IBM Resilient and Palo Alto Networks Cortex XSOAR are leading contenders in the security orchestration, automation, and response (SOAR) category. Cortex XSOAR seems to have the upper hand with its playbook library and user-friendly interface.
Features: IBM Resilient is notable for its integration with IBM QRadar, comprehensive incident response capabilities, and flexibility in playbook creation and automation. It has a robust security architecture and offers stability and scalability. Cortex XSOAR stands out for its extensive playbook library, advanced automation features, and excellent integration with third-party vendors. It is user-friendly and supports advanced threat intelligence functions.
Room for Improvement: IBM Resilient faces challenges with third-party integrations and has compatibility hurdles. It is considered expensive and lacks proactive technical support. More built-in integrations and easier customization are needed. Cortex XSOAR is noted for high licensing costs and a complex setup process. There is room for better integration with non-security solutions and more affordable pricing. Missing built-in functionalities such as SIEM is a gap.
Ease of Deployment and Customer Service: IBM Resilient primarily offers on-premises deployment with variable technical support. Some users experience delays, while others appreciate effective issue escalation. Palo Alto Networks Cortex XSOAR provides cloud and on-premises deployment options. Its support is generally average, sometimes slow in resolving issues. Both could enhance technical support and deployment ease, but IBM Resilient shows a slightly better escalation mechanism.
Pricing and ROI: IBM Resilient is seen as expensive, with high annual licensing fees and added costs for support services. Its user-based pricing may not be ideal for larger environments. Cortex XSOAR is also considered pricey, particularly after Palo Alto's acquisition, which increased costs significantly. Despite this, some users see value in its features. Both products are expensive but offer significant ROI in time savings for those leveraging their capabilities fully.
| Product | Mindshare (%) |
|---|---|
| Palo Alto Networks Cortex XSOAR | 8.8% |
| Torq | 3.7% |
| IBM Resilient | 2.2% |
| Other | 85.3% |

| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 3 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 21 |
| Midsize Enterprise | 9 |
| Large Enterprise | 26 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
IBM Resilient is renowned for its ease of use, flexibility, and stability, seamlessly integrating with IBM QRadar to support comprehensive incident response.
IBM Resilient excels in facilitating dynamic playbook creation and managing security threats effectively with a mature, scalable architecture. Its integration capabilities and complete stack make it pivotal for incident response automation and orchestration. However, it requires enhanced integration with third-party applications, improved technical support, and better pricing strategies. Users have noted complexities in setup, necessitating more detailed documentation and customization efforts.
What are IBM Resilient's most important features?IBM Resilient is deployed across sectors like finance and governance, aiding in incident response automation. It supports security services management, integrates with IBM QRadar, and leverages the MITRE ATT&CK tactics. Benefiting from its flexibility, it's ideal for case management, research, and integrating with other security controls, allowing organizations to handle incidents effectively.
Palo Alto Networks Cortex XSOAR enhances security operations automation and integration. Users rely on its incident management capabilities and machine learning to improve response times and efficiency.
Cortex XSOAR stands out for its capability to automate and orchestrate security tasks through customizable playbooks and robust third-party integrations. Its analytics offer insights into incidents, while machine learning prioritizes alerts and reduces false positives. Despite its powerful features, users note room for improvement in documentation, interface design, and integration capabilities. Cost and complexity in setup and deployment are also concerns. Users in security operations centers benefit significantly from automated data enrichment, streamlined incident response, and efficient handling of threats like phishing and endpoint management.
What are the key features of Cortex XSOAR?Cortex XSOAR is implemented across industries for automating and streamlining security operations. Organizations use it to create playbooks, integrate with security tools, and automate repetitive tasks, thereby improving the efficiency of their security operations centers and incident management processes.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.