://www.g2.com/de/discussions/what-are-the-benefits-of-check-point-unified-security-architecture)
- [What are the 4 components of the Infinity architecture?](https://www.g2.com/de/discussions/what-are-the-4-components-of-the-infinity-architecture)
- [What is Infinity Total protection?](https://www.g2.com/de/discussions/what-is-infinity-total-protection)

### [Palo Alto Networks Cortex XSOAR](https://www.g2.com/de/products/palo-alto-networks-cortex-xsoar/reviews)

Cortex XSOAR von Palo Alto Networks ist eine umfassende Plattform für Security Orchestration, Automation und Response (SOAR), die darauf ausgelegt ist, Sicherheitsoperationen zu optimieren und zu verbessern. Durch die Integration von Automatisierung, Fallmanagement, Echtzeit-Zusammenarbeit und Bedrohungsinformationsmanagement befähigt Cortex XSOAR Sicherheitsteams, effizienter und effektiver auf Vorfälle zu reagieren. Hauptmerkmale und Funktionalität: - Prozessstandardisierung und Automatisierung: Cortex XSOAR bietet über 270 einsatzbereite Playbooks, die die Automatisierung zahlreicher Sicherheitsanwendungsfälle ermöglichen. Diese Playbooks orchestrieren Reaktionsmaßnahmen über mehr als 350 Drittanbieterprodukte hinweg und erleichtern nahtlose Integration und betriebliche Konsistenz. - Sicherheitsorientiertes Fallmanagement: Die Plattform vereint Warnungen, Vorfälle und Indikatoren aus verschiedenen Quellen in einem einzigen Fallmanagement-Framework. Diese Konsolidierung beschleunigt die Vorfallreaktion, indem sie einen umfassenden Überblick über Sicherheitsereignisse bietet. - Echtzeit-Zusammenarbeit: Cortex XSOAR umfasst einen virtuellen War Room mit integriertem ChatOps und einer Befehlszeilenschnittstelle. Diese Funktion ermöglicht es Sicherheitsteams, in Echtzeit zusammenzuarbeiten, Befehle über den gesamten Produktstapel hinweg auszuführen und Vorfälle effektiver zu verwalten. - Bedrohungsinformationsmanagement: Die Plattform aggregiert unterschiedliche Bedrohungsinformationsquellen, passt Feeds an und bewertet sie und gleicht Indikatoren mit der spezifischen Umgebung der Organisation ab. Diese Fähigkeit ermöglicht es Sicherheitsteams, schnell fundierte Maßnahmen zu ergreifen. Primärer Wert und Problemlösung: Cortex XSOAR adressiert die Herausforderungen, denen sich Sicherheitsteams gegenübersehen, wie das überwältigende Volumen an Warnungen und die Notwendigkeit einer schnellen Vorfallreaktion. Durch die Automatisierung sich wiederholender Aufgaben und die Standardisierung von Prozessen reduziert die Plattform die für Vorfälle aufgewendete Zeit um bis zu 90 %, sodass Analysten sich auf kritische Bedrohungen konzentrieren können. Die Integration des Bedrohungsinformationsmanagements mit SOAR-Funktionen stellt sicher, dass Organisationen Bedrohungsfeeds effektiv operationalisieren können, was ihre allgemeine Sicherheitslage verbessert. Darüber hinaus ermöglicht das umfangreiche Integrationsökosystem der Plattform mit über 360 Drittanbieterintegrationen Organisationen, komplexe Workflows über ihre bestehende Sicherheitsinfrastruktur hinweg zu orchestrieren, ohne umfangreiche kundenspezifische Entwicklungen.

**Average Rating:** 4.6/5.0

**Total Reviews:** 28

#### How Do G2 Users Rate Palo Alto Networks Cortex XSOAR?

- **Automatisierte Problembehebung:** 9.0/10 (Category avg: 8.7/10)
- **Support-Qualität:** 8.5/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 8.9/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 8.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Palo Alto Networks Cortex XSOAR?

- **Verkäufer:** [Palo Alto Networks](https://www.g2.com/de/sellers/palo-alto-networks)
- **Gründungsjahr:** 2005
- **Hauptsitz:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NYSE: PANW

#### Who Uses This Product?

- **Top Industries:** Computer- und Netzwerksicherheit
- **Company Size:** 50% Large, 32% Medium

#### What Do G2 Reviewers Say About Palo Alto Networks Cortex XSOAR?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **leistungsstarken Automatisierungs** fähigkeiten von Cortex XSOAR, die die Effizienz und Anpassung der Vorfallreaktion verbessern.
- Benutzer genießen die **großartige Benutzeroberfläche** von Palo Alto Networks Cortex XSOAR, die die Benutzerfreundlichkeit und Anpassungsmöglichkeiten erheblich verbessert.
- Benutzer bewundern die **Genauigkeit der Informationen** in Palo Alto Networks Cortex XSOAR, was die Sicherheit und Effizienz in den Abläufen verbessert.
- Benutzer schätzen die **leistungsstarken Automatisierungs** fähigkeiten von Cortex XSOAR für ein effizientes Vorfallmanagement.
- Benutzer schätzen den **direkten Kundensupport** von Palo Alto Networks Cortex XSOAR, was ihr Gesamterlebnis verbessert.

##### Cons

- Benutzer finden die **Lernkurve steil** , was erheblichen Zeit- und Arbeitsaufwand erfordert, um die Komplexität von Cortex XSOAR effektiv zu bewältigen.
- Benutzer empfinden, dass die **begrenzten Anpassungsmöglichkeiten** das gesamte Berichtserlebnis in Cortex XSOAR beeinträchtigen.
- Benutzer finden, dass **Protokollierungsprobleme** durch schwer lesbare Datenprotokolle entstehen, die zur Klarheit in einem neuen Tab geöffnet werden müssen.
- Benutzer finden **Probleme mit der Protokollverwaltung** frustrierend, da das schnelle Lesen von Datenprotokollen aufgrund von Fenstergrößenbeschränkungen schwierig ist.
- Benutzer finden die **Berichterstattung unzureichend** und wünschen sich erweiterte Anpassungsoptionen für ein besseres Erlebnis.

