Security teams today face rising threats, alert fatigue, and a shortage of skilled analysts. At the same time, CISOs are under pressure to improve response times and reduce costs. To meet these demands, organizations are turning to Security Orchestration, Automation, and Response (SOAR) platforms, but not all SOAR solutions are created equal.
Modern SOAR is no longer just about incident response. With the infusion of generative AI and hyperautomation, SOAR has the potential to drive business-wide efficiency, extend beyond IT, and become a central nervous system for the modern Security Operations Center (SOC). But how do you distinguish real innovation from marketing hype?
Alejandro Leal, Senior Analyst at KuppingerCole, will provide a strategic perspective on SOAR trends, including where AI is making a tangible impact, what hyperautomation really means in a SOC context, and how SOAR is evolving beyond cybersecurity use cases. He will also highlight what buyers should look for in a modern solution.
Kevin Faulkner, Product Marketing Director at Fortinet, will explore how FortiSOAR fits into this shifting landscape. He will share real-world customer profiles, explain key use cases, and outline FortiSOAR’s value for managed service providers. Expect insights on embedded vs. stand-alone automation and where SOAR is headed next.
Hi, my name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole and I would like to welcome you to today's webinar, What Security Teams Need from SOAR Now. Today I'll be joined by Kevin Faulkner. He's the Product Managing Director at Fortinet. Good morning, Kevin. How are you? Great.
Good day, all. Good. Glad to have you on board. I'm looking forward to the conversation, but before we begin, I would just like to remind the audience of a few things.
So, all of you are muted. There's no really need for you to mute or unmute yourself. We will also be conducting a couple of poll questions, so I encourage you all to participate on those. It can help us on our research. And in the coming days, you will be able to access the recording as well as the slides that we use in today's webinar. And if you have any questions, please just feel free to write your question in the panel and we'll make sure to address those at the end of the webinar.
Okay, so here's the agenda for today. I will be introducing the topic, discuss some market trends that I observed based on my latest research. I published a report last year.
And then, at the end of the webinar, we'll be having just a brief overview of that report. So, here's the first poll question. How many of you currently use automation in your security operations?
So, first, I think it's important to look at the origins of SOAR. As we know, cyber threats are just constantly evolving. They do not remain static. Attackers are integrating new solutions and new technologies to create different TTPs.
So, organizations need to be able to detect and respond to incidents by monitoring security and analyzing events in real time. SIEM solutions, security information and event management, these were once hailed as the, let's say, the ultimate solution for managing security operations. In many organizations, they still form the foundation of the sub-team. But many organizations realize that the visibility of potential security events is not always enough for analysts to discover new threats.
And also, one of the main problems that analysts face is the amount of time they spend on manual tasks and repetitive processes, which is something that is extremely annoying for them. So, here's where SOAR solutions come in. These solutions enable organizations to automatically collect and consolidate data from multiple sources to also streamline the management of incident response processes and to orchestrate different workflows across security tools.
So, many people often ask, what's the best approach? Is it better to have SOAR as a standalone or to have this sort of bundled SOAR in SIEM?
So, the bundled approach could be better for organizations that are maybe committed to a specific vendor stack. And when they have, let's say, more simple workflows, the integration is better, it's a faster setup, and it could be much more simple. But when it comes to standalone SOAR, there are other benefits. For example, the vendor-agnostic orchestration, it's more easy to customize. It also has more advanced playbooks, more case management features, and cross-team collaboration.
And it also provides more extensibility at scale as organizations grow, which is also an important aspect for MSSPs or complex organizations in highly regulated industries. So, on this slide, we see the evolution till more or less the present day. And as I said, many organizations adopt SOAR based on their own needs and requirements. And that is the main question of today's webinar. What security teams need from SOAR now? A few months ago, an analyst firm, they claimed that SOAR solutions are obsolete.
And it's true that automation is increasingly being embedded in other security tools like EDR, XDR, SIEMs. But I think that SOAR is solving a different problem, more of a cross-domain orchestration and centralized coordination. It's something that Kevin and I will talk more in the next slides. But as organizations continue to automate more processes, I think SOAR can bring a unique set of benefits.
