Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should security teams combine SOAR and AI…
Cyber Security

How should security teams combine SOAR and AI to improve incident response without over-automating?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Cyber Security

Security teams should use AI to enrich, correlate, and prioritise alerts, then let SOAR execute the repeatable response steps. The right model is human guided automation, where AI handles pattern recognition and context while playbooks remain constrained by policy. That reduces noise, speeds triage, and limits the risk of a rigid workflow taking the wrong action on incomplete data.

How SOAR and AI Should Divide the Work in Incident Response

SOAR and AI improve incident response when they play different roles rather than competing for the same decisions. AI is best used to enrich alerts, correlate indicators, summarise context, and surface likely priorities. SOAR is best used to execute bounded, repeatable actions such as ticketing, containment requests, enrichment lookups, and notifications. That separation preserves speed without turning machine output into an unreviewed authority.

Security teams often get value fastest when they treat AI as a triage assistant and SOAR as a policy-bound action engine. The practical reason is simple: incident response is full of partial evidence, conflicting signals, and context that changes mid-investigation. ENISA Threat Landscape is useful background because it shows how varied modern threat activity can be, which is exactly why automation has to be selective rather than blanket. In practice, many security teams discover over-automation only after a playbook has already taken the wrong branch on incomplete evidence.

When teams combine the two well, AI helps analysts see the shape of an incident sooner, while SOAR shortens the time between confirmation and response. The goal is not maximum automation. The goal is controlled automation with clear decision boundaries, so that responders stay accountable for actions that change business state.

Where Incident Response Automation Becomes Safe, and Where It Does Not

Safe use depends on the maturity of the action being automated. High-confidence, low-regret steps are the best candidates, especially where the response is reversible or already pre-approved. That includes alert deduplication, asset and identity enrichment, case routing, evidence collection, and opening or updating tickets. AI can improve these steps by ranking severity, grouping related alerts, and drafting a concise incident summary for the analyst.

  • Use AI for pattern recognition, not final authority.
  • Use SOAR for actions that have an approved, narrow playbook and a clear rollback path.
  • Require human approval for containment, account disablement, blocking, quarantine, or changes that can interrupt operations.
  • Record why the action was taken, not only what the action was.

That operating model works because it separates interpretation from execution. AI can infer that two alerts are probably related; it should not decide that a host must be isolated unless the organisation has already defined the exact conditions under which isolation is allowed. SOAR can then carry out the approved steps consistently, which is especially useful during high-volume events where manual routing would slow the response.

Anthropic — first AI-orchestrated cyber espionage campaign report is relevant here because it reinforces a key operational point: AI can accelerate malicious workflows as well as defensive ones, so response automation must assume that adversarial activity may be adaptive. The guidance breaks down when the playbook needs contextual judgement that the model cannot reliably supply, or when the action is high-impact and not easily reversed.

Over-Automation Risks, Edge Cases, and Control Boundaries

Tighter automation often improves speed but increases the chance of a fast, wrong action, so organisations have to balance response latency against decision quality.

One edge case is noisy detections that look similar but have different business meanings. AI may correctly cluster them while still missing the fact that one event concerns a test system and another concerns a regulated production service. Another is model drift: a summarisation or prioritisation model can become less reliable as tools, logs, or attacker behaviours change. In those cases, the issue is not just accuracy but governance, because the automation may still appear to be working while it is quietly steering responders toward the wrong branch.

There is also a difference between automation that recommends and automation that acts. Industry consensus is stronger on using AI to recommend or enrich than on letting it execute controls directly, especially where access, privilege, or customer-impacting systems are involved. Security teams should treat that boundary as a control decision, not a tooling preference. When the response step changes a system’s state, the organisation should be able to explain why the action was allowed without relying on the model’s output as the only justification.

Where this model becomes weakest is in novel incidents, sparse telemetry, or situations where the same alert can mean very different things depending on business context. Those are the moments when a human still has to arbitrate, because over-automation tends to fail most visibly when uncertainty is highest.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0RS.RP-1 — Response Plan ExecutionSOAR operationalises repeatable incident response actions.
RS.AN-1 — Incident AnalysisAI is used to enrich and prioritise incident analysis.
RS.MI-1 — MitigationContainment actions need bounded, policy-driven execution.
Recommendation — Define and rehearse playbooks so automation follows approved response procedures. Use AI to improve incident analysis without letting it replace analyst judgement. Constrain automated mitigation to approved actions with clear rollback paths.
CIS Controls v88.2 — Audit Log ManagementAutomated incident actions should be traceable and reviewable.
17.1 — Security Awareness and Skills TrainingHuman-guided automation depends on analyst oversight and escalation discipline.
Recommendation — Retain evidence of model inputs, decisions, and playbook actions for review. Train responders to challenge automated recommendations and escalate uncertain cases.
MITRE ATT&CKT1082 — System Information DiscoveryAI enrichment often correlates host and environment context during triage.
Recommendation — Map enrichment output to observed discovery activity and validate the incident context.

Practitioner Guidance

What to prioritise: Automate the workflow fragments that are repetitive, auditable, and reversible before touching containment or access-changing actions. That usually means enrichment, correlation, routing, evidence capture, and notification. The more a step can alter availability or privilege, the more tightly it should be constrained.

Decision rule: If the system can safely be wrong for a short period, AI can help rank or summarise it. If the system cannot safely be wrong, a human should approve the action even if the playbook is otherwise automated.

What practitioners underestimate: The biggest failure is not usually a dramatic model error. It is an apparently sensible automated branch that becomes institutionalised because it is fast, repeatable, and difficult to challenge after the fact.

Practitioner takeaway: The best incident response design uses AI to sharpen judgement and SOAR to enforce bounded execution, with human approval reserved for any step that changes trust, access, or service availability.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org