#### What Are Recent G2 Reviews of Palo Alto Networks Cortex XSOAR?

**["Leistungsstarkes Werkzeug mit sauberen Daten und nahtlosen Integrationen"](https://www.g2.com/de/survey_responses/palo-alto-networks-cortex-xsoar-review-11967977)**

**Rating:** 5.0/5.0 stars

_— Pablo V._

[Read full review](https://www.g2.com/de/survey_responses/palo-alto-networks-cortex-xsoar-review-11967977)

**["Freischaltung der Automatisierung von Sicherheitsoperationen mit Cortex XSOAR"](https://www.g2.com/de/survey_responses/palo-alto-networks-cortex-xsoar-review-10447892)**

**Rating:** 5.0/5.0 stars

_— Jai P._

[Read full review](https://www.g2.com/de/survey_responses/palo-alto-networks-cortex-xsoar-review-10447892)

#### What Are G2 Users Discussing About Palo Alto Networks Cortex XSOAR?

- [Wofür wird Palo Alto Networks Cortex XSOAR verwendet?](https://www.g2.com/de/discussions/what-is-palo-alto-networks-cortex-xsoar-used-for)

### [Palo Alto Cortex XSIAM](https://www.g2.com/de/products/palo-alto-cortex-xsiam/reviews)

Produktbeschreibung: Cortex XSIAM von Palo Alto Networks ist eine KI-gesteuerte Sicherheitsoperationsplattform, die darauf ausgelegt ist, traditionelle Security Operations Centers zu transformieren, indem sie zentrale Funktionen wie Datenzentralisierung, Bedrohungserkennung und Vorfallreaktion integriert und automatisiert. Durch den Einsatz von maschinellem Lernen und Automatisierung ermöglicht sie es Organisationen, Bedrohungen effizienter zu erkennen und darauf zu reagieren, manuelle Arbeitslasten zu reduzieren und die allgemeine Sicherheitslage zu verbessern. Hauptmerkmale und Funktionalität: - Datenzentralisierung: Aggregiert Daten aus verschiedenen Quellen in einer einheitlichen Plattform und bietet umfassende Sichtbarkeit im gesamten Unternehmen. - KI-gestützte Bedrohungserkennung: Nutzt maschinelle Lernalgorithmen, um Anomalien und potenzielle Bedrohungen in Echtzeit zu identifizieren. - Automatisierte Vorfallreaktion: Optimiert Reaktionsprozesse durch Automatisierung und ermöglicht eine schnelle Eindämmung von Sicherheitsvorfällen. - Integrierte SOC-Fähigkeiten: Kombiniert Funktionen wie Extended Detection and Response, Security Orchestration, Automation, and Response, Attack Surface Management und Security Information and Event Management in einer kohärenten Plattform und eliminiert die Notwendigkeit für mehrere unterschiedliche Tools. - Skalierbarkeit: Entwickelt, um große Datenmengen zu verarbeiten und sich an die sich entwickelnden Bedürfnisse moderner Unternehmen anzupassen. Primärer Wert und gelöstes Problem: Cortex XSIAM adressiert die Herausforderungen von fragmentierten Daten, schwacher Bedrohungsabwehr und starker Abhängigkeit von manueller Arbeit in traditionellen SOCs. Durch die Zentralisierung von Daten und die Automatisierung von Sicherheitsoperationen vereinfacht es Prozesse, verbessert die Genauigkeit der Bedrohungserkennung und beschleunigt die Reaktionszeiten bei Vorfällen. Diese Transformation ermöglicht es Organisationen, Bedrohungen proaktiv zu überholen, Betriebskosten zu senken und eine robustere Sicherheitslage zu erreichen.

**Average Rating:** 4.5/5.0

**Total Reviews:** 83

#### How Do G2 Users Rate Palo Alto Cortex XSIAM?

- **Automatisierte Problembehebung:** 7.3/10 (Category avg: 8.7/10)
- **Support-Qualität:** 8.5/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 8.1/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 7.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Palo Alto Cortex XSIAM?

- **Verkäufer:** [Palo Alto Networks](https://www.g2.com/de/sellers/palo-alto-networks)
- **Unternehmenswebsite:** www.paloaltonetworks.com
- **Gründungsjahr:** 2005
- **Hauptsitz:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen, Computer- und Netzwerksicherheit
- **Company Size:** 44% Large, 37% Medium

#### What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer heben **erstklassiges Log-Management** und effektive Alarmierungsfunktionen hervor, die die allgemeine Benutzerfreundlichkeit und Integration verbessern.
- Benutzer schätzen die **benutzerfreundlichen Dashboards** von Palo Alto Cortex XSIAM, die die einfache Verständlichkeit von Warnungen und Metriken hervorheben.
- Benutzer schätzen die **Echtzeitüberwachungs** fähigkeiten von Palo Alto Cortex XSIAM, die die Effizienz der Bedrohungserkennung und -reaktion verbessern.
- Benutzer schätzen die **benutzerfreundliche Oberfläche** von Palo Alto Cortex XSIAM, die Überwachung und Bereitstellung nahtlos und effizient macht.
- Benutzer schätzen die **gute Dashboard-Anpassung** in Palo Alto Cortex XSIAM und erwähnen die Benutzerfreundlichkeit und Integration.