So, from my experience talking to vendors and organizations, I would say that I would say that SOAR is more like evolving. It's not disappearing, especially with features like Gen AI and agents and other tools. These are driving that evolution.
So, if we go to the next slide, we see that there's still urgency today. There's still security incidents. If you've been checking the news, you'll see that a couple days ago, major European airports suffered ransomware, which delayed hundreds of flights.
So, I think that SOAR needs to adapt to the needs of the sub today, right? There's still security incidents. It's still costing a lot of money to organizations.
So, SOAR could be a sort of a place for holistic orchestration rather than fragmented automations, a centralized orchestration and task management hub. And in addition to the threats that we mentioned, like ransomware, we also see geopolitical changes that are affecting countries and critical infrastructure. We also see supply chain attacks. And these are just a few examples, but it's also important to talk about the internal challenges that organizations face.
So, if we look at this slide, we see that the number of false positives, the high volume of alerts, the complexity of integrating different tools and keeping up with compliance standards, those are major challenges organizations face. Kevin and I had a nice conversation the other day on ITDR, which is another topic that we cover at Coupling & Co. And actually, we'll be publishing the Leadership Compass on ITDR this fall, probably in a month or six weeks.
So, stay tuned for that. But ITDR is an interesting example because many ITDR vendors are integrating with SOAR solutions to respond to identity-based threats.
So, ITDR is an interesting area where identity and access management is connecting with security teams, with the SOC. I know that Kevin will go deeper on the compliance use case, but yeah, this is also an area where many organizations struggle.
So, we could say that SOAR is a sort of unified command center. And in the next slides, we'll talk more about this need for human-machine collaboration and also understanding the limitations of that collaboration.
So, so far, we more or less had an introduction on SOAR, and it's important now to look at market trends. So, when I wrote my report on SOAR last year, it was a year ago, so that feels already like a long time. I remember that many SOAR vendors were enthusiastic about Gen-AI, but they all had a different approach. Some vendors would tell me that they were already integrating ChatGPT, Copilot, Gemini, etc. Others decided to create their own LLMs, while other vendors decided to be more cautious and to just wait how the market evolves and how it integrates these new solutions.
So, they decided to form partnerships before and slowly adapt to the market. So, these are just some of the opportunities that Gen-AI presents here on this slide.
So, it can help suggest playbooks. It can help predict attacks.
Of course, it can greatly improve the task of incident response summaries, and it can also increase adaptability. But there are also major challenges.
Earlier, Kevin and I talked about how organizations are mainly interested in getting their problems solved, and if Gen-AI or AI agents or any other new solution can help do that, then great. But vendors are not just asking AI because it's hot and hype and cool these days. They want to make sure that AI-based solutions will provide real value to their organizations and especially solve the problems, which is what they want.
So, another interesting area here is the use of AI agents, and it's important to mention that this is still a work in progress. Many store vendors are still starting to explore this area. There's been some interesting academic papers written on this topic, but it's still a work in progress. We still have to see how the market unfolds.
But we can see that there are some limitations in traditional SOAR solutions, and the emergence of agentic AI could be an important step forward because SOAR has this stereotype sometimes of being a little bit rigid with all these prescriptive workflows and playbooks, and it often lacks adaptability. So, the use of agents could address that.
So, SOAR, it still remains useful, of course, but maybe for some structure and repetitive tasks, and the emergence of agentic AI could have an impact on how SOAR behaves, let's say. So, we see SOAR automates tasks while agentic AI automates decision making. And here on the top, I say SOAR with a brain, but not really a brain because, well, it's an interesting question, and that's why on this slide, I have this interesting medieval painting because talking about this is like a rabbit hole that the opening of AI is a sort of new space, and this painting was, I found it on a book on Immanuel Kant.
He was a German Enlightenment philosopher, and one of the interesting things about the Enlightenment, and one of the important lessons, is that when it comes to epistemology, and epistemology is the study of knowledge, so the study of how we know what we know, one of the claims of the Enlightenment was that knowledge arises not just from processing data, but from reflecting on the conditions that made that possible. So, reflecting on the conditions of knowledge to question and to ask, where does knowledge come from? And that's something that we could say machines cannot really do that.
