A security alert is a peculiar sort of achievement. A machine has noticed something suspicious. An expensive system has done its job. Now a person must work out whether the alarm matters, which other alarms belong beside it, and who has permission to act. The software has delivered a warning. It has also delivered homework.
Siemplify built its business around that homework. Founded in 2015 by Amos Stern, Garry Fatakhov, and Alon Cohen, it offered a shared security operations workbench. In January 2022, Google acquired the company. The attraction was the distance Siemplify could help close between noticing a threat and responding to it.
- The job: connect security tools, group related alerts, and coordinate investigation and response.
- The buyers: enterprise security teams and managed security service providers.
- The outcome: $58 million raised before acquisition; the technology now sits within Google Security Operations.
01 / The trainers saw the trouble
The founders met at Elbit Systems, the Israeli defense contractor, where they trained security operations teams around the world. That work offered an unusually useful vantage point. Training exposes the gap between what a system promises and what a tired person actually has to do with it.
The recurring problem was operational: teams moved among separate tools, gathered context, and repeated tasks. In a later interview, Siemplify’s marketing chief described how those experiences persuaded the founders to build a product. Their expertise came from watching security operations happen, with all the awkward handoffs included.

02 / Give the alarm a case
The category is SOAR: security orchestration, automation, and response. Orchestration lets different products participate in one workflow. Automation handles repeatable steps. Response turns the investigation into an action. Siemplify wrapped those capabilities in case management, contextual investigation, and reporting for the people running the security operations center, or SOC.
Its distinctive pitch was breadth within the workbench. Related alerts could be grouped into a case; analysts could investigate connected entities; engineers could build reusable playbook blocks rather than repeatedly assemble the same steps. Managers could see workflows and performance. Siemplify sold a place where those jobs met.
The useful unit is the investigation. Conceptual workflow, not a measured performance claim.
A concrete example appeared in its Check Point partnership: a workflow could support malware investigation or firewall policy management, drawing on integrated tools to investigate and remediate. The same announcement described more than 200 third-party integrations in 2020. That is a historical figure, but it explains the appeal: customers already had security equipment worth connecting.
03 / The customers had queues
An enterprise SOC handles its employer’s security incidents. An MSSP does similar work for multiple customers, making consistency, reporting, and repeated procedures commercially consequential. Both were central to Siemplify’s market. Historical product material named Choice Solutions and Crowe among its customer references.
“My analysts love Siemplify.”Cameron Rayner, SOC Manager, Crowe
Siemplify product overview, 2020
That short endorsement is vendor-published, and enthusiasm is no substitute for an evaluation. Still, it points to the product’s chosen audience. Analysts had to use the system every day. A clever automation engine would be a poor purchase if the investigation around it remained a chore.
Alternatives included other SOAR products such as Demisto, now Cortex XSOAR, and Swimlane. Siemplify’s claimed distinction was its complete SOC workbench. That was a positioning argument, not proof that competitors lacked case management or that every team would prefer it.
04 / The money followed the workflow
The financing came in stages: $4 million in early funding and a $10 million Series A in 2016, then $14 million in 2018. Georgian Partners led the $30 million Series C in May 2019, with existing investors participating. The stated uses included global commercial expansion and further product development.
Siemplify reported doubling annual recurring revenue and its customer install base during 2019. Those are company-reported growth measures, without absolute totals. Its business depended on recurring software revenue and distribution; the September 2020 agreement made Check Point a reseller as well as an integration partner.
Google announced the acquisition on January 4, 2022. Reuters reported a price of about $500 million, citing a source; Google did not disclose the sum. For today’s buyer, the relevant cost is a quoted Google SecOps subscription plus the work of implementation. Google’s product page directs customers to sales for package pricing.
05 / A workbench becomes part of the machinery
Google’s public rationale paired Siemplify’s response capabilities with Chronicle’s security analytics. In October 2022, it announced Chronicle Security Operations and said the Siemplify brand would become Chronicle SOAR. By 2024, the combined offering was being presented as Google Security Operations, with additional intelligence and AI capabilities.
The lineage remains visible in the work. September 2026 release notes introduce case playbooks and reaction triggers in preview: workflows can operate across a case or react to changes during an investigation. The unit of attention is still the case, and the practical ambition is still to reduce repeated effort.

06 / Start with the tedious investigation
The useful lesson is available without buying anything. Siemplify’s MSSP buyer guide recommends evaluating processes with many manual tasks across multiple products. Pick one recurring investigation. Map the handoffs. Decide who owns each action. Measure the effort before automating it.
This approach needs usable integrations, maintained playbooks, and clear authority to act. A rare, poorly understood incident offers fewer repeatable steps. An unattended workflow can preserve a bad decision remarkably efficiently. The sensible test is whether a real team can complete a real investigation with less friction.
There is a pleasing human footnote. During the pandemic, Stern said distributed work could succeed, but physical meetups still mattered: “a tether is absolutely necessary.” Even a company selling a shared digital workbench understood that collaboration had a social cost. The software could organize the case. People still had to trust one another with it.