##### Cons

- Benutzer finden die Lösung **ressourcenintensiv** , was die Kosten erhöht und die Implementierung aufgrund hoher Hardwareanforderungen kompliziert macht.
- Benutzer finden die **komplexe Implementierung** von Palo Alto Cortex XSIAM zeitaufwändig und ressourcenintensiv, was erhebliche technische Fachkenntnisse erfordert.
- Benutzer finden die **Kosten** von Palo Alto Cortex XSIAM höher als die der Konkurrenz, was die Erschwinglichkeit für kleinere Unternehmen beeinträchtigt.
- Benutzer berichten von **Dashboard-Problemen** , die das Monitoring behindern und eine unübersichtliche Oberfläche schaffen, was die Benutzerfreundlichkeit und Sichtbarkeit beeinträchtigt.
- Benutzer haben Schwierigkeiten mit der **schwierigen Einrichtung** von Palo Alto Cortex XSIAM und finden sie komplex und zeitaufwändig in der Implementierung.

#### What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

**["Effiziente Sicherheitsüberwachung mit leistungsstarker Automatisierung"](https://www.g2.com/de/survey_responses/palo-alto-cortex-xsiam-review-13129157)**

**Rating:** 4.0/5.0 stars

_— Anas M._

[Read full review](https://www.g2.com/de/survey_responses/palo-alto-cortex-xsiam-review-13129157)

**["Palo Alto Cortex XSIAM: Zentralisierte Sicherheit mit leistungsstarker KI-Automatisierung"](https://www.g2.com/de/survey_responses/palo-alto-cortex-xsiam-review-13174734)**

**Rating:** 4.5/5.0 stars

_— Tim H._

[Read full review](https://www.g2.com/de/survey_responses/palo-alto-cortex-xsiam-review-13174734)

#### What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

- [Wofür wird IBM Security ReaQta verwendet?](https://www.g2.com/de/discussions/what-is-ibm-security-reaqta-used-for) - 1 comment
- [What does QRadar stand for?](https://www.g2.com/de/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
- [Wie benutze ich IBM QRadar?](https://www.g2.com/de/discussions/how-do-i-use-ibm-qradar) - 1 comment
- [Was sind die Hauptkomponenten von IBM QRadar?](https://www.g2.com/de/discussions/what-are-the-key-component-of-ibm-qradar) - 1 comment
- [Was ist IBM QRadar Siem?](https://www.g2.com/de/discussions/what-is-ibm-qradar-siem) - 1 comment

### [Barracuda Incident Response](https://www.g2.com/de/products/barracuda-incident-response/reviews)

Keine E-Mail-Abwehrtechnologie kann zu 100 Prozent der Zeit vor immer fortschrittlicheren E-Mail-Bedrohungen schützen. Einige fortschrittliche Social-Engineering-Angriffe wie Business Email Compromise werden die Postfächer der Benutzer erreichen. Und wenn dies geschieht, müssen Sie schnell und genau reagieren, um das Ausmaß und die Schwere des Schadens zu minimieren. Barracuda Incident Response ermöglicht es Ihnen, schnell und effektiv auf Bedrohungen zu reagieren, indem es Untersuchungsabläufe automatisiert und die direkte Entfernung bösartiger E-Mails ermöglicht.

**Average Rating:** 4.5/5.0

**Total Reviews:** 16

#### How Do G2 Users Rate Barracuda Incident Response?

- **Automatisierte Problembehebung:** 9.2/10 (Category avg: 8.7/10)
- **Support-Qualität:** 9.4/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 9.6/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Barracuda Incident Response?

- **Verkäufer:** [Barracuda](https://www.g2.com/de/sellers/barracuda)
- **Gründungsjahr:** 2002
- **Hauptsitz:** Campbell, CA
- **Twitter:** @Barracuda  
15,239 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f781b15d43db259998c089a305a16438e46ef7f458b40ed200cb81a2a683bea5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbarracuda-networks%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,248 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** Private

#### Who Uses This Product?

- **Company Size:** 50% Medium, 25% Large

#### What Do G2 Reviewers Say About Barracuda Incident Response?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die Funktion zur **sofortigen Entfernung von E-Mail-Bedrohungen** , die eine schnelle Lösung und ein verbessertes Sicherheitsmanagement ermöglicht.
- Benutzer heben die **wesentlichen Schutz- und Untersuchungskapazitäten** von Barracuda Incident Response als entscheidend für die Cybersicherheit hervor.
- Benutzer schätzen die **E-Mail-Such- und Entfernungsfunktion** , die die Kontrolle über den Posteingang mühelos verbessert.
- Benutzer finden Barracuda Incident Response als ein **unverzichtbares Werkzeug** für effektive E-Mail-Bereinigung und Untersuchung.
- Benutzer schätzen die **sofortige Entfernung von E-Mail-Bedrohungen** der Barracuda Incident Response, die potenzielle Risiken effektiv mindert.

##### Cons

- Benutzer wünschen sich, dass die **E-Mail-Blockierungsfunktion** auf alle Gateway-Ebenen angewendet wird, um eine effizientere Verwaltung zu ermöglichen.

#### What Are Recent G2 Reviews of Barracuda Incident Response?

**["Sofortige Entfernung von E-Mail-Bedrohungen, die einen großen Unterschied macht"](https://www.g2.com/de/survey_responses/barracuda-incident-response-review-12340166)**

**Rating:** 4.5/5.0 stars

_— Jose C._

[Read full review](https://www.g2.com/de/survey_responses/barracuda-incident-response-review-12340166)

**["Erstaunliches Produkt"](https://www.g2.com/de/survey_responses/barracuda-incident-response-review-12337161)**

**Rating:** 5.0/5.0 stars

_— Peter E._

[Read full review](https://www.g2.com/de/survey_responses/barracuda-incident-response-review-12337161)

#### What Are G2 Users Discussing About Barracuda Incident Response?

- [Wofür wird Barracuda Incident Response verwendet?](https://www.g2.com/de/discussions/what-is-barracuda-incident-response-used-for)

### [Proofpoint Threat Response](https://www.g2.com/de/products/proofpoint-threat-response/reviews)

Proofpoint Threat Response nimmt die manuelle Arbeit und das Rätselraten aus der Vorfallreaktion, um Ihnen zu helfen, Bedrohungen schneller und effizienter zu lösen.

