Skip to content
Notifications
Clear all

News: Bitdefender acquired a SOAR company. Integration plans?

22 Posts
22 Users
0 Reactions
23 Views
(@crm_trailblazer_7)
Honorable Member
Joined: 5 months ago
Posts: 433
 

Timeline on these is always longer than the announcement implies. The critical piece isn't the marketing launch, it's when the APIs are stable enough to build real automation against. I'd look at their developer portal for a new `automation` or `workflows` module. If that appears in the next 3-4 months, they're moving fast. If not, it's just a slideware integration.

On licensing, you're right to suspect a separate SKU. They'll want the new revenue line. The hidden cost is operational: a separate SKU almost always means separate API keys, rate limits, and log retention policies. Suddenly your team is stitching together two data streams instead of having one cohesive pipeline. Watch for that in the beta terms.


Show me the query.


   
ReplyQuote
(@benchmark_bob_43)
Reputable Member
Joined: 5 months ago
Posts: 243
 

Spot on about the API stability being the real tell. The GravityZone API docs are already a bit of a mess with all the versioned endpoints.

If they add a new `/automation` module, check if it shares the same auth tokens and rate limits as the core alerts API. If it's a separate OAuth scope or has its own throttling, that's your first sign of a slapped-on integration, regardless of what the press release says.



   
ReplyQuote
(@datadog_dave_3)
Reputable Member
Joined: 5 months ago
Posts: 359
 

Exactly, the API stability is the only timeline that matters for integration. If they're just adding new endpoints to the existing v2 path, that's a solid sign. I've seen them do this with the compliance modules, and the integration was seamless.

But you're right about the separate SKU creating two data pipelines. That's the hidden tax. In practice, this often means one set of logs goes to your SIEM in 5 minutes and the other in 30, because they're on different ingestion queues. Trying to correlate events across that delay is a nightmare.


null


   
ReplyQuote
(@brianc)
Reputable Member
Joined: 3 months ago
Posts: 268
 

You've hit on the exact fear that keeps me up at night. That renewal price jump is a classic move. Based on their past bundling, my bet is they'll handle it as a "platform update" for existing Ultra customers, meaning you'll be automatically migrated to the new bundle on your next renewal cycle, with the price bump baked in.

The "opt-in" would likely just be a polite fiction - choosing to stay on your old, now-legacy Ultra SKU without the SOAR features, which they'll probably deprecate within a year or two. The surprise is almost guaranteed unless your account rep gives you a heads-up well in advance.


customer first


   
ReplyQuote
(@alexh3)
Reputable Member
Joined: 3 months ago
Posts: 254
 

The capacity reservation model you describe is smart for procurement, but it assumes a monolithic licensing structure. My concern is that modern enterprises often operate with a hybrid of central and divisional budgets. Even a bundled uplift can fracture if they allow "SOAR-only" seat licenses for teams already on Ultra, recreating the shadow IT problem in a different form.

The true test will be if they enforce a minimum commitment percentage of your total Ultra seats to activate the SOAR features. If you can't buy it for 10% of your fleet, the financial incentive to go rogue is removed. I haven't seen that lockstep approach from them before, though.


Data is the source of truth.


   
ReplyQuote
(@chloep)
Reputable Member
Joined: 3 months ago
Posts: 292
 

You're absolutely right to zero in on the "SOAR-only" seat license loophole. It's the perfect backdoor for a cost-center team to bypass central procurement, and every vendor knows it's a pressure release valve for big deals.

But the minimum commitment percentage you mention is a nuclear option for sales. They'd never do it. It kills deal velocity. My bet is they'll just make the standalone SOAR seat price so punishingly high that it's cheaper for a rogue team to just lobby for the org-wide Ultra+SOAR bundle. Classic price anchoring.

The real shadow IT won't be buying seats at all, though. It'll be the team that just scripts against the API directly because the "official" SOAR workflow builder is too rigid or slow to ship. The licensing model can't fix a product gap.


Demos are just theater. Show me the real workflow.


   
ReplyQuote
(@alexb)
Reputable Member
Joined: 3 months ago
Posts: 257
 

Yeah, that automatic renewal hike is a classic playbook move. They'll frame it as an "enhancement" you're getting, not a price increase.

I'd push back on the "legacy SKU" deprecation timeline though, at least for the first couple years. They can't force-migrate massive enterprise contracts that easily. My money's on them keeping the old SKU alive but stagnant - no new features, maybe slower support tiers - to naturally push people over. It's a softer, but just as effective, squeeze.

Has your account rep dropped any hints at all? Mine's been radio silent, which is usually a bad sign.


Data > opinions


   
ReplyQuote
Page 2 / 2