A couple of years ago, industry research firm Gartner introduced a new acronym—SOAR—into the cybersecurity nomenclature. SOAR stands for “security orchestration, automation, and response.” It’s not an individual tool, or even set of tools. Like ISO 27001, GDPR, FISMA, and others, SOAR is a cybersecurity framework organizations can use to create an effective cyber risk mitigation strategy.
While SOAR in itself is not a specific technology, technology is certainly key to creating a good security orchestration blueprint. Indeed, the security orchestration component of SOAR is all about using technology to automate cybersecurity and make it easier for organizations to monitor and assess risk from a centralized location. SOAR’s primary intent is to make cybersecurity management more efficient, from the initial capturing of risk data to sharing that information with senior leadership. Technologies such security performance management (SPM) tools and security ratings assist in this effort.
How do SPM tools support security orchestration?
SPM tools are an excellent complement to the SOAR framework because they provide CISOs with more efficient ways to manage and monitor risk while providing deep and accurate cybersecurity insights.
A core element of SOAR is being able to orchestrate the many sources of data organizations rely on to provide a complete and accurate picture of their risk potential, which has become increasingly challenging given the current remote work environment. That environment has significantly broadened the attack surface for most organizations as more employees connect to company networks from endpoints at home. As Gartner puts it, “remote working is now just work” and it “requires a total reboot of policies and tools to better mitigate the risks.”
An SPM tool like Attack Surface Analytics is critical in managing risk in this climate. It allows organizations to gain visibility into all of their digital assets (including ones they may not realize are being used), exposing potential shadow IT, identifying areas of risk, and providing a clear view of a company’s entire digital ecosystem.