**Average Rating:** 4.6/5.0

**Total Reviews:** 17

#### How Do G2 Users Rate Proofpoint Threat Response?

- **Automatisierte Problembehebung:** 9.0/10 (Category avg: 8.7/10)
- **Support-Qualität:** 8.8/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 9.3/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Proofpoint Threat Response?

- **Verkäufer:** [Proofpoint](https://www.g2.com/de/sellers/proofpoint)
- **Gründungsjahr:** 2002
- **Hauptsitz:** Sunnyvale, CA
- **Twitter:** @proofpoint  
31,157 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9ffe74895a6dd57f2366e3788b5672d95f77f75231d2b11c49b36c398e662c8d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fproofpoint&secure%5Burl_type%5D=linkedin_company_website)  
5,146 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NASDAQ: PFPT

#### Who Uses This Product?

- **Company Size:** 56% Medium, 22% Large

#### What Do G2 Reviewers Say About Proofpoint Threat Response?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **automatisierte Rückholung verdächtiger E-Mails** in Proofpoint Threat Response für verbesserte E-Mail-Sicherheit.
- Benutzer schätzen den **automatisierten Rückruf verdächtiger E-Mails** , was die Sicherheit erhöht und das Risiko effektiv reduziert.
- Benutzer schätzen den **automatischen Rückruf verdächtiger E-Mails** , was ihre Bemühungen zur Phishing-Prävention effektiv verbessert.
- Benutzer schätzen die **umfassenden Sicherheitswerkzeuge** von Proofpoint Threat Response, die ihre Unternehmen effektiv schützen.
- Benutzer schätzen die **umfassenden Bedrohungserkennungstools** von Proofpoint, die die Sicherheit ihres Unternehmens verbessern.

##### Cons

- Benutzer berichten von häufigen **falsch positiven** Ergebnissen in der E-Mail-Verwaltung, was zur Rückruf und zum Austausch von Hunderten von E-Mails führt.
- Benutzer berichten von **zahlreichen Fehlalarmen** , die erhebliche Störungen bei E-Mail-Rückrufen und -Ersatz verursachen.
- Benutzer finden die **Lernkurve steil** , obwohl reichlich Schulung und Unterstützung verfügbar sind, um den Prozess zu erleichtern.

#### What Are Recent G2 Reviews of Proofpoint Threat Response?

**["Schnelle Warnungen und klare, detaillierte Zusammenfassungen für verdächtige E-Mails"](https://www.g2.com/de/survey_responses/proofpoint-threat-response-review-12478488)**

**Rating:** 5.0/5.0 stars

_— Casey M._

[Read full review](https://www.g2.com/de/survey_responses/proofpoint-threat-response-review-12478488)

**["Es braucht Zeit zu lernen, aber ein großartiges Produkt!"](https://www.g2.com/de/survey_responses/proofpoint-threat-response-review-9471662)**

**Rating:** 4.0/5.0 stars

_— Joshua B._

[Read full review](https://www.g2.com/de/survey_responses/proofpoint-threat-response-review-9471662)

### [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/de/products/splunk-soar-security-orchestration-automation-and-response/reviews)

Splunk SOAR bietet Sicherheitsorchestrierung, Automatisierung und Reaktionsfähigkeiten, die es Sicherheitsanalysten ermöglichen, intelligenter zu arbeiten, indem sie sich wiederholende Aufgaben automatisieren; schneller auf Sicherheitsvorfälle reagieren mit automatisierter Erkennung, Untersuchung und Reaktion; Produktivität, Effizienz und Genauigkeit steigern; und die Abwehr stärken, indem komplexe Arbeitsabläufe im Team und mit den Tools verbunden und koordiniert werden. Splunk SOAR unterstützt auch eine breite Palette von Funktionen des Security Operations Center (SOC), einschließlich Ereignis- und Fallmanagement, integrierte Bedrohungsinformationen, Kollaborationstools und Berichterstattung.

**Average Rating:** 4.4/5.0

**Total Reviews:** 40

#### How Do G2 Users Rate Splunk SOAR (Security Orchestration, Automation and Response)?

- **Automatisierte Problembehebung:** 8.6/10 (Category avg: 8.7/10)
- **Support-Qualität:** 8.8/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 8.1/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Splunk SOAR (Security Orchestration, Automation and Response)?

- **Verkäufer:** [Cisco](https://www.g2.com/de/sellers/cisco)
- **Gründungsjahr:** 1984
- **Hauptsitz:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NASDAQ:CSCO

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen, Beratung
- **Company Size:** 41% Medium, 34% Large

#### What Do G2 Reviewers Say About Splunk SOAR (Security Orchestration, Automation and Response)?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Automatisierungsfähigkeiten** von Splunk SOAR, die die Sicherheit und Reaktionsfähigkeit dramatisch verbessern.
- Benutzer schätzen das **effektive Vorfallmanagement** von Splunk SOAR, das die Sicherheitsreaktion und Automatisierung in ihren Arbeitsabläufen verbessert.
- Benutzer schätzen die **Flexibilität und Integration** von Splunk SOAR, die eine nahtlose Workflow-Orchestrierung für verbesserte Sicherheit ermöglicht.
- Benutzer schätzen die **einfache Bedrohungserkennung** von Splunk SOAR, die die Effizienz der Sicherheitsanalyse und -reaktion verbessert.
- Benutzer schätzen die **Benutzerfreundlichkeit** von Splunk SOAR und loben seine intuitive Benutzeroberfläche und nahtlosen Integrationsmöglichkeiten.

