Frequently Asked Questions

SOAR Automated Response

Popular

What can you do with SOAR?

  • Security operations personnel can define tasks previously done manually into playbooks, allowing for both automated and manual processing. Detection, analysis, and response can be carried out swiftly, and administrators can manage these processes quantitatively.

💡 In actual implementation, there is a case where the daily event processing volume increased from 1,900 to 8,400, approximately 4.5 times.

What is a Playbook?

  • It is a document that organizes workflows and response methods in a flow format.
    In cybersecurity, it can be understood as the security monitoring operational process. It can be created without coding using a GUI-based drag-and-drop interface,
    and it provides 28 standard playbooks by default.

Is it possible to integrate with existing security devices?

  • We provide over 80 of the largest domestic components.

💡 We support integration with products from various manufacturers such as AhnLab, Secu-IT, Fortinet, Penta Security, Wins, Genieus, Xgate, Trend Micro, etc.
We have cases where response time was reduced from 30 minutes to within 1 minute through integration with P company's firewall blocking.

Popular

Is it possible to have automated response from the beginning when implementing SOAR?

  • A phased approach is recommended. Start by automating repetitive and standardized tasks (such as IP blocking and alert sending) and gradually expand from there.
    We provide 28 validated standard playbooks to facilitate a quick start.

💡 We support a quick start by providing 28 validated standard playbooks based on over 5,000 references.

Isn't it difficult to create a playbook?

  • You can create playbooks without coding using a GUI-based drag-and-drop method.
    It allows you to combine over 80 components tailored for security tasks, and during the initial setup, a SecureLayer expert engineer will assist in designing a playbook that fits your organization's needs. Additionally, 28 standard playbooks based on MITRE ATT&CK are provided by default.

Is it possible to implement SOAR alone?

  • A SIEM for log processing must be implemented as a prerequisite. (SOAR cannot be used alone)
    If you purchase only SOAR, you will need to implement a SIEM for log processing as well.

    Integration with third-party SIEMs is possible, but it is optimized for integration with our product,  eyeCloudXOAR SIEM.
    When built together with SIEM, a complete automation cycle from detection to automatic response is achieved.

Popular

Can you still see the benefits of SOAR even with a shortage of security personnel?

  • The main purpose of implementing SOAR is to alleviate the burden on personnel.
    There is a case where the actual daily event processing volume increased from 1,900 to 8,400, which is about a 4.5 times increase, and it automates repetitive manual tasks, creating an environment where analysts can focus solely on high-risk threat analysis.

Do you have CC certification and GS certification?

  • CC Certification: EAL2 level - certified on July 14, 2026 (eyeCloudXOAR V4.0 R3)

  • GS Certification: Grade 1 (TTA, certified on June 20, 2022)

Is redundancy configuration possible?

  • Redundancy configuration is possible according to the user environment.
  • Redundancy configuration for each server tier
  • Support for various methods such as full redundancy (DR network) configuration

Couldn't find the answer you were looking for? Our experts will guide you directly.

Request an Agent