top of page

Security Automation (SOAR) Software Options 2026

  • Writer: Phil Turton
    Phil Turton
  • 20 hours ago
  • 10 min read
Security Automation (SOAR) Software Options 2026/27

Security teams are drowning in alerts, chronically understaffed, and expected to contain incidents faster than ever, even as attack surfaces multiply across cloud, identity, and endpoint environments. Security automation platforms, commonly known as SOAR (Security Orchestration, Automation and Response), have moved from a nice-to-have for the largest SOCs to a practical requirement for any team trying to close the gap between detection and response, and 2026 has brought a fresh wave of AI and agentic capability that makes the market worth a fresh look.


This guide walks through the established enterprise SOAR platforms alongside the newer no-code and API-first automation tools built for teams that want to build and own their own playbooks. Viewpoint Analysis is a Technology Matchmaker, helping enterprise and mid-market security and IT teams find and select the right technology fast - aiming to be the place buyers go to understand the software and technology market before speaking to vendors. Read on to learn about the SOAR options.


Included Security Automation (SOAR) Software Vendors


This guide covers the following SOAR platforms, evaluated independently across established enterprise and no-code / API-first tiers. Our viewpoint on each vendor follows below.


Palo Alto Networks Cortex XSOAR | Splunk SOAR | IBM QRadar SOAR | Fortinet FortiSOAR | Swimlane Turbine | Tines | Torq | D3 Smart SOAR | ThreatConnect | Blink

Find Your Personalized Shortlist and Longlist of Options:

Use the free personalized Longlist Builder to find the solution that fits your specific company, size, and needs. Simply answer a few questions and we'll come back with a detailed report to explain the key companies you might want to look at.


Free Longlist Builder

 

What is Security Automation (SOAR) Software?


SOAR software connects the different tools in a security stack, such as SIEM, endpoint detection, threat intelligence feeds, and ticketing systems, so that repetitive analyst work can run automatically instead of being handled manually, alert by alert. A platform typically ingests an alert, enriches it with context pulled from other tools, applies a playbook to decide what should happen next, and either takes action directly or hands the case to an analyst with the investigation already done. The aim is not to remove people from security operations but to give them back the time that currently goes on triage, data gathering, and repetitive containment steps, so they can focus on the incidents that genuinely need human judgement.


Businesses invest in SOAR to reduce the time between detection and response, to make incident handling consistent regardless of which analyst is on shift, and to cope with alert volumes that have grown faster than security team headcount. For a broader view of how automation fits alongside the rest of the security and IT stack, see our IT Operations Technology page.


How to Find Security Automation (SOAR) Software


The fastest way to see what is realistically available is the Longlist Builder, a free, personalised tool powered by HUEY, the Viewpoint Analysis AI Technology Analysis Agent. It generates a tailored longlist matched to your company size, location, and requirements in minutes, which is a useful starting point before diving into the vendor detail below.


If you would rather have vendors come to you, the Technology Matchmaker Service works a bit like Dragons' Den or Shark Tank. Viewpoint Analysis interviews your team, writes a Challenge Brief setting out what you actually need, and invites relevant vendors to pitch directly to you.


Established Enterprise SOAR Platforms


Palo Alto Networks Cortex XSOAR - Cortex XSOAR is one of the longest-established SOAR platforms on the market, built on the case management and playbook engine that Palo Alto Networks acquired with Demisto. It combines a large marketplace of pre-built integrations with the option to write custom automation in Python, giving security teams both out-of-the-box coverage and the flexibility to build exactly what they need. The platform is designed for large security operations centres, particularly those already running other Palo Alto Networks tools such as Cortex XDR or Prisma Cloud. Palo Alto Networks has been extending the platform with agentic capability under the Cortex AgentiX name, aimed at moving beyond fixed playbooks toward automation that can adapt its own investigation steps.

Our Viewpoint: A strong fit for large SOCs that want the deepest integration marketplace available and the option to hand complex, custom automation to their own engineers.


Splunk SOAR - Splunk SOAR, formerly known as Phantom, brings playbook-based automation and case management to organisations already using Splunk for security data and analytics. It offers a visual playbook editor alongside the option to script custom logic in Python, with several hundred pre-built app integrations covering the tools most security teams already run. Because it shares a vendor and a data model with Splunk's SIEM products, teams running Splunk Enterprise Security get a more connected experience between detection and response than they would piecing together separate tools. Cisco's ownership of Splunk has also brought closer ties into Cisco's own security portfolio.

