In the first quarter of 2026, the USSC SOC cyberattack response center completed a project to integrate a new SOAR solution. The Security Vision platform served as the technological foundation. The project's goals were to increase the speed of incident handling and the degree of automation of incident detection and response processes.
SOAR platform plays a key role in the SOC's work, providing end-to-end incident management: it aggregates data on information security incidents from systems such as SIEM, EDR and XDR, carries out contextual enrichment and forms a single incident timeline – from detection to closure. Centralized, automated orchestration of interactions between various elements of the information security incident management system (EDR, NGFW, AV, ticketing, Threat Intelligence, etc.) in SOAR facilitates the rapid and seamless implementation of new services. SOAR ensures efficient management of automation scenarios (playbooks) for the SOC team and makes the monitoring and response process transparent for Customers.
The ability to fine-tune information security incident management processes in the SOAR Security platform Vision enabled the USSC SOC team to transfer its accumulated experience, proprietary methods, and information security incident management processes directly into the system, ensuring high speed and accuracy in countering cyber threats. During the project, Threat services were integrated into SOAR Intelligence (TI), as well as EDR / XDR solutions and SIEM used USSC SOC. Our immediate plans include integrating the vulnerability management service (VM) and the USSC-developed AI SOC analyst assistant into the SOAR platform.
"The flexible adaptation capabilities built into Security Vision SOAR allowed us not only to automate existing USSC SOC processes but also to implement new tasks and ideas that emerged during the project. At the same time, we maintained flexibility and responsiveness to our clients' needs during monitoring, adapting our processes to their infrastructure and business objectives," comments Konstantin Mushovets, Head of the USSC SOC.
The platform is integrated into the 24/7 operational work of the USSC SOC, and customers can already appreciate the benefits of the upgrade: reduced incident processing time and improved user experience in the new personal account.
"We are especially pleased that such an experienced and demanding market player as the USSC has entrusted Security Vision with the key task of automating response processes. I am confident that through our joint efforts, we will not only be able to take the center's efficiency to a new level but also create a benchmark approach to building modern SOCs," noted Ekaterina Cherun, Commercial Director of Security Vision.
SOAR platform is a significant milestone in the development of the Security Operations Center (SOC), enabling the rapid launch of new security services and more effective counteraction to modern cyberattacks.