{"id":119373,"date":"2020-10-09T15:00:04","date_gmt":"2020-10-09T22:00:04","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=119373"},"modified":"2020-10-09T12:57:34","modified_gmt":"2020-10-09T19:57:34","slug":"secops-gartner-soar-solutions","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2020\/10\/secops-gartner-soar-solutions\/","title":{"rendered":"Gartner: Market Guide for SOAR Solutions"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Gartner recently published an updated Market Guide for Security Orchestration, Automation and Response Solutions. We believe this report delivers valuable insight on the current state of and forward outlook for the SOAR market, and once again outlines what Cortex XSOAR by Palo Alto Networks offers in alignment with their vision.\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/02\/cortex-xsoar\/\"><span style=\"font-weight: 400;\">Automation<\/span><\/a><span style=\"font-weight: 400;\"> is a critical initiative for many security operations teams, who look to overcome resource constraints while keeping pace with evolving attackers and a growing volume of security alerts. SOAR plays a key role in addressing these challenges:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe security technology market, in general, is in a state of overload, with pressure on budgets, staff shortages and too many point solutions. Customers often cite problems with an overload of events or alerts, complexity and duplication of tools. As a general practice, automation promises to solve many of these problems and, in cybersecurity, SOAR is the primary vehicle for this functionality.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We understand from the report that <\/span><span style=\"font-weight: 400;\">\u201cSOAR solutions are steadily gaining traction in real-world use to improve security operations.\u201d <\/span><span style=\"font-weight: 400;\">While SOAR has many potential <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/security-operations\/category\/use-cases\/\"><span style=\"font-weight: 400;\">use cases<\/span><\/a><span style=\"font-weight: 400;\"> \u2013 from cloud security orchestration, to vulnerability management, to non-security use-cases \u2013 the most common starting point for SOAR adoption is for incident response. Gartner states that <\/span><span style=\"font-weight: 400;\">\u201cSOAR solutions are primarily adopted to improve the processes around detection and response by context enrichment and by improving downstream prioritization and efficiency.\u201d<\/span> <span style=\"font-weight: 400;\">SOAR achieves this by combining case management, orchestration and automation, and threat intelligence functionality, all of which feed into each other to provide a robust and integrated \u201ccontrol plane for the modern SOC environment.\u201d\u00a0<\/span><\/p>\n<figure id=\"attachment_119400\" aria-describedby=\"caption-attachment-119400\" style=\"width: 500px\" class=\"wp-caption alignright\"><div style=\"max-width:100%\" data-width=\"500\"><span class=\"ar-custom\" style=\"padding-bottom:70.2%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"wp-image-119400 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/10\/SOAR-convergence.png\" alt=\"The screenshot shows how SOAR solutions converge three technologies: Security Incident Response Platforms (SIRP) (case\/incident management, workflows, incident knowledgebase), Security Orchestration and Automation (SOA) (integrations, play\/process\/workflow automation, playbook management) and Threat Intelligence Platforms (TIPs) (TI Aggregation, curation, distribution, alert enrichment, TI visualization). Source: Gartner\" width=\"500\" height=\"351\" \/><\/span><\/div><figcaption id=\"caption-attachment-119400\" class=\"wp-caption-text\">SOAR combines three formerly separate technologies \u2013 SIRP, SOA and TIP<\/figcaption><\/figure>\n<p><span style=\"font-weight: 400;\">As Palo Alto Networks rapidly expands the already broad and robust capabilities of Cortex XSOAR, we continue to feel 100% in alignment with Gartner\u2019s vision for SOAR. We\u2019ve integrated threat intelligence manag<\/span><span style=\"font-weight: 400;\">ement earlier this year, and we continue to release new machine learning capabilities and third-party integrations to increase insight, automation and speed for incident responders. Per Gartner, \u201cXSOAR\u2019s focus has been to optimize the efficiency of security operations by offering a single platform for SOC analysts to manage incidents, automate and standardize incident response processes, as well as collaborate on incident investigations.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SOAR has shown greater adoption among larger security operations centers and managed security providers who are at a level of maturity to be able to design automation. We aim to accelerate the time-to-value and accessibility of SOAR above and beyond the market trend, not only with our famously easy-to-use visual <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/playbooks\/\"><span style=\"font-weight: 400;\">playbook<\/span><\/a><span style=\"font-weight: 400;\"> editor, but also in a number of ways which we believe to be in alignment with Gartner\u2019s analysis:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Through the <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/08\/cortex-xsoar-marketplace\/\"><b>Cortex XSOAR Marketplace<\/b><\/a><span style=\"font-weight: 400;\">, which offers a way for more security teams to accelerate their automation with pre-built, vendor-certified integration and automation playbooks that can be activated in a matter of clicks.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Through rich <\/span><b>cloud-delivered SOAR functionality<\/b><span style=\"font-weight: 400;\"> to minimize resource requirements and support an increasingly remote workforce.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Through our <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/09\/cortex-xdr-2-5\/\"><b>extended detection and response (XDR)<\/b><\/a> <span style=\"font-weight: 400;\">platform, which complements the extensibility of Cortex XSOAR in the incident response tech stack with pre-built investigation automation and enrichment functionality.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">To read more, including key findings, recommendations, and investment considerations, download a complimentary copy of the <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/2020-gartner-mg-for-soar.html\"><span style=\"font-weight: 400;\">Gartner Market Guide for Security Orchestration, Automation and Response Solutions<\/span><\/a><span style=\"font-weight: 400;\"> today.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We believe the Gartner Market Guide for SOAR Solutions delivers valuable insight on the current state of and forward outlook for the SOAR market.<\/p>\n","protected":false},"author":657,"featured_media":119374,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6765,6770],"tags":[7317,117,7316,7241],"coauthors":[6810],"class_list":["post-119373","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-enterprise","category-secure-the-future","tag-automation-and-response-solutions","tag-gartner","tag-market-guide-for-security-orchestration","tag-soar-2","sec_ops_category-must-read-articles","sec_ops_category-news-and-events"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/10\/Monitor-blog.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/119373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/657"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=119373"}],"version-history":[{"count":2,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/119373\/revisions"}],"predecessor-version":[{"id":119414,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/119373\/revisions\/119414"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/119374"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=119373"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=119373"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=119373"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=119373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}