So, the Enlightenment lesson is that to preserve clarity, AI must remain accountable to human reason, which alone can critically question, interpret, and assess meaning to make security decisions.
So, the human must remain in the picture and be the one that questions and interprets whatever the output is, especially when questions of trust, identity, and accountability are at stake, and that's why on the left side, I have this this little quote saying that we simply cannot outsource epistemology to machines, and if we take this claim seriously, we could argue that with gen AI and agentic AI and whatever comes next, the role of the human analyst in the sub will change and adapt.
So, maybe the role will become more strategic, because as I said on this slide, if the human is the one that holds knowledge of the world and meaning, it will be important to be in the picture, because the machine doesn't know it knows, or it doesn't know that it doesn't know if we follow this Kantian example.
So, I see that I'm running a little bit out of time, so I believe Kevin will talk more about use cases and examples, but here we see some emerging new use cases when it comes to SOAR, and just to conclude, SOAR does provide value today, but it faces challenges such as the complexity of implementation, it can also be costly and not very easy to scale, but there are some opportunities, and that includes the ability to leverage new tools and to take maybe different approaches, depending on what truly customers want, what is driving the solution to their problems.
So, before we jump into the Leadership Compass Report, just another poll question here, and the question is, what are your primary goals when considering implementing SOAR solutions? So, we'll be moving on, but you can still see the questions, so please feel free to participate on that.
So now, the Leadership Compass, maybe just a quick summary on how we do this. We first identify vendors on a given topic, we reach out to them, and we send them a question with a lot of questions, sorry, we send them a questionnaire with a lot of questions, sometimes even a thousand, very technical questions, Kevin can probably complain about that, but that's how we get most of the information, and then we also have a briefing with vendors, we see a demo, and then that's how we assess and analyze the information that we get.
Then we go through a period of fact check, where we send back the content to the vendor to see that everything makes sense and everything is accurate, and then we publish the report. So, it really depends on the topic, but it takes between two to three to four months, depending on also how many vendors participate in the report.
So, now, here are the results of the Leadership Compass from last year. We see some well-established vendors, as well as some innovative small companies that maybe just focus on specific industries or niche areas, but I'm looking forward to the next update, which will take place summer of next year, and it will be interesting to see how this market has changed based on the developments that we see and to see how these vendors have adapted to the changes.
And, yeah, each chapter has also like a spider graph where we assess different set of features that we believe are important when it comes to evaluating source solutions. So, now, I will, I think I finished right on time, I will give the floor to Kevin, and he will be now presenting his slide deck, and then we will also have some time for a discussion, a conversation between me and Kevin, and answer the questions that you may have.
Kevin, the floor is yours. Great.
Thank you, Alejandro. That's a very comprehensive but concise look at SOAR today and the trends that are happening. I'd like to pick up and go a little further on several of those points, and in doing so, give you an introduction to FortiSOAR, which is our SOAR product at Fortinet, and some of the use cases that we see with customers out there, really in line with the kind of things you just heard from Alejandro.
So, let's get started. Again, on the right, for those who aren't that familiar with a SOAR platform, what it's all about is, first of all, connectivity, and bidirectional connectivity, so that we can take alerts and information from systems, but also give systems a command and wait for the response. For example, scan this endpoint and then wait for those results. The bidirectional connectors, of course, connect to an automation engine that runs on playbooks, and so you will see vendors with pre-built playbook libraries.
We have over 840 SOAR and custom playbook building, which I'll cover a little bit later as well, of course. And then, basically, to this level, we really aren't necessarily focused or limited in any way to security.
So, it's an automation engine. We can automate anything and connect to anything.
And so, for security's sake, though, we built, if you want to think of it as applications or use cases out on top of this automation engine, the typical cases that customers use SOAR for, or at least start their journey, is alert investigation and response, collaboration case management, and threat intel management. And I'll touch on those, but I'll also spend some time on other use cases for SOAR that we see, like vulnerability management and compliance, IT and NOC use cases.
And then, ultimately, because the larger customers and MSSPs, they're really running their entire SOC on SOAR. And so, it's a natural place to add functionality like workforce management, SLA management, and reporting.
