SOAR
Also known as Security orchestration, automation and response
Tooling that automates the repetitive parts of responding to an alert, such as isolating a device or disabling an account.
Analysts spend a large share of their time on the same handful of steps: enrich the alert, check reputation, look up the user, contain if confirmed. SOAR encodes those into playbooks that run in seconds instead of minutes.
The benefit is consistency and speed rather than headcount reduction. Automated containment at 3am buys back the hours that used to pass before a human saw the alert.
Where this comes up
SOAR sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.