* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What is SOAR?
What is SOAR?
=============
Published  February 10, 2026•*5*-minute read
Copy URL
Jump to section
---------------
OverviewCase and workflow managementTask automation and orchestrationWhy automate security processes?Automation vs. orchestrationCentralized threat intelligenceDevSecOpsHow can Red Hat help?
Overview
--------
Security orchestration, automation, and response (SOAR) describes a set of capabilities used to protect IT systems from threats.
SOAR refers to 3 key software capabilities that cybersecurity teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence. The term SOAR comes from analyst group Gartner. Security analysts also describe SOAR with other terms: IDC refers to the concept as Security Analytics, Intelligence, Response, and Orchestration (AIRO), and Forrester describes the same capabilities as Security Automation and Orchestration (SAO).
SOAR is usually implemented in coordination with an organization’s Security Operations Center (SOC). SOAR platforms monitor threat intelligence feeds and trigger automated responses to security issues, which can help IT teams to quickly and efficiently mitigate threats across numerous complex systems.
Case and workflow management in SOAR
------------------------------------
Whether you have a mature and established SOC or you are just beginning your organization’s security transformation, best practices for vulnerability management prescribe that every security incident be documented and managed as a case. Case management practices are the means by which incidents are documented and knowledge surrounding the threat is created. This ensures that security threats are identified, prioritized based on risk, and investigated. It also makes it possible for the intelligence gathered responding to an incident to be documented and shared within organizations and communities.
SOAR technology frequently comes with pre-configured workflows for common use cases. If these default use cases do not meet your organization's specific needs they can be adapted to your requirements through custom development.
[Learn more about SOAR at the Enterprisers Project](https://enterprisersproject.com/article/2020/10/what-is-soar-security-orchestration-automation-and-response)
Red Hat resources
-----------------
[Keep reading](/en/resources "Keep reading")
Task automation and orchestration
---------------------------------
Security automation is the process of executing security operations tasks without the need for human intervention. In security, the need for automation is heightened due to the complexity of infrastructure and the likely lack of integration between its various parts. But how do we know which tasks to automate? Ask yourself:
1. **Is the task routine?** Does it need to be done on a regular basis?
2. **Is the task tedious?** Does it involve a specific set of actions that need to be completed precisely?
3. **Is it time consuming?** Does this set of actions consume a significant amount of your team’s time?
Answering "Yes" to any of these questions suggests that automation can help. There are potentially many positive outcomes for your organization including: reduced human error, greater efficiency and speed, and improved consistency in security incident response.
[Read more about security automation](/en/topics/automation/what-is-security-automation "article | what is security automation")
Why automate security processes?
--------------------------------
A primary benefit of task automation is that it allows security teams to be more efficient, freeing up their time to be spent elsewhere. As there simply aren’t enough security professionals to meet every organization's needs, automation can help to bridge this talent gap by helping security teams do more and do it faster.
Security teams must contend with a huge set of different tools and products—like Endpoint Detection and Response (EDR) software, firewalls, and [security information and event management (SIEM)](/en/topics/security/what-is-SIEM) solutions—which are probably not integrated with one another. Manually managing all of this can result in slower detection and remediation of issues, errors in resource [configuration](/en/topics/automation/what-is-configuration-management), and inconsistent policy application, leaving systems vulnerable to serious attacks and compliance issues. Automation can help streamline daily operations as well as integrate security into processes, applications, and infrastructure from the start, as with a [DevSecOps](/en/topics/devops/what-is-devsecops) approach.
According to the Ponemon Institute, detecting and containing security breaches within 200 days or less reduces the average cost of a breach by an average of [US$1.22 million](https://www.ibm.com/security/data-breach). Fast threat detection can reduce the likelihood of a security breach and the associated costs, but remediation across multiple platforms and tools can be complicated, time-consuming, and error-prone.
While manual processes can delay threat identification in complex IT ecosystems, automating security processes can help organizations identify, validate, and escalate threats faster, without manual intervention. Security teams can use automation to improve response times and concurrently apply remediation to affected systems across their environments.
[Learn why to choose Red Hat for automation](/en/topics/automation/why-choose-red-hat-for-automation "article | Why choose Red Hat for automation")
What’s the difference between automation and orchestration?
