SOC teams are drowning in events and alerts coming from their various underlying threat and vulnerability detection systems. In many SOCs this volume far outstrips their triage and investigative capacity. Many surveys show that alerts are so numerous that the majority are strategically ignored to stop infinite queue growth. One report found that SOC teams receive 3,832 alerts per day on average, with 62% of those ignored. That’s a key operational gap SOAR is meant to close.
What SOAR is in 2025
SOAR—Security Orchestration, Automation, and Response—transforms detections to understanding, decisions, and actions. SOAR systems ingest events and alerts, enriches them with context, supports analysis, orchestrates cross-tool/cross-team workflows, and drives incident response to resolution. The SOAR category of security solutions emerged in the 2014/2015 timeframe and has worn many labels along the way (TRO, IRAP, CRA, SecOps automation, and others) but I’ll use SOAR throughout for clarity.
Why SOAR remains a high priority
You can’t scale a 24×7 SOC function with headcount alone; even well-staffed enterprises run out of people. For enterprises with more than 5K employees, a “typical” in-house SOC has approximately 11-25 people already. It is not reasonable to expect to get more people to throw at this problem.
In today’s enterprise, made up of on-premises, cloud and SaaS applications, remote and hybrid staff, thousands or even millions of identities, and the recent explosive rise of AI, this growing attack surface keeps pushing threats and thus security events and alerts up.
The result is that defenders need smart(er) automation to keep pace while also improving detection and response efficacy. In my conversations, I hear the same goals: shrink MTTR, cut false positives while not increasing false negatives, keep approvals and audit trails tight, and make playbooks creatable and maintainable by more than one “hero” automation engineer. Enterprises confirm they simply “can’t throw people at the problem” anymore.
The SOAR market has matured over these past 10 years. There are now dozens of offerings and vendor go-to-market strategies, reflecting the age-old buyer decision conundrum of “best of breed” or “integrated security platform”. But there is also an ongoing twist to this historically binary choice, with some vendors (and independent managed service providers) providing outsourced SOC services as managed detection and response (MDR) services. With some SOAR/MDR providers also enabling 3rd-party MDR providers with their SOAR and broader security stack. The bottom line is that there are many automation solution options from which enterprises can choose!
Thus, a key enterprise buying decision for 2025 and beyond, select a SOAR that is:
- Best-of-breed
- Part of a broader security platform
- Delivered as part of an outsourced, SOAR-enabled MDR service?
This is one question I plan to help answer as part of my in-process research.
The basic capabilities of SOAR have stabilized—but how they provide them is evolving
Across all SOAR products, three pillars of core capabilities show up consistently:
- Event/alert collection, correlation, enrichment, and analysis
- Orchestration and automation across security and IT systems and organizations
- Case management and incident response/mitigation (both automated and human-in-the-loop)
What is changing is how teams deliver these capabilities, as AI quickly enters the SOAR realm.
AI in SOAR: assistive now, more autonomous later?
On the defender side, chat interfaces and task-specific agents are becoming common tools for analysts and responders. What will AI ultimately enable? Perhaps faster enrichment, triage, and summarization, smarter next-step suggestions, more reliable alert prioritization, and safer automation with/without human involvement. But how to do this safely with non-deterministic, black box AI systems?
What I’m researching now (and how to weigh in)
Over the coming months, I’m building an updated KuppingerCole Leadership Compass on SOAR to publish in early 2026. In this Leadership Compass, I will assess:
- The operating models that work and for whom (standalone, embedded, hybrid, MDR/outsourced led)
- How playbook and workflow authoring and maintenance scales (versioning, testing, drift control)
- Integration coverage, functionality, and ease of expansion.
- Evidence, auditability, and reporting that prove improvement and value
- Where AI helps today—and how far down the AI-based automation road SOCs can go in the near future.
If you have a SOAR product, customer stories, hard metrics, or a contrarian view, I’d love to hear it. SOAR vendors with a dog in this fight: please reach out and take part.
Matthew Gardiner is a Fellow Analyst at KuppingerCole covering security operations, identity, and the intersection of AI and automation. This article kicks off a series leading to the 2026 Leadership Compass on SOAR.