Top 3 Market Trends for SOAR Solutions

The year 2020 was a rollercoaster ride for all of us across the globe, and the challenges persist into 2021. Security analysts and SOCs faced a new set of obstacles, including the advent of COVID-19 related phishing attacks and increased security risks as a result of more employees working from home. Unfortunately, these new challenges did not negate the old ones. Security teams today are still overwhelmed by a never-ending barrage of cyberattacks, immense workloads, and fast burnout rates.

This is not a sustainable working environment and teams must find a new apparatus to tackle the abundance of incoming threats and security alerts. Many security analysts have realized, especially over the past year, that adding a security orchestration, automation, and response (SOAR) tool to their toolkit can help decrease workloads, respond to incidents faster, and automate alert triage, investigation, and response.

Gartner recently released their 2020 SOAR Market Guide. It provides valuable insights into the must-have capabilities provided by a SOAR, the trajectory of the technology and marketplace, and recognizes Splunk Phantom amongst a representative list of SOAR vendors in alignment with Gartner’s vision.

Let’s take a look at a few notable insights from Gartner’s research:

1. “Orchestration and automation, basic incident/case management, and operationalizing threat intelligence are ‘table stakes’ for SOAR tools.” Many security teams turn to SOAR solutions to help reduce alert fatigue, mean time to respond, and overall workload. With orchestration and automation, analysts no longer have to spend hours manually executing actions across a multitude of point products to investigate and remediate threats. Instead, the analyst can have a SOAR tool automate actions, without human interaction, across different products in a matter of seconds. This not only saves time, but frees the analyst to focus on mission critical tasks.

Capabilities such as automated alert triage help the analyst prioritize the highest risk alerts; case management helps analysts coordinate a comprehensive investigation or response at a faster rate; and automated threat intelligence empowers analysts to make better educated decisions backed by data.

Based on Gartner’s recommendations for evaluating SOAR capabilities, Splunk Phantom offers all of the above and more, including:

Some of the most common security use cases for Splunk Phantom customers include alert triage, ransomware response, and phishing email triage. And although most of the use cases for orchestration and automation in the market are security related, our customers habitually use Splunk Phantom for non-security use cases such as ticket creation and processing, service monitoring and investigation, and network access control.

3. “Security information and event management vendors continue to add SOAR capabilities via acquisitions, OEM agreements or internal development; however, the solutions are still primarily sold as premium add-ons and not being merged with SIEM tools.”SIEM and SOAR technologies, when used together in a security workflow, greatly complement one another. The SIEM collects and organizes information and detections from your various security tools, analyzes that activity and provides insights, and then generates alerts. Then, the SOAR tool will automatically triage those alerts, and orchestrate automated responses to those alerts. In other words, while the SIEM “observes” and “orients” the security team to potential malicious activity in their environment, the SOAR tool then automates the decision-making and actions (executed by your other various security tools) to resolve such activity.

Splunk is one of the few vendors on the market that offers both SIEM and SOAR in their security portfolio. We are proud that Splunk Enterprise Security is recognized by Gartner as a leader in the 2020 Gartner Magic Quadrant for SIEM.

To learn more about the general market trends for SOAR, investment recommendations, and how Splunk Phantom aligns with Gartner’s vision for SOAR, download a complimentary copy of the 2020 Gartner SOAR Market Guide.

----------------------------------------------------
Thanks!
Kelly Huang

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.