New SOAR Playbook to Counter Ransomware
On June 3rd 2026, NetApp and Cisco announced an expansion of their collaboration to enhance enterprise cyber resilience. This partnership introduces a new Security Orchestration, Automation, and Response (SOAR) playbook aimed at countering ransomware attacks more effectively.
Combining NetApp’s Intelligent Data Infrastructure with Splunk’s advanced analytics and observability capabilities provides deep, real-time visibility into storage and infrastructure health. This integration enables customers to transform operational data into actionable insights that enhance reliability, security, and business outcomes.
Sandeep Singh, Senior Vice President and General Manager at NetApp, emphasised the urgency of rapid response to cyber threats, mentioning the acceleration of attacks driven by AI. “To limit the cost and impact of ransomware, organisations must act the moment a threat is detected,” Singh explained.
The new playbook allows Splunk SOAR users to automate incident response actions directly on NetApp ONTAP storage. These actions include blocking suspicious users, creating data snapshots, and taking data volumes offline to prevent further infection. As a result, enterprises can better contain ransomware attacks and limit data loss at the storage layer.
Strengthening Defense-in-Depth Strategies
The collaboration aims to make storage an active component of a defence-in-depth strategy. NetApp, known for delivering secure storage solutions, is uniquely positioned to integrate storage into broader security ecosystems. The playbook also facilitates Splunk Enterprise Security’s integration with NetApp Ransomware Resilience, enhancing incident triage and prioritisation.
David Dalling, Group Vice President of Splunk Security at Cisco, remarked that the playbook empowers organisations to “contain threats directly targeting enterprise data.” This strengthens collaboration between security and storage teams, making defence strategies simpler and more effective.
The NetApp Splunk SOAR playbook is available for download on SplunkBase. It serves as a vital resource for enterprises aiming to reinforce their cyber resilience and protect critical data from sophisticated cyber threats.
Last updated: 4 June 2026, 1:47 pm

