FoundationsVerified 19 Jun 2026
What Is SOAR? Security Orchestration, Automation, and Response Explained for 2026
SOAR is the SOC's reflex arc: take an alert, enrich it with context, decide, and act. Gartner coined the term in 2017 and the category became table-stakes by the end of the decade.
2017
Gartner coined the SOAR acronym
3
Pillars: Orchestration, Automation, Response
16
Notable SOAR vendors we track
$0-$1.5M+
Annual cost range, free Community to enterprise
The three pillars
Orchestration is making different tools work together. Automation is replacing analyst clicks with code. Response is the part where something actually changes (a credential is revoked, a host is isolated, a ticket is created with full context). SOAR is the layer that makes those three pillars stand up.
“SOAR exists because every SOC team has the same conversation: we have too many alerts, our analysts are spending hours doing the same five things, and our SIEM cannot make decisions.”
Position in the SOC stack
SOAR sits above detection (SIEM, XDR, EDR) and beside ticketing (ServiceNow, Jira). It reads alerts, calls enrichment APIs (threat intel, IdP, asset DB), makes a decision per the playbook, and executes response actions.
- Step 01DetectionSIEM / XDR / EDR fires an alert
- Step 02IngestSOAR receives the alert via API or webhook
- Step 03EnrichTI lookups, IdP lookups, asset context
- Step 04DecidePlaybook logic + analyst-in-the-loop where needed
- Step 05ActIsolate / revoke / ticket / notify
- Step 06CloseUpdate case, push lessons learned
When SOAR became table-stakes
- 2017 - Gartner publishes the first SOAR Market Guide.
- 2019 - Palo Alto acquires Demisto, the original modern SOAR.
- 2020 - Splunk acquires Phantom; IBM positions Resilient.
- 2022 - Google acquires Siemplify; Gartner publishes the final standalone SOAR MQ.
- 2023 onward - SOAR features increasingly bundled inside SIEM, XDR, and Cloud SecOps suites; standalone SOAR remains a category for buyers wanting vendor-neutral orchestration.