-----------------------------------------------------------
Orchestration is process-based and automation is task-based. Security orchestration is the means by which you connect and integrate disparate security tools and systems in order to streamline your response workflows. By connecting your tools and systems—and the processes that govern them—you can take advantage of automation across your environments.
Automation can simplify workflows, but *people* are required for one of the most valuable aspects of SOAR: high-level security orchestration. Orchestration allows IT teams to define the process by which automated tasks are executed. The orchestration of security processes relies on the people of these teams to determine the what, why, and when of security automation.
[Read more about orchestration](/en/topics/automation/what-is-orchestration "article | What is orchestration?")
Centralized threat intelligence
-------------------------------
Threat intelligence refers to knowledge about existing and emerging threats to your organization’s assets. Many vulnerability databases exist as sources of threat intelligence. Reference methods, like the [CVE](/en/topics/security/what-is-cve) list, make it easier to identify and share these vulnerabilities across databases and platforms. Threat intelligence platforms collect this knowledge from a variety of feeds. SOAR tools use multiple threat intelligence feeds to identify potential threats. SOAR aggregates these feeds into a unified source that can be queried by teams and used to trigger automation tasks.
Organizationally, your SOC is the core of your security response, but it can still be difficult to coordinate and communicate with the many departments that comprise your business. Automation can serve as a unifying force and common language between departments. An automation solution across all of your platforms—in every department—can establish clear channels of interaction that make it easier to identify and triage the most urgent security threats.
[Learn more about security automation with Ansible Automation Platform](/en/technologies/management/ansible/security-automation)
Shift security left in DevOps practices
---------------------------------------
A cultural shift can improve security by changing where in the development process security is considered. The term “[DevOps](/en/topics/devops)” describes approaches to speeding up the processes by which an idea goes from development to deployment in a production environment. In the past, the role of security was isolated to a specific team in the final stage of development. When development cycles lasted months or even years, that wasn’t as problematic, but now, we often deliver apps within weeks. In the collaborative framework of DevOps, security can become a shared responsibility integrated from end to end and referred to as "[DevSecOps](/en/topics/devops/what-is-devsecops).”
Like DevOps, DevSecOps is a cultural model. In the thinking of DevSecOps, risk management is considered throughout the development process. Security-minded companies are often the first to adopt DevSecOps methodologies, where developers work closely with security teams and implement measures earlier in the development life cycle—also known as “shifting left.”
No matter the cultural groundwork laid, successfully implementing DevSecOps relies on automation. This automation may include source control repositories, container registries, CI/CD pipeline, API management, and operational management and monitoring.
How can Red Hat help?
---------------------
Enterprise [open source](/en/topics/open-source/what-is-open-source) software uses a [development model](/en/about/development-model) that enhances testing and performance tuning—usually with a security team that stands behind it. It improves processes for responding to new security vulnerabilities and protocols to notify users about security issues with remediation steps. It's an enhanced version of the [open source web of trust](/en/blog/open-source-web-trust) that makes sure you're never alone when it comes to IT security.
With a [Red Hat® Ansible® Automation Platform](/en/technologies/management/ansible) subscription, you can automate, [orchestrate](/en/technologies/management/ansible/orchestration), and integrate different security solutions to simplify investigation and response to threats across the enterprise in a coordinated, unified way using a curated collection of modules, roles, and playbooks. You can also integrate external applications using APIs, SSH, WinRM, and other standard or pre-existing access methods.
Ansible Automation Platform enables full-stack processes, from infrastructure to applications, allowing everything to be coordinated with a layer of security technologies. And security operations teams can use Ansible Automation Platform to manage other enterprise applications, like SOAR solutions.
Additionally, Red Hat’s expertise in open hybrid cloud gives us a unique perspective on implementing cloud security to guard against cyberthreats and cyberattacks. Adopting a [zero trust](/en/topics/security/what-is-zero-trust) model can change the security perspective of an organization and realign security policies.
Recommended for you
E-book
The cost of human error and the advantages of automation
--------------------------------------------------------
Learn about the benefits of modernizing your monolithic Java applications using cloud-native and microservice architectures and approaches.
