HomeBlog
Life After SOAR (Hint - It's Not Next-Gen SOAR)

Antivirus became a feature of EDR. SOAR is on the same path.

Today, SOAR is a capability within agentic security: a module of bigger platforms that run triage, investigation, hunting,  detection engineering and response across all sources.

The Evolution of Automation: Each generation fixed part of the problem

SOAR is where most SOCs automate investigation and response today. To see where it goes next, it helps to look at how we got here.

Legacy SOAR gave security teams programmable response. Playbooks are deterministic and human-authored: call this API, take this field, branch on this value. That works until the environment changes. A tool swap or a schema change breaks the playbook. Playbooks cover a fraction of cases, everything else is manual, and keeping them running takes a full-time engineering team.

Legacy SOAR: human-authored playbooks

Next-gen SOAR brought AI into authoring. AI helps write and fix playbooks, which reduces maintenance. The architecture underneath stays the same: deterministic scripts that assume the world holds still.

Next-gen SOAR: AI-authored playbooks, same architecture

First-Wave AI SOC went the other way. Free-running agents that investigate on their own. This gave teams adaptability, but the agents are expensive, hard to control, and hard to trust with response actions so they handle investigation only. Detection and response stay untouched, so the work never compounds.

First-wave AI SOC: free-running agents

Each generation fixed part of the problem. None of them joined investigation, detection, and response into one system.

The cyber defense lifecycle is consolidating

The attacker is driving the change. AI-powered attackers keep each action small, below the detection threshold, so nothing fires. They chain those actions into a compromise, and they switch techniques before the last detection is tuned. A playbook handles what someone scripted. An adversary that does something no one scripted needs defense that adapts with it.

The market is converging on one agentic cyber defense platform, where SOAR, AI SOC, detection engineering, threat hunting, and UEBA work as one system. Three properties define it:

  • One context layer. Every agent and every team reasons over the same living model of the organization: its assets, identities, dependencies, crown jewels, and policies.
  • One defense loop. What's learned in investigation and hunting becomes new detections, so coverage gets cheaper and sharper over time.
  • Controlled autonomy. Automation is agentic where investigation needs judgment and deterministic where fixed steps are safer. Agents act on their own only where they've proven themselves against known-answer cases, and escalate the rest.

The context layer is what the platform knows. The loop is how it improves. The controls are what make it trustworthy.

In that platform, SOAR is one capability: response, grounded in the same context and the same loop as everything else.

When the world changes, playbooks break

Next-gen SOAR keeps the playbook architecture, and with it the same limits.

Playbooks break on change, leave coverage gaps, take heavy maintenance, and are unfit for AI attacks. Change is where those limits show first.

The root of it is what a playbook describes. A security team's intent sounds like this: confirm whether the endpoint is compromised, and contain it if it is. A playbook sounds like this: call the EDR endpoint, take the value from field 4, send it to the reputation service, wait 30 seconds, and branch left if the score is above 5.

The first describes a security outcome. The second describes one implementation of it, at one moment in time, on one stack. That difference shows up the moment the world changes.

You swap your EDR. The playbooks built around the old tool's API need rewriting.

You acquire a company with a different stack. The playbooks are rebuilt from scratch.

A new alert type appears. There's no playbook for it until someone builds one, and until then it's handled manually.

Your senior analyst leaves. The reasoning behind the playbook leaves with them. The threshold is still set to 5, and nobody remembers why it was 5 instead of 3 or 7.

Today, the best platforms are built around investigative intent, and on them the same events play out differently. The tool changes and the procedure holds. The same investigative logic runs across both stacks. The reasoning lives in the shared context, where the next analyst can find it.

Before you renew your SOAR license

I speak to teams who want to replace SOAR and aren't sure about the alternative. Before the next contract, it helps to know what moving to an agentic platform involves.

Migration seems difficult. Years of accumulated playbooks hold real institutional knowledge (and a lot of stale knowledge). Rebuilding them by hand looks like a long project.

When built correctly,  migration should be a translation of intent. The platform imports your existing playbooks, translates each one into an agentic procedure that follows the same process, and validates it before it goes live. Brittle API calls are replaced. The custom logic stays.

You choose what moves and how fast. Some procedures will run agentically from the start, others stay deterministic, and autonomy expands as the agents prove themselves on your own cases.

The result is fewer artifacts with broader coverage: hundreds of playbook branches consolidate into a handful of procedures that a security leader can read on one page and govern.

Buy the dog

Antivirus became one capability of EDR. SOAR gave us programmable response. First-wave AI SOC gave us adaptability. The 2026 buy is the agentic cyber defense platform, with SOAR as one capability, grounded in one context layer and one defense loop.

Buy the dog, and the tail comes with it.

I will be talking about this on November 17th with James Berthoty, founder of Latio. Join our webinar.

‍

Get a Demo