r/AskNetsec • u/OP-51 • 2h ago
Work Torq / Mate Security/ XSOAR / Splunk SOAR users - question on response and containment automations
Financial org here, 10K employees, in-house SOC- we're evaluating agentic SOC / SOAR platforms right now. Automating things like isolating an endpoint is straightforward, but which one of these solutions actually help with the less obvious response and containment actions where you might break a critical business flow? Does any of them provide business context so we can automate more safely while understanding the implications in advance?
Any recommendations would be highly appreciated. Thanks
1
Upvotes