“When a security incident is identified, organizations need to contain the damage, preserve evidence, and restore business functions. As many previous incidents show, there is mayhem in the initial hours of responding to an ongoing attack, from identifying the significance of a threat to considering the tradeoffs between containment and business disruption. The idea behind SOAR is to make security incident response more efficient through automation. –Tsvi Korren, field CTO at Aqua Security