Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Legacy SOAR friction: what security teams are missing in SOC triage


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A Global 1000 security team described four years of daily friction with ServiceNow SOAR, then moved to Morpheus after seeing alert stories, traceable reasoning, and case memory assembled across EDR, identity, email, cloud, and network telemetry, according to D3. The broader lesson is that SOC tooling is now judged by investigation coherence and auditability, not orchestration depth alone.

NHIMG editorial — based on content published by D3: the SOC move from ServiceNow SOAR to Morpheus

Questions worth separating out

Q: What breaks when legacy SOAR does not preserve investigation context?

A: Analysts waste time rebuilding the same case across multiple tools, handoffs become inconsistent, and audit trails get weaker because the reasoning behind response actions is scattered.

Q: Why do identity signals matter in AI-driven SOC investigations?

A: Identity signals matter because many security decisions depend on who acted, from where, with what access, and whether the behaviour fits the user's normal pattern.

Q: How do you know if SOC automation is actually helping?

A: SOC automation is helping when it reduces repetitive work, improves triage quality, and shortens the time between signal and decision.

Practitioner guidance

  • Audit investigation handoff friction across the SOC Track how often analysts must reopen EDR, identity, email, cloud, and network tools to complete a single case.
  • Test traceability before trusting automated verdicts Require a visible evidence-to-conclusion trail for alerts that can trigger account disablement, isolation, or escalation.
  • Keep human approval on disruptive containment actions Allow automation to prepare recommendations and gather evidence, but reserve approval for actions that affect accounts, hosts, or service availability.

What's in the full article

D3's full article covers the operational detail this post intentionally leaves for the source:

  • The demo-based comparison between ServiceNow SOAR and Morpheus in day-to-day SOC workflows
  • The migration experience, including how case history and parallel run support the cutover
  • The product-specific handling of IT requests such as patching hosts or disabling accounts
  • The self-learning and adaptive tasking behaviour described for analyst-assisted investigations

👉 Read D3's analysis of the SOC move off ServiceNow SOAR →

Legacy SOAR friction: what security teams are missing in SOC triage?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Investigation quality is becoming the real SOAR differentiator. The market has spent years treating orchestration breadth as the main buying criterion, but this article shows that analysts now feel the pain of fragmented investigation more acutely than the appeal of another automation rule. When identity, endpoint, email, cloud, and network evidence do not converge into one case view, the SOC pays in time, consistency, and defensibility. The practical conclusion is that investigation coherence has become a first-order platform requirement.

A question worth separating out:

Q: How should teams decide when to keep human approval in the loop?

A: Keep human approval whenever a response can disrupt service, alter access, or change a production system. Use automation to assemble context, recommend actions, and prefill requests, but require a person to approve irreversible or high-impact steps. That keeps accountability aligned with operational risk.

👉 Read our full editorial: SOC triage friction is driving teams to replace legacy SOAR



   
ReplyQuote
Share: