01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Identity & Access Operations | 0 executions | 0.0% | 14 14 active |
| Endpoint Detection & Response | 0 executions | 0.0% | 6 5 active |
| Email Security & Phishing Response | 0 executions | 0.0% | 4 4 active |
| External Attack Surface & Vulnerability Management | 0 executions | 0.0% | 4 4 active |
| Total | 0 executions | 100% | 28 27 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Deep identity automation coverage. With 14 playbooks spanning Entra ID and a three-tier on-premises AD estate (T1/T2/T3), Carlsberg has built one of the more comprehensive identity response libraries seen across Blink customers. The tiered AD structure — with separate LDAP connections per tier — reflects a mature, segmented directory environment.
- Structured EDR response chain. The Cortex XDR playbooks form a coherent response sequence: check host visibility → get last-seen info → isolate → update incident. The BDO MDR Isolate playbook adds an approval gate via email, indicating a hybrid SOC/MDR operating model with appropriate human-in-the-loop controls.
- Email security covers the full phishing cycle. The combination of MDO analysis, Microsoft Graph bulk deletion, and Mimecast blocklist management gives analysts a complete end-to-end phishing response capability across both detection and remediation.
- Cross-platform attack surface correlation. The CyCognito CVE playbook integrates both CyCognito and OrcaSecurity in a single workflow, enabling asset correlation across external and cloud attack surface tools — a more sophisticated pattern than single-tool lookups.
###
Gaps
- Zero executions across all 28 playbooks. This is the most significant finding. A fully built automation library with no execution history suggests the automations are not yet integrated into active SOC workflows — whether due to a recent deployment, reliance on manual processes, or tooling not yet triggering these playbooks. The immediate priority should be wiring these playbooks into the alerting and ticketing pipeline so they run on real events.
- No event-triggered (automated) playbooks. Every workflow in the library is
automation_type: on_demand. There are no trigger-based automations — no alert-driven triage, no scheduled enrichment, no case auto-creation. On-demand playbooks require an analyst to manually initiate each run, limiting throughput and defeating the purpose of automation at scale.
- No SIEM or ticketing integration visible. There is no ServiceNow, Jira, Splunk, Sentinel, or SOAR integration in any playbook. This means there is no automated case creation, no alert-to-action pipeline, and no ticket lifecycle management — a significant gap for a SOC operating at enterprise scale.
- Duplicate identity playbooks. Three playbooks perform nearly identical "check user existence against EntraID" logic across two different workspaces. Consolidating these would reduce maintenance overhead and confusion.
- No cloud security or GRC automation. Despite Carlsberg's scale as a global enterprise, there are no playbooks covering CSPM, compliance reporting, access reviews, or cloud configuration management — areas that typically carry high automation ROI at this size.
Integration Ecosystem
| Tool | Use Case | Playbook Count |
|---|---|---|
| Microsoft Entra ID | IAM | 6 |
| Active Directory (LDAP — T1/T2/T3) | IAM | 7 |
| Cortex XDR | SOC / EDR | 5 |
| CyCognito | Vulnerability Mgmt | 3 |
| Microsoft Defender for Office 365 | SOC / Email | 1 |
| Microsoft Graph | SOC / Email | 1 |
| Mimecast | SOC / Email | 2 |
| Qualys | Vulnerability Mgmt | 1 |
| OrcaSecurity | Vulnerability Mgmt | 1 (co-used) |
| Email (approval gate) | SOC / EDR | 1 |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 4 use cases | 0 executions (12m)
Business KPIs
No KPI table is generated because all executions_last_12_months values are 0. Once executions are flowing, this section will surface metrics such as:
- Accounts disabled or suspended automatically
- Password resets completed without helpdesk involvement
- Endpoints isolated in response to threats
- Phishing emails identified and deleted at scale
- Attack surface assets inventoried by CVE exposure
Use Case Summary
| # | Use Case | Category | Subcategories | Playbook Count |
|---|---|---|---|---|
| 1 | Identity & Access Operations | IAM | Password & credential lifecycle, Identity sync & directory mgmt, Access review & group mgmt | 14 |
| 2 | Endpoint Detection & Response | SOC | EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR | 6 |
| 3 | Email Security & Phishing Response | SOC | Phishing detection & response, Alert enrichment / IOC lookup | 4 |
| 4 | External Attack Surface & Vulnerability Management | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation | 4 |
Total: 28 playbooks across 4 use cases
Use Cases
1. Identity & Access Operations
Category: IAM
Subcategories: Password & credential lifecycle · Identity sync & directory mgmt · Access review & group mgmt
Description:
Carlsberg operates a dual-domain on-premises Active Directory estate (T1/T2/T3 tiers) alongside Microsoft Entra ID (formerly Azure AD). This use case covers the full spectrum of day-to-day identity operations: account lookups, enable/disable actions, password resets, and bulk user existence checks across both directory stacks.
