Cyberattacks have grown in number and sophistication while many organizations still rely on fragmented security stacks, sometimes operating 50+ disjointed tools. Although SIEM products remain foundational in many Security Operations Centers (SOCs), they have not fully solved the problem of efficient incident handling. In parallel, incident investigation and response platforms have evolved into SOAR solutions, driven by demand for centralized, automated control over analysis and response workflows across disparate tools. SOAR platforms complement or integrate with SIEMs to reduce Mean Time to Detect (MTTD) and Mean Time to Resolve (MTTR), which can reach roughly six months and two months respectively, increasing the damage from incidents.
SOAR’s core value is orchestration and automation via out-of-the-box connectors (integrations) that pull telemetry from upstream sources and can also trigger actions in downstream tools through exposed APIs. Beyond collecting and correlating events, SOAR can open cases, enrich alerts with additional forensic evidence (e.g., EPP scan outputs, non-standard logs, memory dumps), initiate automated threat hunts, and query cyber threat intelligence (CTI) sources. Some solutions add machine learning to reduce false positives and deliver more actionable intelligence, ideally automating substantial work before analysts are alerted.
Logsign, founded in 2010, launched SIEM in 2015 and SOAR in 2021. Logsign SOAR is primarily on-premises on Ubuntu Linux, with cloud-ready and SaaS plans targeting GCP. Licensing is based on incidents tracked per day and the number of integrations. Logsign highlights its Personal Workbench as a differentiator: an analyst-centric console with prioritized task lists, drill-down investigation views, collaborative case management, an emergency escalation button, and visibility into playbook execution. Playbooks are executed by specialized “bots” (investigation, analysis, response, remediation) enabling parallel activity streams. The product offers extensive integrations (roughly 300), a visual playbook editor, CTI and sandbox feed ingestion, dashboards for MTTD/MTTR, and a customer-extensible knowledge base. Key challenges include the need for broader cloud/SaaS integrations and the absence (so far) of strong console authentication/MFA, which is on the roadmap.
See All Locations
See All Locations