A recent trend in the security space is that more and more companies are shifting from SIEM (security information and event management) to SOAR (security, orchestration, automation, and response). Deidre Smith and Neelima Rustagi share some of their insights from the vendor and customer perspectives.
Neelima Rustagi is the Senior Director of Product at Palo Alto Networks. Her day-to-day involves talking to a lot of customers and defining how the product features on the XSOAR side are going to serve the customers. Deidre Smith is VP, Service Delivery Transformation at NTT, where her principal tasks are making each of the services NTT offers more efficient and leading-edge and responding to client requirements.
The market is changing rapidly, and one of the challenges for many organizations is pulling together all the different aspects of their cybersecurity solutions. How do SIEM and SOAR compare with each other and how do they work together? Neelima and Deidre discuss the increasing complexities of security operations, the potential for automation within these systems, and the importance of playbooks. Tune in to find out more.
Key Takeaways:
[:22] Ian Murphy introduces his guests for this episode — Neelima Rustagi and Deidre Smith.
[1:46] Many companies are shifting from SIEM to SOAR. What is driving this change?
[5:54] Deidre and Neelima share insights on why customers want automation and response done for them.
[10:20] What is the relationship between SIEM and SOAR systems in organizations, and how much of a mix of the two systems is there in organizations?
[15:20] How complex does the process become when multiple data sources are providing information?
[18:16] How broad is the potential scope for automation?
[20:45] How much automation lies within the SOAR tool and how much of that is about additional automation that is brought in?
[22:25] How can organizations bring new people in?
[25:29] How much does the fact that playbooks are an integral part of SOAR work for analysts going out to help customers but also customers themselves?
[27:03] From a vendor perspective, how much commonality can be created with playbooks?
[28:46] How are playbooks built?
[30:31] How much have playbooks increased the ability to respond to clients’ demands, and how has SOAR changed the response environment?
[32:13] Deidre and Neelima share more about forensics, and how playbooks provide the ability to build in the forensics of the response.
[35:43] What are the three reasons why people should be moving towards SOAR, and customers should be adopting SOAR?
Mentioned in This Episode:
Securing Today Podcast
Palo Alto Networks — Website, LinkedIn, Twitter, Facebook, YouTube
Ian Murphy
Neelima Rustagi
Deidre Smith
NTT Limited