So, touch on all of those. You can see a few things on the left that are part of the aspects of our R40 SOAR and the overall value that it brings.
So, let me talk a little bit more about that in detail. It's starting to touch on today's, at least, view and capabilities of GenAI.
So, we look at GenAI as a way to speed investigation and reduce time, simplify and uplift the analyst experience. And so, it's all about the sufficiency and getting things done in a faster way.
Now, there's more to it than that, of course, and I'll talk about that in a second. But to stick with GenAI, these are some examples that we see in use today. Automatic alert analysis, including recommendations on next steps.
Of course, a copilot, if you will, for analyst intel and guidance, you know, using natural language, of course. And then, a big area is playbook building and playbook testing and validation.
So, there's a lot of work going on there to simplify that process and to help validate those processes through GenAI. Today, we're moving towards an agenda capability across these use cases and more, and you can imagine with the built-out agenda capability, for example, with threat analysis or with playbook building that become very specialized knowledge there that's within the system that can really be a boost.
So, we're looking forward to those kind of innovations coming later in the year, and you're going to start to see those, generally speaking, with SOAR. If I take a look, though, and start going a little broader on some of these use cases as an introduction, of course, as I said earlier, the threat alert investigation and response is the key use case that most customers start with and that motivates them to, because of the superior user interface for investigation, the superior automation capabilities that they have, case management, collaboration, war rooms, et cetera, et cetera.
It's a much richer environment to investigate and respond to alerts than, let's say, a SIM or an XDR or any other tool. Phishing investigation and response, automating that process and getting the analyst out of the loop there, unless there are decisions to make, that's another use case that saves corporations hundreds of hours per month. But we'll speak a little bit later about this idea of vulnerability and compliance management, processing the CVE and the KVE alerts, assigning the tasks, prioritizing them, tracking them, setting SLAs on those tasks, making sure all that is done.
This is a use case that we're seeing customers buy SOAR strictly for this use case rather than the other two. So this is emerging as not only an additional use case for security-focused, alert-focused customers, but also just their entry into SOAR. And finally, I've seen in the last six or eight months quite an uptake in NOC and IT task processing. And all we have to do in our customer discussions is to get beyond the fact that SOAR starts with an S that stands for security and talk about that SOAR can do a lot more than security.
And we're seeing a lot of interesting uptake that I'll touch on a little more later. But one last thing I'd like to thought I'd like to leave on these use cases and on SOAR in general, automation, if you will, is about efficiency and responsiveness, but it's also about ensuring results. Because when you automate something and you are going to centralize it and you're going to standardize it, it's going to happen the same way all the time. It's going to happen from the same place in a central manner all the time. And you'll be able to track and report it.
So you're going to get a lot of consistency, which is really important, especially in some of these use cases that otherwise had a lot of human activities, interactions that were follow-ups that were necessary, rigor that was necessary, that some analysts may be able to execute, others not so reliably or get distracted or other things come up. So the idea of standardization across playbooks makes sure everything does happen and happens in the same way.
So as Alejandro said, the typical use case for investigation and response is with SOAR at the quote-unquote top of the pyramid, where all the alerts, whether they're detections and coming through a SIM or coming directly from other products, go into SOAR for investigation and response and then automated action. The idea is the analyst will sit in SOAR.
He will not have to swivel to these other tools because playbooks will be used to interact, to give orders, get information, et cetera, from other tools like a vulnerability management system or further information from the SIM or further information from an EDR system. So this is the idea. We're not reducing the number of tools that are used for security and detections, but we're minimizing the usage of those tools by the analyst and allowing them to work in a consistent centralized environment.
I'll give you a quick example here from one of our customers, Groupama, which is an insurance and financial company in France. They're not a large SOC, but they're very sophisticated. They use SOAR for investigation response, but also vulnerability management, phishing, threat intel management. And then they are a ServiceNow shop, but because SOAR has the capability of doing ticketing that can be separate from the overall corporate ticketing, we connect to ServiceNow and pull in the tickets from ServiceNow, creating tickets within SOAR.
And once those tickets are complete, then we'll update ServiceNow. So, but the important point here probably is automatic processing over 85% of their alerts in SOAR without analyst intervention. And in their words, we have virtually eliminated what they consider the tasks of a level one SOC analyst because SOAR is doing that for them and empowering level two analysis from the get-go.