Our Viewpoint: A natural choice for any organisation already standardised on Splunk, where the shared data model between SIEM and SOAR removes a layer of integration work.


IBM QRadar SOAR - IBM QRadar SOAR, built on the technology IBM acquired with Resilient Systems, focuses on dynamic playbooks, case management, and the audit trail that regulated organisations need to demonstrate how an incident was handled. It integrates with a wide range of security tools through IBM's App Exchange and has been adding generative AI support through watsonx.ai to help analysts summarise cases and draft response actions. The platform is aimed squarely at organisations in regulated sectors, including financial services and government, where compliance reporting is as important as the response itself. This SOAR product is a separate line from IBM's QRadar SIEM business, so buyers should treat the two as distinct evaluations.

Our Viewpoint: Worth a close look for regulated organisations that need strong case documentation and audit trails built into the response process itself.


Fortinet FortiSOAR - FortiSOAR is Fortinet's automation and orchestration platform, built with a drag-and-drop playbook designer and a large library of connectors covering both Fortinet's own Security Fabric products and a wide range of third-party tools. It supports multi-tenant deployments, which makes it a common choice for managed security service providers running response operations across many client environments. Fortinet has added FortiAI agents to the platform to help automate investigation steps and suggest response actions. It suits organisations that already run a meaningful part of their security stack on Fortinet hardware and software.

Our Viewpoint: A good option for organisations already invested in the Fortinet Security Fabric, and for MSSPs that need clean multi-tenant separation between client environments.


Swimlane Turbine - Swimlane Turbine is a low-code automation platform built around a visual canvas for designing workflows, paired with Hero, its AI agent layer for suggesting and assisting with automation steps. It places a strong emphasis on case management and evidence handling, which has made it a common choice for compliance-driven security operations, including federal and public sector teams. Swimlane's marketplace includes both pre-built and custom connectors, and the platform is designed to extend automation beyond traditional security use cases into adjacent operational technology and audit workflows. It is built to scale from a single security team up to large, multi-tenant MSSP deployments.

Our Viewpoint: Particularly well suited to compliance-driven and public sector security teams that need strong case evidence and audit capability alongside the automation itself.

Let vendors come to you

Rather than chasing demos, try the Technology Matchmaker Service - Viewpoint Analysis writes your Challenge Brief and invites the right SOAR vendors to pitch directly to you.


Technology Matchmaker Service

 

No-Code and API-First Security Automation


Tines - Tines is a no-code automation platform originally built for security teams, based around a visual story builder that connects to almost any tool through direct API and webhook connections rather than relying on a fixed library of pre-built connectors. This gives security teams flexibility to automate against tools that a more traditional SOAR marketplace might not yet support. It is used for phishing triage, identity workflows, and alert enrichment by security teams at organisations including Databricks, GitLab, and Coinbase. Tines has been extending beyond its security roots into wider IT and operations automation, while continuing to describe itself as born in security.

Our Viewpoint: A strong fit for engineering-minded security teams who want to build and own their own automation without waiting on a vendor's connector roadmap.


Torq - Torq is an automation platform built around both deterministic playbooks and agentic automation, aimed at security operations centres that want to scale their automation coverage without growing headcount at the same rate. It combines a large connector library with the ability to run more autonomous, AI-driven investigation steps for lower-severity alerts, freeing analysts to focus on higher-priority incidents. The platform is designed for enterprise SOCs that already have some automation in place and are looking to extend it further, rather than teams starting from nothing. Torq positions itself around reducing the manual triage burden that has traditionally consumed the bulk of a Tier 1 analyst's time.

Our Viewpoint: A good option for enterprise SOCs looking to push further into autonomous, agentic response without giving up the option of tightly controlled deterministic playbooks.


D3 Smart SOAR - D3 Smart SOAR focuses on codeless playbook building and a library of connectors that D3 maintains and updates on the vendor's own side, reducing the ongoing engineering effort typically needed to keep integrations working as other tools change their APIs. The platform covers alert triage, case management, and threat intelligence enrichment, with an emphasis on getting new automations live quickly rather than requiring extensive scripting. It suits security teams that want the benefits of automation without dedicating a specialist engineer to building and maintaining it. D3 also supports MSSP-style multi-tenant deployments for providers managing several client environments.

Our Viewpoint: Worth considering for security teams that want automation up and running quickly without taking on the ongoing burden of maintaining custom integrations themselves.