[Read the e-book](https://www.redhat.com/en/resources/advantages-security-automation-e-book?percmp=RHCTG0250000455234)
Recommended for you
Enterprise Kubernetes Storage with Red Hat OpenShift Data Foundation
--------------------------------------------------------------------
Learn the essential skills required to design, implement, and manage a Red Hat OpenShift Data Foundation cluster and perform day-to-day Kubernetes storage management tasks
[View course](https://www.redhat.com/en/services/training/do370-enterprise-kubernetes-storage-with-red-hat-openshift-data-foundation?percmp=RHCTG0250000455236)
Keep reading
------------
### What's an insider threat?
An insider threat is leaked or misused data that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
[Read the article](/en/topics/security/what-are-insider-threats "article | What's an insider threat")
### What is post-quantum cryptography?
Learn about Red Hat’s approach to post-quantum cryptography, which refers to encryption algorithms that can resist attacks from quantum computers.
[Read the article](/en/topics/security/post-quantum-cryptography "What is post-quantum cryptography?")
### What is lightweight directory access protocol (LDAP) authentication?
Lightweight directory access protocol (LDAP) is a protocol that helps users find data about organizations, persons, and more. It stores data in the LDAP directory and authenticates users to access the directory.
[Read the article](/en/topics/security/what-is-ldap-authentication "article | what is lightweight directory access protocol ldap authentication")
Security resources
------------------
### Related content
* Blog post
  [Zero CVEs: The symptom of a larger problem](/en/blog/zero-cves-symptom-larger-problem)
* Blog post
  [Extend trust across the software supply chain with Red Hat trusted libraries](/en/blog/extend-trust-across-software-supply-chain-red-hat-trusted-libraries)
* Blog post
  [Chasing the holy grail: Why Red Hat’s Hummingbird project aims for "near zero" CVEs](/en/blog/chasing-holy-grail-why-red-hats-hummingbird-project-aims-near-zero-cves)
* Blog post
  [Elevate your vulnerabiFrom challenge to champion: Elevate your vulnerability management strategy lity management strategy with Red Hat](/en/blog/elevate-your-vulnerability-management-strategy-red-hat)
### Related articles
* [Why choose Red Hat for automation?](/en/topics/automation/why-choose-red-hat-for-automation)
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [What's an insider threat?](/en/topics/security/what-are-insider-threats)
* [What is an Ansible Playbook?](/en/topics/automation/what-is-an-ansible-playbook)
* [How to build an IT automation strategy](/en/topics/automation/build-an-automation-strategy)
* [Learning Ansible basics](/en/topics/automation/learning-ansible-tutorial)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [Ansible vs. Chef: What you need to know](/en/topics/automation/ansible-vs-chef)
* [Ansible vs. Puppet: What you need to know](/en/topics/automation/ansible-vs-puppet)
* [Ansible vs. Salt: What you need to know](/en/topics/automation/ansible-vs-salt)
* [Ansible vs. Terraform](/en/topics/automation/ansible-vs-terraform)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [What is IT service management (ITSM)?](/en/topics/automation/what-is-it-service-management-itsm)
* [Automating Microsoft Windows with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-microsoft-windows-with-ansible)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [What is DevOps automation?](/en/topics/automation/what-is-devops-automation)
* [What is Infrastructure as Code (IaC)?](/en/topics/automation/what-is-infrastructure-as-code-iac)
* [Ansible vs. Kubernetes: how they work together](/en/topics/automation/Ansible-vs-Kubernetes)
* [What is cloud migration? And how can automation help?](/en/topics/automation/what-is-cloud-migration)
* [What is a configuration management database (CMDB)?](/en/topics/automation/what-is-a-configuration-management-database-cmdb)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is a software-defined data center (SDDC)?](/en/topics/automation/what-is-a-sddc)
* [What is IT automation?](/en/topics/automation/what-is-it-automation)
* [Why choose Red Hat Ansible Automation Platform as your AI foundation?](/en/topics/automation/automation-and-ai)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is virtual infrastructure management? And how can automation help?](/en/topics/automation/virtual-infrastructure-management)
* [What is IT migration?](/en/topics/automation/what-is-it-migration)
* [How to automate migrations with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-migrations-with-red-hat-ansible-automation-platform)
* [Why use Red Hat Ansible Automation Platform with Red Hat OpenShift?](/en/technologies/cloud-computing/openshift/ansible-on-openshift)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [What is CloudOps?](/en/topics/automation/what-is-cloudops)
