Securing DoD Systems — A Look at SOAR

It would be hard to overstate the critical importance of security orchestration, automation and response (SOAR) capabilities for the effective mission success of security operations centers (SOC). Without a solid SOAR capability in place, an SOC will be easily overwhelmed with routine and repetitive tasks that in and of themselves could become a vulnerability.

During his confirmation hearing before the Senate Armed Services Committee in October, DoD CIO John Sherman highlighted the continued focus of the Department on ensuring the effective cybersecurity of its networks. While specific attention has been given to the rollout of the zero trust approach, security automation also plays an important role. In his responses to the Committee’s advance policy questions, Sherman rightly noted that “[t]he scope and scale of the information cyber operations and security organizations need to perform their duties is vast and requires automation, big data analytics, and visualization to reach their full potential” and that “[t]he Department has been making significant investments to accelerate digital modernization, and are working towards real-time direction and orchestration in all areas.” Likewise, in the current edition of the Defense Information Systems Agency (DISA)’s Strategic Plan automation is mentioned multiple times. Perhaps most notably is the focus on automating enterprise cybersecurity solutions.

For several years Congress has pushed DoD to add SOAR to its cybersecurity tool chest. This year’s NDAA, signed by President Biden in late December, is no different. Section 1529 of the FY2022 NDAA calls for the DoD CIO, acting through DISA, to complete a demonstration and assessment of automated security capabilities by October 2024. The Senate Armed Services Committee in particular is insistent on the need for DoD to fully utilize automated cyber capabilities. In the report that accompanied their version of the FY2022 NDAA, the Committee again pointed to prior years’ direction to the Department to carry out pilot programs on SOAR. In this year’s report they went a step further and recommended an authorized appropriations increase of $25 million specifically for SOAR pilot programs at Joint Force Headquarters, Department of Defense Information Network (JFHQ-DODIN).

It can be incredibly difficult to implement and further build upon these policy and legislative requirements in an unpredictable appropriations cycle. As of this writing, DoD and the rest of the federal government continues to operate under a Continuing Resolution. While the hope is to have a full year omnibus appropriation in the near future, the continued start/stop appropriations process year after year continues to hinder the effective cyber operations of the federal government. A return to regular budgetary order would allow departments and agencies to more effectively utilize SOAR capabilities to protect critical infrastructure and national security systems. SOAR produces a strong return on investment through faster or real time alerts and solutions and a stronger collective cyber defense.

For more information, check out Splunk’s cybersecurity orchestration and automation capabilities here!

Related Articles

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues
Industries
3 Minute Read

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues

Dive into how Splunk aligns with key priorities highlighted at EDUCAUSE 2025.
Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions
Industries
3 Minute Read

Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions

Splunk helps government agencies boost security and efficiency with powerful, mission-ready AI and automation.
Solving Manual Mayhem in Telecom with Agentic AI
Industries
3 Minute Read

Solving Manual Mayhem in Telecom with Agentic AI

Agentic AI cuts downtime, improves security, and boosts customer experience, and with unified data from Splunk and Cisco, teams can build more resilient operations.
Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers
Industries
2 Minute Read

Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers

Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0 deliver the most secure, stable, and modernized platform for a digitally resilient and compliance-ready future.
Building the Next Generation of Defenders: From the Classroom to the SOC of the Future
Industries
3 Minute Read

Building the Next Generation of Defenders: From the Classroom to the SOC of the Future

Resilience in the AI era doesn’t just happen – it's built one student, one SOC, and one organisation at a time.
Analytics That Work: 3 Approaches for the Future of Contact Centers
Industries
3 Minute Read

Analytics That Work: 3 Approaches for the Future of Contact Centers

Splunker Khalid Ali explains how unified, real-time intelligence connects data, empowers agents, and builds lasting customer loyalty.
Observability + Security: Real-Time Digital Resilience for SLED
Industries
1 Minute Read

Observability + Security: Real-Time Digital Resilience for SLED

Cisco and Splunk are helping public sector organizations build digital resilience.
Digital Resilience for State and Local Governments (Part Two)
Industries
3 Minute Read

Digital Resilience for State and Local Governments (Part Two)

Discover how collaboration—powered by shared data platforms like Splunk—can enhance incident response and overall digital resilience.
Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?
Industries
2 Minute Read

Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?

Discover key insights from SIBOS 2025 on how AI, collaboration, and data will reshape financial services over the next 5 years—prepare for rapid change and exciting opportunities ahead.