##### Cons

- Benutzer finden die **hohen Kosten** von Splunk SOAR abschreckend, was es durchschnittlichen Benutzern schwer macht, es sich zu leisten.
- Benutzer finden die **Lernkurve steil** , was umfangreiches Wissen und Training erfordert, um Splunk SOAR effektiv zu nutzen.
- Benutzer finden die **schwierige Lernkurve** herausfordernd, insbesondere für Anfänger, die neu in Automatisierungsplattformen sind.
- Benutzer finden die **Komplexität** von Splunk SOAR herausfordernd, was umfangreiches Lernen für eine effektive Nutzung erfordert.
- Benutzer finden das **schlechte Schnittstellendesign** von Splunk SOAR herausfordernd, insbesondere für diejenigen, die neu in Automatisierungsplattformen sind.

#### What Are Recent G2 Reviews of Splunk SOAR (Security Orchestration, Automation and Response)?

**["Umfassende SOC-Automatisierung mit Splunk SOAR"](https://www.g2.com/de/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-13157846)**

**Rating:** 4.5/5.0 stars

_— Verifizierter Benutzer in Informationstechnologie und Dienstleistungen_

[Read full review](https://www.g2.com/de/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-13157846)

**["Splunk SOAR ist eine gute Software für Automatisierung."](https://www.g2.com/de/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)**

**Rating:** 5.0/5.0 stars

_— Dheeraj T._

[Read full review](https://www.g2.com/de/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)

#### What Are G2 Users Discussing About Splunk SOAR (Security Orchestration, Automation and Response)?

- [Wofür wird Splunk SOAR (Security Orchestration, Automation and Response) verwendet?](https://www.g2.com/de/discussions/what-is-splunk-soar-security-orchestration-automation-and-response-used-for)

### [Blink](https://www.g2.com/de/products/blink-ops-blink/reviews)

Automatisieren Sie Alles Sicherheit im Augenblick der KI Blink ist eine Plattform zur Automatisierung von Sicherheits-Workflows, die darauf ausgelegt ist, alles rund um Sicherheit und darüber hinaus mühelos mit generativer KI zu gestalten, zu kollaborieren und zu skalieren. Egal, ob Sie Code, Low-Code oder No-Code bevorzugen, Blink hat alles, was Sie brauchen. Ziehen Sie einfach die gewünschten Aktionen in einen Workflow und nutzen Sie die über 30.000 Integrationen, die in der Automatisierungsbibliothek verfügbar sind, oder verwenden Sie Blink Copilot, um mit einem natürlichen Sprachbefehl einen Workflow zu generieren. Nutzen Sie Blink als Automatisierungs-Hub, wo Sicherheitsteams schnell ihre Sicherheitsideen entwickeln, zusammenarbeiten und automatisieren können. Nutzen Sie die über 10.000 Workflows der Plattform, die sofort einsatzbereit sind, um schnell Workflows für die Echtzeitbehebung zu erstellen. Generieren Sie Automatisierungs-Workflows für eigenständige Anwendungsfälle oder entwickeln Sie eine umfassende proaktive Automatisierungsstrategie, die Sicherheitsreaktionen in Ihrer gesamten Organisation optimiert.

**Average Rating:** 4.7/5.0

**Total Reviews:** 19

#### How Do G2 Users Rate Blink?

- **Automatisierte Problembehebung:** 9.0/10 (Category avg: 8.7/10)
- **Support-Qualität:** 9.8/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 9.5/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Blink?

- **Verkäufer:** [Blink Ops](https://www.g2.com/de/sellers/blink-ops)
- **Unternehmenswebsite:** www.blinkops.com
- **Gründungsjahr:** 2021
- **Hauptsitz:** Austin, US
- **Twitter:** @getBlinkOps  
706 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0e65f853537ff0ed09ad1f58bf9582d05c18ee23890cc577cf275f7f98b6d61a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblink-ops%2F&secure%5Burl_type%5D=linkedin_company_website)  
126 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computersoftware
- **Company Size:** 63% Medium, 21% Large

#### What Do G2 Reviewers Say About Blink?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Benutzerfreundlichkeit** von Blink, die eine schnelle und zufriedenstellende Einrichtung für eine effektive Projektausführung erleichtert.
- Benutzer schätzen die **Automatisierungsfähigkeiten** von Blink und vermerken signifikante Ergebnisse sowie eine verbesserte Sicherheitsorchestrierung.
- Benutzer loben den **reaktionsschnellen Kundensupport** von Blink, was das Gesamterlebnis und die Effektivität des Produkts verbessert.
- Benutzer schätzen die **einfache Einrichtung** von Blink, die einen nahtlosen Start ermöglicht und ihr Gesamterlebnis verbessert.
- Benutzer schätzen die **reibungslose JavaScript-Ausführung** von Blink, die die Effizienz und Kompatibilität von Webprojekten verbessert.

##### Cons

- Benutzer identifizieren **begrenzte Erweiterbarkeit** in Blink, was insbesondere große und komplexe Projektabläufe betrifft.
- Benutzer finden die **begrenzte Erweiterbarkeit** von Blink problematisch, insbesondere für große und komplexe Projektanforderungen.