So, that's a pretty strong set of results. I'd like to point out one other example, though, to give you an even broader perspective on SOAR. This is a healthcare company, large healthcare institution here in California.
Now, not only do they do incident response, but then vulnerability management, threat intelligence. They have a DLP team, a red team, pen testing team also that uses this, and then detection engineering and automation engineering.
Now, all of these teams use SOAR as their main tracking assignments and collaboration environment. So, they have their own dashboards, their own playbooks, their own workflows, SLAs and metrics for each of the teams, but the teams can also collaborate because they're using this centralized platform.
So, for example, when the detection team or the incident response team, excuse me, finds a new incident, it might be that they want to assign the task to the detection engineering team to say, hey, we didn't catch this as soon as we could. Can you create a new detection?
So, they collaborate in that way, and this becomes a complete system of record of what's going on, what is each team doing, and it becomes the de facto way that the SOC manager and CISO report to each other and report up to the board of directors of what's going on in the SOC. So, this is truly a SOC and overall security operations that's running on SOAR. Automation is part of that, but it's not just about automation. It's about centralization and collaboration and then the flexibility to create these work environments.
So, let me touch in closing on just a couple of these use cases that are broader than investigation response in a little bit of detail. So, compliance is costly, and I'm talking about compliance with as a broad umbrella that would include vulnerability management and include what we call referred to as advisory feed automations.
Now, we see in government agencies and, in fact, in lots of different organizations around the world, the idea of them receiving IOC updates on several times a week with admonishment that you need to block these IOCs within your infrastructure, within X number of hours, and then you need to report back to us that you did it. This is part of compliance for these companies, and this is very costly, and typically, this is pretty, let's say, level one type of work.
Like, are we already blocking these IOCs? Okay.
If not, let's block them. That might mean putting in a ticket to the IT system. That might mean that the security team can do it themselves and validate that that's done, and we're talking about a lot of hours per week when these come in, and sometimes they come in in relatively unsophisticated ways, like an Excel spreadsheet that needs to be.
So, it's very, very error prone, and we have customers who bought just for this use case because of the time it will save them. Vulnerability management, as I mentioned a little bit earlier, certainly, SOAR is not a vulnerability system. It's not a scanner. It's not QALYS, but we can take, as part of our threat intelligence management, CVE, KVE alerts, track those across assets, assign the vulnerability to be fixed, prioritize it, assign it, and then track that it's done.
So, this whole idea, and, of course, automate any aspects of that, those activities that we can, but it's also, again, this centralized control task management and follow up and then reporting on it. So, that's important as well, all of that tracking and reporting, and this just gives you an idea. It's a very repetitive task, right, and it's very important, both from a compliance perspective, but also from a risk perspective, especially with the vulnerabilities.
So, we've got modules and dashboards and everything set up just for that. Another one, I'll just go a little further on the NOC and IT automation that I mentioned earlier. These are some of the use cases that we see customers going after. Device provisioning, you know, at scale. Site validation testing, this is a really interesting one, for example, with a major bank here in North America with over 4,000 branches.
Anytime they made a change to the IT, excuse me, infrastructure at one of the branches, they had a 100-step validation test that they were doing by hand, manually, and some of that had to be done on-site. Instead, now, we have playbooks and dashboards, and we allow them to do this in a completely automated way. It not only allows them to validate when they've made a change, it's so simple now that they can run monthly checks, if that's what they want to do, just to make sure that things are running. Config policy updates, employee or visitor onboarding, et cetera, et cetera.
You can imagine the type of things that can be automated, and again, the whole task management aspect and tracking of this can be really important. So, I'd like to, you know, I think, you know, I'd like to hope to broaden people's understanding of the possibilities of SOAR and why independent SOAR is so important to handle all of these different kinds of use cases.
So, I'll close with this. Typically, once we POC to a customer and do a proof of concept, they're sold, they understand the kind of things that can be done.
