No more typing reviews! Try our Samantha, our new voice AI agent.

Galvanize IncidentBond [EOL] vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Galvanize IncidentBond [EOL]
Average Rating
9.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
61
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
 

Featured Reviews

DE
Information Security Engineer at a financial services firm with 1,001-5,000 employees
Customization and transparency of data, while maintaining a mostly user-friendly UI
Sadly, I can’t provide specific examples due to the nature of the content of the improvements. I will say that, prior to implementation, and post-implementation, we saw a nearly 800% increase in volume of completed and correctly completed documentation in regards to specific tasks being completed. Rsam puts the workflow first, and lets the record follow it. It literally puts a task on rails and the person needing to do the work only need respond to the prompts accordingly and let Rsam automate the rest. The data is cleaner, more uniform, and there’s simply more of it created more quickly, as a result.
Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Security automation has transformed incident workflows and now reduces response time dramatically
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX. We have communicated with the vendor team about this, but they are prioritizing product functionality over usability because most target customers are technical and understand a primitive UI. They face difficulties in implementing UI changes as their team is stretched. Thus, the UI/UX of the tool needs significant improvement. There are plans on their roadmap, but a lot remains to be done. Parts of the tool run on an older framework, causing slowness. Usability is a broader issue than features alone. This usability problem is common in many cybersecurity tools, unlike customer-facing applications. Some integrations have speed issues and might not function seamlessly with different upstream configurations, requiring manual updates. These are the main pain points we encountered, particularly with UI/UX, integration speed, and the usability of certain inbuilt playbooks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Rsam puts the workflow first, and lets the record follow it, literally putting a task on rails so the person needing to do the work only needs to respond to the prompts accordingly and let Rsam automate the rest."
"The customization and the transparency of data while still maintaining a mostly user-friendly UI, are key features. It allows for me, as an engineer, to evolve the individual components and modules, and to create a much more meaningful picture than the individual pieces in isolation ever could."
"For organizations that are stable with their security operations, like those with around 50 members in their security team running full-phased operations 24/7, Cortex is necessary."
"The biggest advantage in Cortex XSOAR that I see is its extensive AI capabilities, where it unifies all your log collection mechanisms and can ingest the logs from almost all of the end devices."
"The set of playbooks that XSOAR already has inside it is really huge, and it is also great for a lot of informational security managers and engineers that can just choose what they need and not have to create anything from scratch."
"I chose Cortex XSOAR because the client also has Palo Alto firewalls. I can incorporate the data from the Palo Alto firewalls into Cortex and send it into the same data lake to manipulate that data. It lets me manage and monitor the data in one place."
"Palo Alto Networks Cortex XSOAR is the number one security platform, so their response also rates highly."
"It was useful as a ticketing tool."
"Palo Alto is easy to use."
"Each incident collected is orchestrated with automation that selects the security analyst to be involved, or provides complex execution plans for managing security incidents."
 

Cons

"Hands down, if Rsam adopted a more industry proper "End of life – Deprecated – Stable – Release – Experimental" system with their releases, and all the proper checks and balances, I’d be an incredibly happy individual."
"Stable – Release – Experimental" system with their releases, and all the proper checks and balances, I’d be an incredibly happy individual. I can appreciate the cause and affect, wherein the customization of the tool drives rapid release schedules, and the paradox that creates with the idea of stable releases. I’d also like more transparency about known bugs and issues."
"One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation."
"With Palo Alto Networks Cortex XSOAR, managing its setup phase can be a complicated task."
"It is both difficult to implement, deploy, and integrate the product."
"Customization and performance can be improved. For example, some formats were incompatible when integrating, and they said we needed to work with the vendor to fix this issue because some logs that AVA logs were not compatible, and it did not readily recognize the format."
"XSOAR could have more integration options."
"Its dashboard features need improvement."
"The biggest area for improvement is simplifying playbook development and debugging."
"It's only one cloud right now. It might be helpful for some companies to have an on-premies option."
 

Pricing and Cost Advice

Information not available
"The price of Palo Alto Networks Cortex XSOAR could be reduced. We are always looking for a discount. There is an annual license needed to use this solution."
"On a scale of one to ten, where one is a low price, and ten is a high price, I rate the pricing a nine."
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"It is expensive."
"It's cheaper compared to its competitors."
"There is a perception that it is priced very high compared to other solutions."
"The solution is a bit on the expensive side."
"My company did not make any payments towards the licensing costs attached to the product since we were only using its pilot version."
report
Use our free recommendation engine to learn which Security Incident Response solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise9
Large Enterprise32
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
My experience with pricing, setup cost, and licensing for Palo Alto Networks Cortex XSOAR is that I was just a consumer as an analyst. I was not part of deploying cost, license, procurement, or pro...
What needs improvement with Palo Alto Networks Cortex XSOAR?
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR as a product or at least as a summarizing feature. If that is there, I think it w...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My main use case for Palo Alto Networks Cortex XSOAR is that we use it as a SOAR platform, Security Orchestration and Response tool for our security incidents. I can give you a quick specific examp...
 

Also Known As

IncidentBond, Rsam SIRP, Rsam Incident Management, Rsam Security Incident Response Platform
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about ServiceNow, Trellix, Broadcom and others in Security Incident Response. Updated: August 2026.
908,834 professionals have used our research since 2012.