#### What Are Recent G2 Reviews of Blink?

**["Zusammenarbeit mit Blink, mit Schwerpunkt auf Ergebnissen statt Möglichkeiten."](https://www.g2.com/de/survey_responses/blink-review-9911596)**

**Rating:** 5.0/5.0 stars

_— Uriel A._

[Read full review](https://www.g2.com/de/survey_responses/blink-review-9911596)

**["Kompatibilitäts-Champion, Begrenzte Erweiterbarkeit"](https://www.g2.com/de/survey_responses/blink-review-11995069)**

**Rating:** 4.5/5.0 stars

_— VISHNU S._

[Read full review](https://www.g2.com/de/survey_responses/blink-review-11995069)

### [IBM QRadar SOAR](https://www.g2.com/de/products/ibm-qradar-soar/reviews)

IBM QRadar® SOAR ist darauf ausgelegt, Ihrem Sicherheitsteam zu helfen, mit Zuversicht auf Cyberbedrohungen zu reagieren, mit Intelligenz zu automatisieren und mit Konsistenz zusammenzuarbeiten. Es leitet Ihr Team bei der Lösung von Vorfällen, indem es etablierte Vorfallreaktionsprozesse in dynamische Playbooks kodifiziert. Die offene und agnostische Plattform hilft, ihre Reaktion zu beschleunigen und zu orchestrieren, indem sie Aktionen mit Intelligenz automatisiert und mit anderen Sicherheitswerkzeugen integriert. IBM QRadar SOAR ist auf dem AWS Marketplace verfügbar.

**Average Rating:** 4.0/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate IBM QRadar SOAR?

- **Automatisierte Problembehebung:** 7.5/10 (Category avg: 8.7/10)
- **Support-Qualität:** 7.9/10 (Category avg: 9.0/10)
- **Einfache Verwaltung:** 6.7/10 (Category avg: 8.6/10)
- **Workflow-Automatisierung:** 7.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind IBM QRadar SOAR?

- **Verkäufer:** [IBM](https://www.g2.com/de/sellers/ibm)
- **Gründungsjahr:** 1911
- **Hauptsitz:** Armonk, New York, United States
- **Twitter:** @IBMSecurity  
74,660 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=14b544adaece4fdbc987f1d7f7028048c22259946811200cc751263825586af9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1009%2F&secure%5Burl_type%5D=linkedin_company_website)  
328,202 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** SWX:IBM

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen
- **Company Size:** 72% Large, 21% Medium

#### What Do G2 Reviewers Say About IBM QRadar SOAR?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer heben die **benutzerfreundliche Oberfläche** von IBM QRadar SOAR hervor, die eine schnelle Erstellung und Anpassung von Workflows erleichtert.
- Benutzer finden, dass die **Automatisierungsfähigkeiten** von IBM QRadar SOAR manuelle Aufgaben erheblich reduzieren und die Effizienz in Sicherheitsoperationen steigern.
- Benutzer schätzen die **einfachen Integrationen** mit verschiedenen Tools, die ihre Sicherheitsoperationen und Arbeitsabläufe effizient vereinfachen.
- Benutzer schätzen die **nahtlose Integration** mit verschiedenen Tools, die Effizienz steigert und Sicherheitsprozesse effektiv optimiert.
- Benutzer schätzen den **reaktiven IBM-Support** und die Benutzerfreundlichkeit der QRadar SOAR-Konsole für schnelle Lösungen.

##### Cons

- Benutzer stehen vor **Integrationsproblemen** mit IBM QRadar SOAR, was seine Funktionalität einschränkt und die Einrichtung mit anderen Anwendungen erschwert.
- Benutzer finden die **anfängliche Komplexität** von IBM QRadar SOAR herausfordernd, was Zeit erfordert, um seine umfangreichen Funktionen zu beherrschen.
- Benutzer erleben **begrenzte Integration** mit IBM QRadar SOAR, was fortgeschrittene Konfigurationen und Implementierungen herausfordernd macht.
- Benutzer finden die **Systembeschränkungen** von IBM QRadar SOAR schränken effektive Transformationen ein und erschweren die Implementierungsbemühungen.
- Benutzer berichten von **Fehlerproblemen** mit IBM QRadar SOAR, einschließlich Fehlern in Workflows und gelegentlicher Verzögerung der Leistung.

#### What Are Recent G2 Reviews of IBM QRadar SOAR?

**["Analysieren Sie Soar Qradar"](https://www.g2.com/de/survey_responses/ibm-qradar-soar-review-9842312)**

**Rating:** 5.0/5.0 stars

_— Aparecido A._

[Read full review](https://www.g2.com/de/survey_responses/ibm-qradar-soar-review-9842312)

**["IBM Security QRadar SOAR"](https://www.g2.com/de/survey_responses/ibm-qradar-soar-review-9696782)**

**Rating:** 4.5/5.0 stars

_— Prashanth K._

[Read full review](https://www.g2.com/de/survey_responses/ibm-qradar-soar-review-9696782)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=2#product-list)
- [3](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=3#product-list)
- [4](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=4#product-list)
- [5](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=5#product-list)
- [6](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=6#product-list)
- [Next &rsaquo;Next ›](/categories/security-orchestration-automation-and-response-soar?open_modal_url=%2Fproducts%2Ftines%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsecurity-orchestration-automation-and-response-soar%26source%3Dcategory&order=g2_score&page=2#product-list)

Spotlight Categories

[Mobile Device Management (MDM) Software](https://www.g2.com/categories/mobile-device-management-mdm)

[Sales Performance Management Software](https://www.g2.com/categories/sales-performance-management)

[Knowledge Base Software](https://www.g2.com/categories/knowledge-base-software)

[Retail POS Systems](https://www.g2.com/categories/retail-pos)

[Electronic Data Interchange (EDI) Software](https://www.g2.com/categories/electronic-data-interchange-edi)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)

- [Deception Technology](/categories/deception-technology)
- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)

- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)
- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)

[Browse Security Orchestration, Automation, and Response (SOAR) Themes](/categories/security-orchestration-automation-and-response-soar/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Security orchestration, automation, and response (SOAR) software products are tools used to help integrate security technologies and automate incident-related tasks. These tools integrate with a company’s existing security solutions to help users build and automate workflows, simplifying the incident response process and reducing the amount of human intervention necessary to handle security incidents. Companies use these tools to create a centralized system complete with visibility into a company’s security software and operational processes. These tools also reduce the time it takes to respond to incidents, as well as the potential for human error in remediating security threats and vulnerabilities.

