Global Hospitality Leader Builds Automations 40x Faster With Torq

Industry: Hospitality |
Region: Global |
Product: Torq AI SOC Platform |

Case Study Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster.

Request a Demo

Replacing Splunk Before the Renewal Clock Ran Out

A globally recognized hospitality enterprise operating nearly 10,000 properties across luxury, upscale, and extended-stay segments came to Torq with a blunt assessment of its incumbent platform: “We’re replacing Splunk because it really slows us down.”

After three years on Splunk, the team had accumulated legacy scripting, dependency sprawl, and slow iteration cycles that throttled them to roughly six new automations a year. Splunk frequently bundled Phantom into large platform suites, an arrangement that sounded efficient but pushed real outcomes into expensive professional services engagements. Worse, a contract renewal deadline was closing in.

The team needed not just an AI SOC, but a partner that could hit a hard target on a tight timeline.

Torq is not a SOAR. It’s the AI SOC platform leader that runs the entire threat lifecycle end-to-end, from agentic triage through investigation and remediation — helping security teams displace legacy tech and augment their SOC staff.


An AI SOC Platform, Not Another SOAR

The Torq AI SOC Platform combines agentic AI, case management, and security automation into a single platform that spans the entire threat lifecycle, from triage through investigation, response, and remediation. Where legacy SOAR stops at executing brittle playbooks, Torq’s AI agents prioritize risks, investigate threats, and take action across the stack, with analysts in the loop for the calls that need human judgment. All agentic reasoning and actions are transparently logged.

That design eliminates the weaknesses of legacy SOAR, expands SOC capacity, accelerates throughput, and delivers end-to-end SecOps at scale. The Torq platform is also built to handle both halves of a migration: rapid like-for-like replacement of legacy automation and the strategic upleveling that follows.


How the Team Put Torq to Work

Torq punched the accelerator for the hospitality company. Their team streamlined the 25 clunky workflows Splunk required for its key use cases into 18 agentic Torq automations in just six weeks, leaving behind three years of accumulated complexity.

With Socrates and the Agentic Builder’s natural-language prompting, the company now builds agentic and deterministic security automations 40x faster than before, without the heavy scripting and maintenance Splunk demanded.

A few of the Torq platform capabilities that made it possible:

Socrates, the AI SOC orchestrator
Security teams describe what they need in plain language, and Socrates plans, builds, tests, and deploys the workflows, turning migration into a sprint instead of a marathon.

Native Case Management
Each security team gets a dedicated workspace with tailored access and reporting, while leadership keeps cross-team visibility. Using Torq Interact, the team built interactive forms that human and AI analysts use to send templated, compliance-guardrail notification emails directly from quick-action buttons in a Torq case

Complete transparency
Every step is auditable, with no hidden calls or Python bypasses. All agentic reasoning is documented, and verdicts can be overridden. For an enterprise under regulatory scrutiny, Torq also provides agent templates for compliance assessments of policy and configuration drift and for expediting a return to an approved state.

Six Use Cases Deployed

Hospitality companies depend on seamless, trusted experiences at every guest touchpoint, from booking to checkout. Torq rapidly deployed six key use cases to secure frictionless operations across the company’s global properties and back-office systems:

  1. Phishing alerts and remediation
  2. CrowdStrike detections, host forensics, and workflow monitoring
  3. Asset tagging workflows
  4. Insider threat email enrichment
  5. Vulnerability management
  6. Threat intelligence operations

Unified AI SOC, Building 40x Faster

In six weeks, the hospitality leader stood up a unified AI SOC platform and left behind three years of legacy SOAR slowdowns:

40x faster automation builds
What once took heavy scripting and dedicated SMEs is now declarative and accessible to the whole team, lifting the ceiling far above Splunk’s roughly six automations a year.

Three years of legacy SOAR, migrated in six weeks
25 clunky Splunk workflows were streamlined into 18 agentic Torq automations, a 28% reduction in count and a clean break from accumulated complexity.

Self-reliance
What previously required expensive professional services engagements can now be done in-house in hours. Agentic Builder simplifies migration and fuels ongoing innovation, giving the team control over its own roadmap.

Audit-ready transparency:
Every decision and action in Torq is logged and overridable, and compliance agent templates help the team assess policy and configuration drift and quickly return to an approved state.

Case Management as a single source of collaboration
Each team — SOC, vulnerability management, insider threat — now has its own workspace and reporting, with leadership visibility across all of them. Using Torq Interact, the team created interactive forms that human and AI analysts alike use to send templated notification emails directly from quick action buttons within a Torq case with built-in comms compliance guardrails. What once required expensive professional services engagements to modify can now be updated in-house, in hours.

For teams running legacy SOAR against a renewal deadline, the path out is a strategic moment. This hospitality leader used six weeks of urgency to retire three years of technical debt and adopt an AI SOC platform built for what the SOC needs to do next: agentic AI across the threat lifecycle, native case management, and an architecture that compounds value over time.