Typically, as I said, we'll start with those three as their center of interest, but then we show them all the rest and then build it in front of them and show this live in their environment, and that really is an enlightening experience for the customer and important to validate what SOAR can do for them. So, with that, I'll close out, and we'll do perhaps a little bit of open discussion between Alejandro and myself to dive a little deeper in some of these points and get each other to expound, and then we'll go to a Q&A.
Great, Kevin. Thank you so much. That was a really nice presentation. We already have some questions from the audience, but maybe we can first just have an initial, yeah. If we look at, for example, the first question, somebody's asking if you could tell us if you see any emerging use cases in compliance. You talked about IOC advisories and vulnerability management, but if there's any specific area that you think has some potential in the future. Okay.
Well, those are the two areas that we see in terms of, let's call it activity-based compliance, so requirements that are requiring specific actions and proof of those actions in time. Now, there's other aspects of compliance, like reporting, and you might have solution packs for NERC SIP compliance, for example, because OT use cases, by the way, we haven't touched on that, but treating and automating OT risk management and operations is also something that we're seeing.
And so, we've built out, if I'm, for example, in the asset view that I can see the OT assets as well as the IT assets, and I can track the vulnerabilities that might be in those assets and so forth. But beyond the actions, if you will, of having to do something particular because of compliance, especially kind of in real time, tasks that come in, there's also reporting, I guess.
In a long-winded way, I'm trying to say that the tracking of all the activities that are out there, the status, the ability to show what my vulnerability levels have been over the last month and so on and so forth, these things could be important for more reporting perspective. So, those are the ones that we see out there in the wild. I'm interested, though, and if anyone has any other ideas and thoughts about compliance-driven activities that SOAR could possibly help with, I'd love to hear your opinion. Thank you for sharing that, Kevin.
I'd be interested to know if there are some differences with the compliance, let's say, demands that you get from customers in North America versus the ones in Europe. I don't expect you to have an answer now, but that's also something that just came to my mind. I will say this. This is a very general statement, but North America, the US, let me be very clear, is a little faster and looser with compliance requirements than I'm seeing elsewhere.
For example, in the Middle East and also in Asia, we're seeing a lot more, let's call it government presence in security and government-led mandates and government-led validations that are required. So, we're seeing more rigor, I would say, in those areas that's imposed on companies with these IOC updates, for example.
But, and then I would say in Europe right now, I'm feeling at least, and Alejandro, you would have a much better idea, I'm feeling there's a lot more pressure with compliance now overall. And then awareness, even if it's not an absolute directive of the company or the government to implement X or Y or Z technology, they're feeling the pressure and understanding the risk a lot more because of all the publicity around these things.
And so, we see a lot of customers coming in saying, well, I don't have a SIM. I'm told I need to get a SIM, right? And that's a good thing, right? Because a SIM is a requirement, right? For most medium to large organizations.
Yeah, it's very interesting because I've also had some conversations recently with not only SOAR vendors, but from other areas like decentralized identity. And there seems to be a surge in interest from the Middle East. Many of these countries are going through a digital transformation process within the public service.
So, we see a lot of institutions and government agencies having these demands that you talked about. But yes, you're right about Europe. There's more pressure when it comes to staying compliant with the regulations that are constantly changing. Just another question, Kevin, for you. I talked about the value of full SOAR versus bundled into SIM. One of the questions was, what's Kevin's opinion on this?
Ah, well, that's great. I think, and Alejandro, you did speak to this and I think I feel really in line with what you said. And that we talk to customers and try and understand and explain that, of course, the differences and the pros and the cons. But in the end, some customers are very SIM focused. And for that, I mean, the focus, I mean, investigation and response.
Of course, SIM for detection and log collection always. But for investigation and response, they, for one reason or another, SIM, they want that at the top of the pyramid.
So, what we propose there, and I think you're seeing out in the vendors, in general, SIM vendors, is some level of SOAR within the SIM can be bundled within the SIM. So, and think of that as focused on automating SIM-oriented tasks.
So, that's where, that's how we would position it. SIM-oriented tasks, which tend to be investigation, response, and threat hunting, right? And it won't be about the compliance automation or won't be about OT automation or IT automation or probably not even phishing automation, right? These are more standalone SOAR use cases.
