SOC / SOC-05
Security orchestration and response automation — SOAR
Automate repetitive alert enrichment and handling tasks, retaining human approval for sensitive actions. SOAR connects tools and procedures; it does not replace judgement in complex incidents.

WHEN IT HELPS
A focused response
to a defined need.
Analysts copying data between consoles, delayed escalation, inconsistent procedures or a need for repeatable responses to well-defined scenarios.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Use-case selection
- connectors
- service identities
- enrichment
- tickets
- approvals
- restricted actions
- errors and retries
- auditing
- tests
- manual fallback
Deliverables
- Playbooks
- authorisation matrix
- restricted service accounts
- execution logs
- tests
- shutdown and recovery procedures
- analyst handover
Acceptance evidence
Normal and error scenarios are tested; sensitive actions follow required approvals; least privilege is applied; execution is traceable; manual fallback works.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
Which tasks are repetitive and stable? Which actions could disrupt business? Who approves them and how can faulty automation be stopped?
IMPORTANT BOUNDARIES
Incorrectly authorised automation can amplify an incident. Connector accounts, API quotas, errors and irreversible actions must be addressed before broad rollout.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A SOC handles many phishing reports. Project: automate enrichment and case creation, then require approval for message removal. Target outcome: repeatable steps without unauthorised bulk deletion.
Scenario 02
A team occasionally isolates the wrong device. Project: verify identifiers, add approval and test reinstatement. Target outcome: better-controlled response; critical assets retain a dedicated procedure.
Technology and reference context
SOAR capabilities connected to existing tools, with verified connector permissions, licensing and approval of sensitive actions.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
