No more typing reviews! Try our Samantha, our new voice AI agent.

Galvanize IncidentBond [EOL] vs Palo Alto Networks Cortex XSOAR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Galvanize IncidentBond [EOL]
Average Rating
9.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
62
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
 

Featured Reviews

DE
Information Security Engineer at a financial services firm with 1,001-5,000 employees
Customization and transparency of data, while maintaining a mostly user-friendly UI
Sadly, I can’t provide specific examples due to the nature of the content of the improvements. I will say that, prior to implementation, and post-implementation, we saw a nearly 800% increase in volume of completed and correctly completed documentation in regards to specific tasks being completed. Rsam puts the workflow first, and lets the record follow it. It literally puts a task on rails and the person needing to do the work only need respond to the prompts accordingly and let Rsam automate the rest. The data is cleaner, more uniform, and there’s simply more of it created more quickly, as a result.
EricRise - PeerSpot reviewer
Noc Network Engineer at a outsourcing company with 51-200 employees
Automation playbooks have reduced soc noise and now streamline daily incident response
To improve Palo Alto Networks Cortex XSOAR, there can be a learning curve to it. It is not a very user-friendly product; it is complex. It handles debugs and automation playbooks. You have to really spend some time dedicated to learning the product, scripting, and acquiring your certifications on it. Cost is another item as well. That can be quite significant; it does depend on other tools for EDR, whether you are using Palo Alto's XDR system or any number of third-party products for that. There are some reporting and logging restrictions and limitations. Some of those are going to be constraints, including window size limits. Database use with it has limited scalability for that type of application.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The customization and the transparency of data while still maintaining a mostly user-friendly UI, are key features. It allows for me, as an engineer, to evolve the individual components and modules, and to create a much more meaningful picture than the individual pieces in isolation ever could."
"Rsam puts the workflow first, and lets the record follow it, literally putting a task on rails so the person needing to do the work only needs to respond to the prompts accordingly and let Rsam automate the rest."
"The set of playbooks that XSOAR already has inside it is really huge, and it is also great for a lot of informational security managers and engineers that can just choose what they need and not have to create anything from scratch."
"The most valuable feature is automation."
"Palo Alto Networks Cortex XSOAR has impacted my organization positively because it has these automations and customized workflows."
"The most valuable features of Cortex XSOAR include its vast library of plugins, which allow us to integrate various tools and solutions seamlessly."
"Palo Alto Networks Cortex XSOAR has positively impacted our organization by making us faster in the incident response process and allowing us to focus on more innovative things instead of just doing the same things repeatedly because of its amazing automation."
"The most valuable feature is automation, as there is a huge variety of automation that can help any team and there is a threat model."
"For organizations that are stable with their security operations, like those with around 50 members in their security team running full-phased operations 24/7, Cortex is necessary."
"They have a portal where you can find any kind of integration that you need."
 

Cons

"Hands down, if Rsam adopted a more industry proper "End of life – Deprecated – Stable – Release – Experimental" system with their releases, and all the proper checks and balances, I’d be an incredibly happy individual."
"Stable – Release – Experimental" system with their releases, and all the proper checks and balances, I’d be an incredibly happy individual. I can appreciate the cause and affect, wherein the customization of the tool drives rapid release schedules, and the paradox that creates with the idea of stable releases. I’d also like more transparency about known bugs and issues."
"To improve Palo Alto Networks Cortex XSOAR, there can be a learning curve to it. It is not a very user-friendly product; it is complex."
"For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective."
"They should provide integration with machine learning platforms."
"The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher."
"It doesn't offer automatic internet reports out of the box."
"It is not a very scalable solution."
"It is both difficult to implement, deploy, and integrate the product."
"The user interface (UI) is quite heavy and takes time to load, which is a major drawback."
 

Pricing and Cost Advice

Information not available
"There is a yearly license required for this solution and it is expensive."
"The solution's cost is reasonable."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"The pricing is fair. The pricing reflects the value and feature set it offers."
"My company did not make any payments towards the licensing costs attached to the product since we were only using its pilot version."
"The solution is expensive."
"The solution is based on an annual licensing model that is expensive."
"The solution's cost is high."
report
Use our free recommendation engine to learn which Security Incident Response solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
13%
Manufacturing Company
8%
Outsourcing Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise9
Large Enterprise32
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
We can quantify the reduction. It is more than sixty to seventy percent reduction in the MTTR, as per documents from Palo Alto, and with proper implementation, we can improve MTTR by up to sixty-fi...
What needs improvement with Palo Alto Networks Cortex XSOAR?
The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher. Other than enterprise clients, they might need to push their management to get additional approva...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
We are a partner for Palo Alto as a service provider. Palo Alto Networks Cortex XSOAR is used as a SIEM solution or XDR-type solutions.
 

Also Known As

IncidentBond, Rsam SIRP, Rsam Incident Management, Rsam Security Incident Response Platform
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about ServiceNow, Trellix, Broadcom and others in Security Incident Response. Updated: September 2026.
913,924 professionals have used our research since 2012.