So, but back to that, if SIM and SOAR are bundled together, typically that SOAR that you get with the SIM is sort of a SIM helper, if I think of it that way, versus a true independent capable SOAR. So, sometimes we sell both. They want the best automation they can get in the SIM, but they have all the other use cases as well.
So, then you end up with an embedded SOAR and an independent SOAR. But in the end, it becomes, you know, a lot about customer preference and breadth of the use cases that they envision. And then the one caveat I would say out there is, if you're looking at that, you know, get under the covers with the SIM vendor to find out just how much SOAR you get when they say they're SOAR in our SIM, because it will be limited versus a standalone.
Yes, absolutely. There's another question that I think is very interesting. How do you define hyperautomation and what is the hype around that? If I can... Please. I say that hyperautomation is the, let's say, the orchestrated use of multiple automation technologies to automate as much as possible within the business, to automate business and IT processes. I think it's often marketed as a product, but I think it's more of a strategy, more of a mindset. And I think that there's some confusion out there. Some vendors rebrand, let's say, simple enhancements as hyperautomation ready.
So, I think that we have to be careful when we look at this term. But in reality, I think it means coordinating different security tools from SOAR, ITCM, other compliance tools, and trying to leverage as much as we can with the technologies that we talked about, GenAI and potentially agents. But I'm interested to hear what you think about this term, Kevin.
Well, I think I, you know, pretty much in line with you, there was a wave of hype around hyperautomation. And SOAR is dead, hyperautomation is here. And to the best of my knowledge and, you know, talking to customers and comparing, having customers take a look at multiple vendor products, hyperautomation as a product is more defined by multiple use cases, ease building playbooks, use of AI. And I hope I just conveyed that that's everything that SOAR does.
So, I think that it's just, if you will, thinking about an advanced SOAR, if you will, a SOAR that hasn't become legacy and not embracing new technologies. And there's a couple of vendors out there who I think their SOAR is getting rather rusty. But most of the vendors that I compete with are not hyperautomation, yet we have all the same capabilities that hyperautomation has. I do like your definition, hyperautomation, meaning more of an approach, a strategy.
And I think that's more in line with what I've read from other analysts as well, when they speak about hyperautomation across the enterprise. Yes, because I think ultimately it's a business decision if this is something that that particular organization wants, and they must have some kind of expectations on what are going to be the benefits if we pursue this option. We have one more question for you, Kevin. Are there MSSP focus features in FortiSOAR?
Yeah, that's, I appreciate you bringing that up, because, you know, to be concise today, we didn't really touch much on MSSPs and the use cases and product features for those. And typically, for example, we'll do at Fortinet, I will do a separate presentation on SOAR that is for MSSPs, and talk about their issues, and then how the product helps solve them. So I've pulled all separate, you know, presentations and separate written materials oriented towards MSSPs.
But to briefly answer your question is yes, there are a bundle of features that are both, let's call it UX experience features, but also management features and implementation features. So a classic use case, or classic example, I suppose, is the concept of multi-tenancy, right? When a MSSP, or sometimes a large enterprise who's doing automation across multiple divisions, they will have a SOAR instance, excuse me, dedicated to each customer.
So if I have 100 customers, I will have 100 different SOAR tenants that will work independently, allow an analyst to work strictly on that customer's alerts, and protect that customer's data, and separate it from another customer's data. So all the way from RBAC of who can use that instance, all the way through the way it's used, multi-tenancy is a really important factor, and the scalability that that is required as well. So there's two types of tenants, you know, to go just a little bit deeper.
There are tenants that are housed in the main SOAR instance, and kind of typically, if you think about a SAS implementation of an application, that's the way it works in SOAR. So you have these multiple instances for each customer running in the SOAR. You can also dedicate a SOAR instance to particular customers, because they may have some compliance or other risk management options.
It says, I never want my data in the same tenant, or in the same system as anyone else. And then the I want the SOAR on-prem. I don't want the SOAR even in the cloud, because I'm that worried about compliance and data risk. And so you can have a dedicated tenant that is running on the customer prem.
Now all of that's managed centrally, with dashboard central, with playbooks that can be run across all of those tenants, and then also an automatic customization capability that says, well, I've got this type of playbook, but when I run it in this tenant, I want it customized automatically this way, or that way, or that way. So that's just one example that, and depending on how the vendor implements, the SOAR vendor implements those features, and also how they charge for them. It can be very expensive per tenant, or in the case of 40 SOAR, it's free.
