This Leadership Compass is related to the report published in October 2024. If you would like to see what it included, please click here.
Inclusion Criteria
Many vendors embrace the terms “SOAR” or “AI SOC”. If a vendor has a solution in its portfolio in any form – standalone, embedded, or hybrid, they are encouraged to take part in this Leadership Compass. Those vendors providing solutions to MSSP/MDR providers are also encouraged to take part.
However, to be included in this Leadership Compass we expect a system to implement all three of the core capabilities described here:
- Security event/alert collection, correlation, analysis, and enrichment: A system should ingest security events/alerts from SIEM/XDR systems and other solutions. When appropriate, the events/alerts should be enriched with additional business context, external threat intelligence, or other data sources to support workflows, rule or AI-based analysis, or decision-support requirements.
- Security orchestration and automation: A system should implement comprehensive workflow management capabilities to ensure that tasks across multiple environments, security tools, and teams can be efficiently coordinated. Whenever possible, repetitive parts of these workflows should be “smartly” automated to free the analyst’s time for more valuable tasks. For manual steps, intelligent guidance and decision support capabilities are a major plus. Increasingly it is expected that AI enabled analytics will be applied to drive even smarter automation and, in some cases, full autonomy.
- Incident response and mitigation: For identified, positive security incidents, the system should be able to offer a range of suggested and automated resolutions: ranging from simple actions like creating an ITSM ticket for manual processing, or blocking an infected machine in a firewall, to more sophisticated responses that coordinate processes across multiple security and IT systems. These responses are often executed by leveraging integration with downstream EDR/XDR, email gateway, IAM, and other security systems. Some responses could be semi-automatic, thus requiring human action at points along the way, whereas others could be set to execute automatically without human involvement.
Exclusion Criteria
We are looking for solutions that provide full-featured and mature security automation systems. Vendors that focus narrowly on automating a specific IT environment or a narrow subset of security systems will be excluded from this report. MSSP/MDR providers would also be excluded unless they provide the software/cloud component of their solution on the market to enterprises or other MSSPs/MDR providers as well.