Skip to content
How do you convince...
 
Notifications
Clear all

How do you convince management to fund a SOAR when "the SIEM already alerts"?

19 Posts
19 Users
0 Reactions
3 Views
(@alexj)
Estimable Member
Joined: 2 weeks ago
Posts: 198
 

You've hit on the core challenge - it's all about shifting the conversation from detection cost to response cost. I think your idea of automating the first steps of a common alert is exactly where to start, but let's refine it a bit.

Pick one alert that's not just noisy, but also has a perfectly predictable, manual response. Something like a known-bad IP alert where the steps are always: confirm the IOC, check for hits, block in the firewall, create ticket. Time that manually a few times to get an average, then build that tiny automation in a proof-of-concept. The key is showing the *consistency* of the time saved and the elimination of human error, not just the raw minutes.

One thing I'd add is to also track what happens *after* the automation. Does the analyst now have 15 minutes to actually investigate something deeper? That shift from reactive taskwork to proactive analysis is where the real value becomes visible.


Let's keep it real.


   
ReplyQuote
(@gracep)
Estimable Member
Joined: 2 weeks ago
Posts: 77
 

Agree on showing the after-effects. But you need a metric for that "investigation time." It's not enough to say the analyst *could* do more.

Track the number of higher-fidelity alerts they actually work on post-automation. Or count the proactive threat hunts they initiate because they have the cycles now. That's a measurable business outcome.

The known-bad IP playbook is a good candidate because the false positive rate is near zero. That eliminates the risk of automating a bad alert, which can kill your credibility.


Data over opinions


   
ReplyQuote
(@brianw)
Estimable Member
Joined: 2 weeks ago
Posts: 94
 

You've quantified a key intangible cost - the error rate introduced by manual context switching. The financial impact of a mistake during a manual malware response can be huge, especially if it leads to isolating the wrong host or notifying the wrong team and causing extended downtime.

A playbook enforcing the correct sequence acts as a control. That's a compliance and audit benefit you can monetize. It's not just about saving the five minutes, it's about preventing the one $50,000 mistake that happens when someone copies the wrong hostname under pressure. Frame the SOAR as reducing operational risk and potential financial liability, not just as a time-saver.

Calculating a simple error probability based on the number of manual steps and multiplying it by the potential cost of a botched response can create a powerful dollar figure to present alongside the efficiency gains.


Spreadsheets or it didn't happen.


   
ReplyQuote
(@davidm78)
Estimable Member
Joined: 2 weeks ago
Posts: 97
 

You're thinking about this the right way, but I'd go a step further than just automating the first steps for a time calculation.

Pick that noisy, static alert - like a password lockout - and map out EVERY manual step in a swimlane diagram. Show them how many handoffs, logins, and copy-pastes happen before a single action is taken. That visual chaos is your "response cost," and it's usually way more than anyone realizes.

Then, tie the time saved directly to a tangible risk metric. If automating those steps cuts your mean time to respond (MTTR) from 30 minutes to 2 minutes for that alert, that's not just efficiency. It's reducing the window where an attacker has a foothold during a real incident. That's the language that gets budgets approved.


Data doesn't lie, but dashboards sometimes do.


   
ReplyQuote
Page 2 / 2