We don't charge based on the number of tenants that are housed together. So you can grow customers without growing price. That's great. I'm happy you talked about this. I often get questions around scalability and flexibility. So I appreciate you getting deeper into this question. We have one final question, and it's a question for both of us. What innovations do we foresee coming in SOAR?
If I can go first, I'd say that based on my research last year, I remember a lot of vendors talking about gen AI assistants, low-code drag-and-drop playbooks was another, just trying to offer different customizable options for the users. Unified dashboards was another one. But I think in the future, we talked a lot about some of these emerging use cases, as well as the technologies that we see. So autonomous agents driven by LLMs, but as we talked about, it's work that remains to be seen. Still nothing concrete yet. Another one would be, perhaps, continuous playbook optimization.
And we also talked a little bit about having more integrations with identity systems. We talked about ITDR. I think a very interesting area. But I'm interested to see what you think, Kevin. It's going to be driving SOAR in the next months or years.
Well, I'll start for the moment with the last thing that you mentioned, because we didn't really talk about this, other than your introduction with ITDR. One of the things, of course, customers and as the threat landscape changes and new types of products are coming out, detection products, we see SOAR being sold alongside them.
So, for example, NDR, network detection response, we sell a lot and talk to customers about deception, for example, as another emerging technology out there. Also, attack surface management as an important detection technology. And as they deploy these, if they're deploying them separately, the question is, when this new product generates an alert, what am I going to do? And the idea is, well, pass that alert into SOAR, and it can be investigated there, interacting further with the ASM system or NDR, whatever it might be, assigned to an analyst, just like something that came out of a SIM.
So, we see that happening as a – I wouldn't say today thing – and a concrete use of SOAR to pull these new technologies into more of a standardized treatment environment. But I think if I were going to speak for a moment to the rest of the question or to other aspects of it, I think that the Gen AI and the Gentic AI aspect of things is really going to be where – have the most impact, both in making today's activities simpler and better, as Alejandro said, about playbook building. Playbook optimization is also really interesting.
So, this idea of having these agents, if you will, that are really focused, not general like things are today with an LLM that's kind of a – as we might say, ability to do all, kind of jack-of-all-trades, but master of none. Think of focused LLM and focused agents that are packed with information about playbooks and how to execute them, or packed with information that's all about threat hunting or threat analysis or remediation activities and so forth.
So, I see that as having the hugest impact and really, really empowering SOAR to be so much more than centralization and automation and pulling threat intelligence information into a same place, but being much more automatically action-oriented. You know, we are hesitating to use the word autonomous too much because really, as Alejandro covered as well, we really believe that it can help with decision-making and work – you know, this other level of decision-making that we can add now to SOAR that's beyond automation.
It's decision-making and then automation below it, if you will, or as part of that. It's still going to be a heavy, heavy human in the loop for a long time.
And so, that balance of that, those activities, and that depth of capability, that's where, you know, you'll see the first results of this kind of push less than a year from now that are concrete and demonstrable. Yes, absolutely.
Yeah, I think that vendors are going to have to do – put some effort in educating the market and being fully transparent and explainable when it comes to adding all of these new automation features because there will be a lot of questions from organizations on many different areas. I think that we're now running a little bit out of time, so I will just quickly go through these last slides. We have a lot of research on the topic, and as I mentioned, we will be doing an update on the Leadership Compass by next year in the summer.
And as Kevin said, things are going to be looking quite interesting by then. I think that the market is changing. It's evolving. We see new things coming out every month.
So, I'm excited for the new report. So, please stay tuned. We will also be having our Impact Day event. The next one will be in Frankfurt in November. And our different services that we have at Copernicol.
So, I really hope that you enjoyed today's webinar, that you learned some new things during the conversation. Please feel free to reach out to me or to Kevin if you have any questions.
And Kevin, it was a pleasure talking to you. Thank you for joining me. My pleasure. Thank you very much. Hope to continue the conversation in the future. And thank you all for – Thank you.
See All Locations
See All Locations