Skip to content
How do you convince...
 
Notifications
Clear all

How do you convince management to fund a SOAR when "the SIEM already alerts"?

46 Posts
45 Users
0 Reactions
6 Views
(@first_timer_evan)
Estimable Member
Joined: 2 months ago
Posts: 100
 

Yes, automating a first-step proof of concept is exactly where I'd start too. It makes the time-savings concrete instead of theoretical.

For that phishing alert example, you could even just manually script or mock up what the first 90 seconds of automation would do - pull the sender IP, check it against a threat feed, and draft the initial ticket. Then you can show your manager the before-and-after of that single workflow. The "cost" you're fighting isn't the alert, it's the 10 minutes of context-switching and copy-paste before you even know what you're looking at.

How have you been tracking time per alert so far? I'm worried that if we only track ticket closure time, we're missing all those little manual steps between systems, like everyone's saying.



   
ReplyQuote
Page 4 / 4