SOAR platforms combine aspects of [vulnerability management](https://www.g2.com/categories/vulnerability-management), [incident response](https://www.g2.com/categories/incident-response), and [security information and event management (SIEM)](https://www.g2.com/categories/security-information-and-event-management-siem) solutions. SOAR products are designed to provide some of each tool’s respective functionality or integrate with third-party tools. Once integrated, processes can be designed to identify incidents and automate remediation tasks.

To qualify for inclusion in the Security Orchestration, Automation, and Response (SOAR) category, a product must:

- Integrate security information and incident response tools
- Allow security professionals to build response workflows
- Automate incident management and response tasks within workflows
- Provide formalized incident, workflow, and performance reports

Show More

### Security Orchestration, Automation, and Response (SOAR) Topics

- [What is Security, Orchestration, Automation, and Response (SOAR) Software?](#what-is-security-orchestration-automation-and-response-soar-software)
- [What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?](#what-are-the-common-features-of-security-orchestration-automation-and-response-soar-software)
- [What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?](#what-are-the-benefits-of-security-orchestration-automation-and-response-soar-software)
- [Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?](#who-uses-security-orchestration-automation-and-response-soar-software)
- [Challenges with Security, Orchestration, Automation, and Response (SOAR) software](#challenges-with-security-orchestration-automation-and-response-soar-software)
- [How to Buy Security, Orchestration, Automation, and Response Software](#how-to-buy-security-orchestration-automation-and-response-software)
- [What does Security, Orchestration, Automation, and Response (SOAR) Software cost?](#what-does-security-orchestration-automation-and-response-soar-software-cost)
- [Security, Orchestration, Automation, and Response (SOAR) Software Trends](#security-orchestration-automation-and-response-soar-software-trends)

[
### Security Orchestration, Automation, and Response (SOAR) Topics
Expand/Collapse ](#)
- [What is Security, Orchestration, Automation, and Response (SOAR) Software?](#what-is-security-orchestration-automation-and-response-soar-software)
- [What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?](#what-are-the-common-features-of-security-orchestration-automation-and-response-soar-software)
- [What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?](#what-are-the-benefits-of-security-orchestration-automation-and-response-soar-software)
- [Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?](#who-uses-security-orchestration-automation-and-response-soar-software)
- [Challenges with Security, Orchestration, Automation, and Response (SOAR) software](#challenges-with-security-orchestration-automation-and-response-soar-software)
- [How to Buy Security, Orchestration, Automation, and Response Software](#how-to-buy-security-orchestration-automation-and-response-software)
- [What does Security, Orchestration, Automation, and Response (SOAR) Software cost?](#what-does-security-orchestration-automation-and-response-soar-software-cost)
- [Security, Orchestration, Automation, and Response (SOAR) Software Trends](#security-orchestration-automation-and-response-soar-software-trends)

## Learn More About Security Orchestration, Automation, and Response (SOAR) Software

### What is Security, Orchestration, Automation, and Response (SOAR) Software?

Security orchestration, automation, and response (SOAR) software helps coordinate, execute, and automate tasks between various IT workers and tools. SOAR tools allow organizations to respond quickly to cybersecurity attacks and observe, understand, and prevent future incidents.

SOAR software gives organizations a comprehensive view of their existing security systems while centralizing the security data. By automating security responses and reducing manual tasks, SOAR helps to generate a faster and more accurate response to security attacks. It also helps better coordinate and route incident response to the most appropriate IT worker in real time.

**What Does SOAR Stand For?**

SOAR stands for security orchestration, automation, and response. SOAR software significantly contributes to identifying potential future security threats.

### What are the Common Features of Security, Orchestration, Automation, and Response (SOAR) Software?

Usually, a SOAR software offering operates under three primary software capabilities:

**Threat and vulnerability management:** Threat and vulnerability management examines key assets and prioritizes efforts to reduce risk. Working with other security teams, threat and vulnerability management helps prevent attacks by threat actors.

**Security incident response:** Security incident response addresses and manages the aftermath of a security breach, cyberattack, computer incident, or security incident. Security incident response is to handle the aftermath of a security breach in a way that limits damage, reduces recovery time, and reduces cost.

**Security operations automation:** Security operations automation is the technology that enables the automation and orchestration of security tasks. This can include both administrative duties and incident detection and response.

### What are the Benefits of Security, Orchestration, Automation, and Response (SOAR) Software?

The benefits of using a SOAR tool are that it lessens the impact of security incidents and reduces the risk of legal liability. SOAR software helps companies’ security teams by enabling them to:

**Maintain a central view:** One of the benefits of SOAR software is that it gives security staff a central view and enables control of existing security systems while centralizing data collection to improve a company's security posture, operational efficiency, and productivity.&nbsp;

**Automate manual tasks:** As with most software today, users are looking for help in terms of automation. SOAR software helps to manage and automate all aspects of a security incident lifecycle. This removes manual tasks, gives security staff more time to be productive, and allows them to focus on more mission-critical security tasks that do not require manual tasks.

