Back to glossaryCyber

SIEM and SOAR

Log correlation and incident-response automation platforms that reduce threat detection and handling times.

Definition

A SIEM (Security Information and Event Management) platform collects, normalizes and correlates event logs from all of an organization's systems in real time, servers, workstations, network devices and applications, in order to detect abnormal behavior or attack patterns. It generates alerts based on correlation rules and behavioral models, allowing SOC analysts to qualify potential incidents. SOAR (Security Orchestration Automation and Response) complements the SIEM by automating part of the alert-response process: automatic context gathering, isolation of a suspect endpoint, blocking a compromised account, or notifying the relevant teams, through predefined playbooks. The main objective of these tools is to reduce MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond), two metrics directly linked to the extent of a cyber loss. A poorly configured SIEM, however, generates an excessive volume of false positives that overwhelm security teams and can mask genuine alerts. For cyber underwriting, the presence and maturity of SIEM/SOAR are advanced hygiene indicators that insurers assess in underwriting questionnaires.

Example

An industrial group deploys a SIEM correlating logs from its 12,000 endpoints and servers. During an attack, the system detects an abnormal lateral movement within 4 hours and automatically triggers via SOAR the isolation of the compromised network segment, limiting the impact to 30 machines instead of the 800 the attacker was targeting.

Related terms
Also known as

SIEM, SOAR, Security Information and Event Management, Security Orchestration Automation and Response