Back to Field Notes
Security Operations/Field Note

SOAR — Avoiding the Shelf-Ware Trap

Automate stable processes, not chaotic ones. The SOAR program that succeeds is the one that automates last, not first.

Author

Yusuf Ahmed

Principal Engineer, Platform Security

Published

April 2, 2026

Read

9 min

Share
AI-generated illustration of a power grid substation
AI-generated illustration of a power grid substation
Key Takeaways
  • 01SOAR platforms commonly become shelf-ware because they are purchased before the SOC has stable processes to automate. Result: automation of the wrong steps and a tool gathering dust six months later.
  • 02Right sequence: stabilize the manual process (runbook, ownership, SLA) → measure the steps that actually consume time → automate the highest-cost stable step first → iterate (observe, refine, expand). Resist the temptation to automate the most complex step first.
  • 03Steps that consistently pay back: phishing triage and user notification, IOC enrichment from threat intel platforms, disable user / lock device on confirmed compromise, block IOC at firewall and SWG, open ticket with full context attached. Each is bounded, well-understood, high-volume.
  • 04Steps that should not be fully automated yet: lateral movement containment without analyst review, major-account takeover response, customer-facing incident communications. The risk of automated wrong action exceeds the time saved.

Security Orchestration, Automation, and Response platforms are commonly purchased early — often before the SOC has stable processes to automate. The result is automation of the wrong steps and a tool that gathers dust six months later.

The right sequence

  • 01Stabilize the manual process — runbook, ownership, SLA
  • 02Measure the steps that actually consume time
  • 03Automate the highest-cost stable step first
  • 04Iterate — observe, refine, expand
  • 05Resist the temptation to automate the most complex step first

Steps that consistently pay back when automated

Phishing triage and user notification. IOC enrichment from threat intel platforms. Disable user / lock device on confirmed compromise. Block IOC at the firewall and SWG. Open a ticket with full context attached. Each is bounded, well-understood, and high-volume.

Steps that should not be fully automated yet

Lateral movement containment without analyst review. Major-account takeover response. Customer-facing incident communications. The risk of automated wrong action exceeds the time saved.

#SOAR#Automation#Operations

/WRITTEN_BY

Yusuf Ahmed

Principal Engineer, Platform Security · Alexa Cybersecurity