Notifications
Clear all
SIEM and SOAR
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
18/07/2026 9:12 pm
We're a mid-sized ecommerce company with a basic security stack. Our SOAR implementation has been running for 18 months, and the renewal quote just came in.
The problem is our team only uses it for a few automated ticket creations from our SIEM. We don't have dedicated security analysts, so the more complex playbooks never got built. The vendor says we're not utilizing its potential, but that feels like a sunk cost argument.
Before I push to shut it down, I want to make sure I'm not missing a critical use case. For those who scaled into their SOAR later, what was the trigger? Is there a simpler, foundational way to get value that we might have overlooked?