* [Red Hat Satellite on Red Hat Enterprise Linux](/en/technologies/management/satellite/satellite-for-rhel)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [Which Red Hat Ansible Automation Platform deployment option is right for you?](/en/technologies/management/ansible/ansible-deployment-options)
* [What is an Ansible module—and how does it work?](/en/topics/automation/what-is-an-ansible-module)
* [How to manage and automate applications at the edge](/en/topics/edge-computing/how-to-manage-automate-applications-edge)
* [How to build an automation Center of Excellence](/en/topics/automation/how-to-build-automation-center-of-excellence)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [What is orchestration?](/en/topics/automation/what-is-orchestration)
* [How to adopt Automation as Code: Extending Infrastructure as Code into Policy as Code](/en/topics/automation/how-to-adopt-automation-as-code)
* [What is a webhook?](/en/topics/automation/what-is-a-webhook)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is an Ansible Role—and how is it used?](/en/topics/automation/what-is-an-ansible-role)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [What is data management?](/en/topics/data-services/what-is-data-management)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is NetOps?](/en/topics/automation/what-is-netops)
* [What is an Ansible Rulebook?](/en/topics/automation/what-is-an-ansible-rulebook)
* [What is edge security?](/en/topics/security/what-is-edge-security)
* [What is configuration management](/en/topics/automation/what-is-configuration-management)
* [What is event-driven automation?](/en/topics/automation/what-is-event-driven-automation)
* [Zero-Touch Provisioning and telco automation with Red Hat](/en/topics/telecommunications/zero-touch-provisioning-and-telco-automation-at-red-hat)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is infrastructure automation?](/en/topics/automation/what-is-infrastructure-automation)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is YAML?](/en/topics/automation/what-is-yaml)
* [What is provisioning?](/en/topics/automation/what-is-provisioning)
* [Understanding Ansible, Terraform, Puppet, Chef, and Salt](/en/topics/automation/understanding-ansible-vs-terraform-puppet-chef-and-salt)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is cloud orchestration?](/en/topics/automation/what-is-cloud-orchestration)
* [What is security automation?](/en/topics/automation/what-is-security-automation)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [What is a configuration file?](/en/topics/linux/what-configuration-file)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [Ansible vs. Red Hat Ansible Automation Platform](/en/technologies/management/ansible/ansible-vs-red-hat-ansible-automation-platform)
* [What is cloud automation?](/en/topics/automation/what-is-cloud-automation)
* [What is network automation?](/en/topics/automation/what-is-network-automation)
* [What are managed IT services?](/en/topics/cloud-computing/what-are-managed-it-services)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [What is business process management?](/en/topics/automation/what-is-business-process-management)
* [What is patch management (and automation)?](/en/topics/management/what-patch-management-and-automation)
* [What is the Red Hat Ansible Automation Platform automation controller?](/en/technologies/management/ansible/automation-controller-product-feature)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [What is business process automation?](/en/topics/automation/what-is-business-process-automation)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [What is IT process automation?](/en/topics/automation/what-is-it-process-automation)
* [What is deployment automation?](/en/topics/automation/what-is-deployment-automation)
* [What is business optimization?](/en/topics/automation/business-optimization)
* [What is Kubernetes cluster management?](/en/topics/containers/what-is-kubernetes-cluster-management)
* [What is SRE?](/en/topics/devops/what-is-sre)
* [What is risk management?](/en/topics/management/what-is-risk-management)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is API security?](/en/topics/security/api-security)
* [What is network management?](/en/topics/management/what-is-network-management)
* [What is robotic process automation (RPA?)](/en/topics/automation/what-is-robotic-process-automation)
* [What is financial services security (and compliance)?](/en/topics/security/security-and-compliance-financial-services)
* [What is an SOE?](/en/topics/management/what-is-an-soe)
* [What is IT system life-cycle management?](/en/topics/management/it-system-life-cycle-management)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
* [What is cloud management?](/en/topics/cloud-computing/what-is-cloud-management)
* [What's business automation?](/en/topics/automation/whats-business-automation)
[More about this topic](/en/topics/security "More about this topic")