The gap between SIEM detection and SOAR response
How context, playbook design and human judgement shape the space between an alert and an action.
SIEM can detect and aggregate events, while SOAR can orchestrate actions—but the path between an alert and a safe response still depends heavily on context and judgement.
Different systems, connected responsibilities
SIEM platforms centralise logs, correlate activity and generate alerts. SOAR platforms coordinate tools and automate response workflows through playbooks. Their capabilities are complementary, but integration does not automatically solve every operational problem.
What exists in the middle
Before a response is executed, someone or something must validate the alert, gather context, estimate impact, select an appropriate playbook and decide whether the action is safe. This middle layer is where analyst effort and uncertainty often remain.
Why predefined playbooks are limited
Playbooks provide repeatability, but they require expertise to design and maintain. A workflow that works in one environment may be inappropriate in another, and rigid automation may not adapt well to incomplete evidence or novel attacks.
The opportunity for AI assistance
An AI-assisted layer could help correlate evidence, summarise incidents, recommend response steps and adapt guidance to context. However, it must be bounded by permissions, explanations and human approval for sensitive actions.
From integration to intelligent coordination
The research opportunity is not merely to place SIEM and SOAR in the same architecture. It is to improve the reasoning, context and communication that connect detection to response.