ThreatConnect - ThreatConnect combines SOAR automation with its own threat intelligence platform, so playbooks can draw directly on curated intelligence feeds alongside the usual case management and orchestration functions. This makes it a natural fit for teams whose response processes lean heavily on threat intelligence, such as identifying indicators of compromise and mapping them against known campaigns. The platform supports both visual playbook building and deeper customisation for teams with the engineering resource to extend it. ThreatConnect is commonly used by threat intelligence and security operations teams working closely together rather than as separate functions.

Our Viewpoint: A sensible choice for organisations that want their intelligence and response workflows genuinely connected rather than living in separate tools.


Blink - Blink, from Blink Ops, is a newer entrant built around AI-assisted, no-code workflow automation for security teams, with an emphasis on getting from idea to working automation quickly using natural language prompts to help build playbooks. It targets teams that find traditional SOAR platforms too heavyweight to configure and maintain, offering a lighter starting point for automating common tasks such as alert enrichment and access reviews. Blink integrates with a broad set of security and IT tools and is positioned as a more modern alternative to platforms built before the current wave of AI-assisted automation. It suits leaner security teams who want quick wins without a lengthy implementation project.

Our Viewpoint: A good starting point for smaller or leaner security teams who want fast, AI-assisted automation wins without a long implementation project.


How to Select Security Automation (SOAR) Software


Start with integration depth against the tools you actually run today, not a vendor's total connector count. A platform with a thousand integrations is no use if the three tools at the centre of your incident response process are not among them, so check specifically for your

SIEM, EDR, identity provider, and ticketing system before looking at anything else.

Think carefully about who will build and maintain your playbooks day to day. No-code and low-code platforms put that work in reach of security analysts rather than dedicated engineers, which matters if you do not have spare automation engineering capacity, while more code-heavy platforms give greater flexibility to teams that do.


Case management and audit trail requirements vary a lot by sector. Regulated organisations should weigh how well a platform documents what happened during an incident and why, since this often matters as much to auditors and regulators as the speed of the response itself.


Finally, be clear-eyed about how much autonomous, agentic action you actually want today. Every vendor in this guide is investing in AI-driven automation that can take action with less human involvement, but the right level of autonomy depends on your risk appetite and the maturity of your existing processes, not on how advanced a vendor's AI roadmap sounds in a demo.


For a structured approach to running the evaluation itself, our Rapid RFI, Rapid RFP, and 30-Day Technology Selection services are all available through Technology Selection Services. For the full methodology behind a structured technology selection, see our Enterprise Software Selection Playbook 2026.


Summary


SOAR has split into two genuinely different buying paths in 2026. Established platforms like Cortex XSOAR, Splunk SOAR, IBM QRadar SOAR, FortiSOAR, and Swimlane Turbine offer the deepest integration marketplaces, the strongest case management, and the closest ties to an existing security stack, and they suit large SOCs and regulated organisations that need that depth. No-code and API-first platforms like Tines, Torq, D3 Smart SOAR, ThreatConnect, and Blink offer faster time to a working automation and put playbook building within reach of security analysts rather than specialist engineers, and they suit teams that want to move quickly without a lengthy implementation project.


Whichever path fits your team, the questions to ask are the same: does it cover the tools you actually run, who will maintain it once the initial project is over, and how much autonomous action are you genuinely comfortable handing over today. Getting those three answers right matters more than any single feature comparison.


SOAR Buyer Help - Next Action

Viewpoint Analysis works with enterprise and mid-market organisations to find and select the right security automation software, independently, without vendor fees or influence.

  • If you are just starting out and want to know what is in the market, the Longlist Builder is free and gives you a personalised list of SOAR vendors in minutes.

  • If you want vendors to come to you rather than the other way around, the Technology Matchmaker Service brings a shortlist of relevant vendors to pitch directly to your team.

  • If you are ready to run a structured selection and want to move quickly, our Technology Selection Services cover Rapid RFI, Rapid RFP, and 30-Day Technology Selection support.


Talk to Viewpoint Analysis


If you are evaluating SOAR software and want independent input, or you are a vendor who would like to be considered for future content and matchmaking opportunities, request a call with Viewpoint Analysis.

© 2026 Viewpoint Analysis Ltd

White on Transparent.png

Viewpoint Analysis Ltd.

3rd Floor, St Paul's House, 23 Park Square South, Leeds, LS1 2ND

+44 0113 5129252

Viewpoint Analysis Ltd is a company registered in England & Wales (company number 13211084) 

St Paul's House, 3rd Floor, 23 Park Square South, Leeds, LS1 2ND.

VAT Registration Number 374 2056 05

bottom of page