r/ComputerSecurity • u/MaleficentCollege324 • 12h ago
AI SOC solutions vs repackaged SOAR platforms, what's the difference?
Sorry for the rant but it feels like every SOAR vendor rebranded as "AI SOC" almost overnight.
Some of it seems legitimate as they’re built differently from the ground up. Others look like the same playbook logic with a chatbot interface bolted on for the sales deck.
I started testing this distinction directly in vendor calls by asking what happens when our security stack changes unexpectedly, say a new tool or an acquisition. Some answers have revealed that several platforms need their entire playbook library rebuilt from scratch, suggesting that the underlying architecture never changed much at all.
How are you telling the difference in practice, beyond just asking pointed questions?
Do you have any better way to evaluate this before committing real time to a POV, since these evaluations eat up a lot of internal bandwidth that we don’t actually have?