Skip to main content
Automation

10 Security Tasks You Should Automate First (A SOAR Field Guide)

John Sabo 6 min read

10 Security Tasks You Should Automate First (A SOAR Field Guide)

I have spent most of the last decade building Security, Orchestration, Automation and Response platforms. SOAR is the short name for that mouthful. I built them for Fortune 500 security operations centers, and I build them now for small teams that have no operations center at all.

The list of work worth automating first is nearly identical in both cases. That surprised me the first time. A 40-person security team and a 4-person IT shop both drown in the same place: repetitive decisions made by hand, on data a machine could have gathered.

Here is the order I would automate in.

1. Alert triage

Triage is the highest-value thing to automate and almost always the first thing I build. A workflow can pick up an alert, pull the asset record, check whether the account is privileged, compare it against the last 30 days of similar alerts, and attach a verdict and a severity before a human ever opens it. A human should only touch the exceptions.

2. Indicator enrichment

An indicator of compromise is a small piece of evidence, like a file hash, an IP address, or a domain name. Enrichment means looking that evidence up in the sources you already pay for. Automation can query those sources in parallel, normalize the answers, and write the result back onto the ticket. A human should only touch the exceptions.

3. Phishing response

A reported email is a data-gathering exercise, and it is nearly always done by hand. A workflow can pull the original headers, check the sender against your mail logs, count how many other people received the same message, and quarantine the copies still sitting in inboxes. A human should only touch the exceptions.

4. Access reviews

Quarterly access reviews die because someone has to build the spreadsheet. Automation can assemble the list from your identity provider, flag accounts with no recent login, flag accounts with more permission than their role needs, and route each one to the right manager. A human should only touch the exceptions.

5. Ticket enrichment

Your help desk tickets and your security tickets should not need two people to reconcile. Automation can attach the requester's device history, recent sign-ins, and open security cases to the ticket the moment it lands. A human should only touch the exceptions.

6. Threat intelligence pulls

Threat intelligence goes stale faster than anything else you own. Automation can pull your feeds on a schedule, deduplicate them, score them against your own asset list, and only surface the entries that mention infrastructure you actually use. A human should only touch the exceptions.

7. Vulnerability scan triage

A scanner will hand you thousands of findings and no opinion about which ones matter. Automation can match findings to assets, drop the ones on retired systems, sort by exploitability, and open a work item for the rest. A human should only touch the exceptions.

8. Case timelines

An incident case should read like a story, not a folder of screenshots. Automation can build the timeline as the case runs, stamping every action, email, and evidence file with a time and an author, in the order it happened. A human should only touch the exceptions.

9. Reporting

If a report takes an afternoon to write, you will write it once a quarter and no more. Automation can draft the numbers, the trend lines, and the open-item counts on a schedule so the report is waiting when you sit down. A human should only touch the exceptions.

10. Onboarding and offboarding

Offboarding is where small companies get hurt, because the leaver's access lives in eleven places nobody wrote down. Automation can run the same checklist every time: disable the identity, revoke the sessions, transfer the files, close the mail, and log each step with a timestamp. A human should only touch the exceptions.

Where to start

Do not start with ten. Start with triage and indicator enrichment, because those two produce the most hours back and they teach you what your data actually looks like. Then add the rest as you go.

There is a second reason to start with triage. Once your alerts carry context, you can finally measure whether your detection rules are any good. Most teams cannot answer that question today, and the reason is not their tools. It is that the context lives in an analyst's head and leaves when they do.

One thing I would push back on: do not automate a process you have not written down. Automation is a photocopier. If the process is sloppy on paper, you now have a fast sloppy process.

SOAR for everyone

SOAR platforms used to be a Fortune 500 purchase. They were priced and sized for teams with a dedicated engineering staff, and they took months to stand up. I built Lono Security to sell the opposite: a fully managed platform, built by me, operational in about two weeks, with enrichment included and no lock-in. You can cancel whenever you like.

Every engagement starts with a free 30-minute consult and a written quote. No retainers you do not need.

Work with me

If you want to know which of these ten would pay off first in your environment, that is exactly what the free consult is for. Thirty minutes, no obligation, and you leave with a straight answer.

Book a free 30-minute consult at /book. You can also call me at 602.501.0772. I answer the phone.

John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere

JS

John Sabo

John Sabo — 30 years in cybersecurity, GoDaddy WAF architect

Work with me

Every engagement starts with a free 30-minute consult and ends with a written quote.

Book a free consult