**Define incident and response procedures:** SOAR software helps security systems define incident and response procedures. This helps to route security incidents to the correct security staff. SOAR can also prioritize and standardize the security response processes in a consistent, transparent, and documented way.&nbsp;

**Optimize incident response** : Because SOAR software helps security staff define incident and response procedures, incident response is more accurate. This accuracy enables security systems and staff to have improved responses where they may have to contain, eradicate, or recover crucial data.&nbsp;

**Identify and assign incident severity levels:** SOAR software helps to identify and assign incident severity levels. Severity levels in cybersecurity measure how severely a security incident impacts various parts of the organization. SOAR software automatically identifies and assigns severity levels, enabling the right security system and staff to respond appropriately. This means both can respond immediately to security incidents that may negatively affect an organization, such as networks, software, employee or customer data, etc.

**Support collaboration and unstructured investigations:** SOAR software supports collaboration and unstructured investigations in real time, helping route each security incident to the security system and security staff best suited to respond. Collaboration with other IT teams for tasks such as remediation or other departments such as legal is possible.&nbsp;

**Streamline operations:** By using SOAR software, organizations can streamline security operations for threat and vulnerability management, security incident response, and security operations automation. SOAR software connects these security elements while integrating disparate security systems. SOAR software’s playbooks allow users to orchestrate, streamline and automate tasks. Playbooks also codify the process workflows that streamline the SOAR software functions.

### Who Uses Security, Orchestration, Automation, and Response (SOAR) Software?

**IT and cybersecurity staff:** They use SOAR software to handle security alerts such as phishing, which includes looking for threat feed data from endpoints, failed user logins, logins from unusual locations, malicious VPN access attempts, and so on. It's also used to hunt for threats and respond to incidents from attached files for malware analysis, cloud-aware incident response, and automate data enrichment. Cybersecurity staff who assign incident severity and check other products for vulnerability scores also use SOAR platforms.

### Challenges with Security, Orchestration, Automation, and Response (SOAR) software

There are a number of challenges with SOAR software that IT teams can encounter.

**Skill gaps:** While there is the misconception that SOAR software could replace security staff, the tool is meant to augment security teams, allowing them to work efficiently and effectively but not replacing them. However, there still may be a skills gap as the security team must be able to create detailed workflows of their processes.

**Effective deployment:** Another challenge of SOAR software is that it must be deployed to the enterprise but also connected to the other applications and technologies, which can be very complicated. An organization must also have staff with enough skills to deploy and maintain the platform. The applications and technologies used by the enterprise must also be able to support or be integrated into the SOAR software. One of SOAR software’s greatest strengths is to connect and orchestrate other technologies; however, if each technology is unable to be integrated, it hampers the benefits of deploying SOAR software.

### How to Buy Security, Orchestration, Automation, and Response Software

#### Requirements Gathering (RFI/RFP) for Security, Orchestration, Automation, and Response (SOAR) Software

If an organization is just starting out and looking to purchase SOAR software, g2.com can help select the best one.

Most business pain points might be related to all of the manual work that must be completed. If the company is large and has a lot of networks, data, or devices in its organization, they may need to shop for a SOAR software that can grow with its organization. Users should think about the pain points in security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use the SOAR software and if they currently have the skills to administer it.&nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The checklist serves as a detailed guide that includes both necessary and nice-to-have features, including budget, features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the scope of the deployment, it might be helpful to produce an RFI, a one-page list with a few bullet points describing what is needed from SOAR software.

#### Compare Security, Orchestration, Automation, and Response (SOAR) Software

**Create a long list**

Vendor evaluations are an essential part of the software buying process from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow down the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list in hand, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure the comparison is comprehensive, the user should demo each solution on the shortlist with the same use cases. This will allow the business to evaluate like for like and see how each vendor stacks up against the competition.&nbsp;

#### Selection of Security, Orchestration, Automation, and Response (SOAR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the entire process, from identifying pain points to implementation, is crucial. The software selection team should consist of organization members with the right interest, skills, and time to participate in this process. A good starting point is to aim for three to five people who fill roles such as the main decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. In smaller companies, the vendor selection team may be smaller, with fewer participants multitasking and taking on more responsibilities.

**Compare notes**

The selection team should compare notes and facts and figures which they noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it's final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and well received, the buyer can be confident that the selection was correct. If not, it might be time to go back to the drawing board.

### What does Security, Orchestration, Automation, and Response (SOAR) Software cost?

SOAR is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization's specific requirements. Once a SOAR solution is purchased, deployed, and integrated into an organization’s security system, the cost could be high, which is why the evaluation stage of selecting SOAR software is so crucial. The notion of rip-and-replace cost can be high. The SOAR vendor chosen should continue to provide support for the SOAR solution with flexibility and open integration.

#### Return on Investment (ROI)

Organizations decide to purchase SOAR software with some type of return on investment (ROI). As they want to recoup the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency.

SOAR software saves security staff costs by eliminating manual tasks. For example, SOAR software automatically investigates the scenario of email phishing attacks which is very common, so this task can be very repetitive and consumes security staff time if it is done manually. A large enterprise used actual data from its SOAR software deployment and compared it to the cost of handling email phishing investigations automatically using SOAR software versus handling them manually. The enterprise found that the reduction in staff time required to handle phishing emails equated to savings of over $680,000 per year.

### Security, Orchestration, Automation, and Response (SOAR) Software Trends

**Enterprises:** Due to the requirements to maintain such large-scale IT and network infrastructure, organizations such as large enterprises tend to be more interested in purchasing SOAR software. Having such large networks and more complex IT makes such organizations more vulnerable to security threats which is another drive to purchase SOAR software. Also, larger organizations have more employees with more devices, which increases threats if they are accessing workplace applications on these devices.

**Retail and e-commerce:** These industries have increased interest in SOAR software due to the vulnerabilities in PoS)transactions and online purchases. It is the processing of these monetary transactions which creates a security risk, especially there personal and financial information of customers. Adopting technologies such as location-based marketing for these types of purchases also makes the retail industry more vulnerable to security threats.