Business problem solved:
Identity operations are among the highest-volume, most repetitive tasks for SOC and IT teams. Manual AD and Entra ID actions are slow, error-prone, and require privileged access. These playbooks automate the response tier — enabling analysts to execute identity actions from a single interface without direct directory access, reducing MTTR on account-based incidents and eliminating helpdesk bottlenecks.
Integrations: Microsoft Entra ID · Active Directory (LDAP T1, T2, T3) · Microsoft Graph
| Playbook | Executions (12 mo) | Link |
|---|---|---|
| Microsoft Entra ID - Get User | 0 | Open |
| Microsoft Entra ID - Revoke User Session | 0 | Open |
| Microsoft Entra ID - Enable/Disable User | 0 | Open |
| Microsoft Entra ID - Password Reset | 0 | Open |
| Microsoft EntraID - Check users list existence | 0 | Open |
| Microsoft Entra ID - Manually Checking multi users existence against EntraID | 0 | Open |
| Manually Checking multi users existence against EntraID | 0 | Open |
| AD T1 - Reset Password | 0 | Open |
| AD T2 - Reset Password | 0 | Open |
| AD T3 - Get User Info | 0 | Open |
| AD T1 - Disable one or more users | 0 | Open |
| AD T2 - Disable one or more users | 0 | Open |
| AD T1 - Enable User | 0 | Open |
| AD T2 - Enable User | 0 | Open |
2. Endpoint Detection & Response
Category: SOC
Subcategories: EDR containment & response · Alert enrichment / IOC lookup · Case mgmt & SOAR
Description:
A set of Cortex XDR–driven response playbooks enabling analysts to contain threats at the endpoint layer — including device isolation by hostname, hash blocklisting, host visibility checks, last-seen lookups, and incident status updates. The BDO MDR Isolate playbook adds an approval-gated isolation workflow with email confirmation, supporting a managed detection and response handoff model.
Business problem solved:
Endpoint containment decisions are time-critical but carry blast-radius risk. These playbooks enforce a consistent, auditable response path: look up the host, confirm visibility in XDR, isolate if needed, and update the incident record — reducing the window between detection and containment while maintaining human control over high-impact actions.
Integrations: Cortex XDR · Email (approval gate)
| Playbook | Executions (12 mo) | Link |
|---|---|---|
| Cortex XDR - Isolate Devices by Hostnames | 0 | Open |
| Cortex XDR - Add Hash to Block List | 0 | Open |
| Cortex XDR - Get Last Seen host Info | 0 | Open |
| Cortex XDR - Update Incident | 0 | Open |
| Cortex XDR - Check host Visible in XDR | 0 | Open |
| BDO MDR Isolate | 0 | Open |
3. Email Security & Phishing Response
Category: SOC
Subcategories: Phishing detection & response · Alert enrichment / IOC lookup
Description:
Playbooks covering the full phishing response chain via Microsoft Defender for Office 365 (MDO) and Mimecast: analyze suspicious emails by recipient and subject, delete confirmed malicious messages at scale via Microsoft Graph, and manage Mimecast blocklist entries for sender addresses.
Business problem solved:
Phishing is Carlsberg's highest-volume threat vector. Manual email investigation and deletion across a large user base is labor-intensive and slow. These playbooks automate the triage-to-remediation pipeline — allowing an analyst to confirm a phishing campaign and trigger bulk deletion and blocklisting in a single workflow run, cutting remediation time from hours to minutes.
Integrations: Microsoft Defender for Office 365 (MDO) · Microsoft Graph · Mimecast
| Playbook | Executions (12 mo) | Link |
|---|---|---|
| MDO - Analyze email | 0 | Open |
| Microsoft Graph - Delete Email | 0 | Open |
| Mimecast - Add to Block List | 0 | Open |
| Mimecast - Remove From Block List | 0 | Open |
4. External Attack Surface & Vulnerability Management
Category: Vulnerability Mgmt
Subcategories: Vuln scanning ingest & report · CVE lookup & remediation
Description:
Playbooks integrating Qualys and CyCognito to surface vulnerability and asset exposure data on demand. Analysts can query Qualys detection results by IP address, and query the CyCognito external attack surface platform for assets matching a service, assets with specific open ports, or assets exposed to a given CVE.
Business problem solved:
Carlsberg has a broad external attack surface that requires continuous monitoring. These playbooks give analysts a fast, repeatable way to pivot from an IOC or CVE advisory to a scoped asset list — without navigating multiple consoles. The CyCognito CVE workflow also correlates against OrcaSecurity asset data, enabling cross-platform exposure correlation.
Integrations: Qualys · CyCognito · OrcaSecurity
| Playbook | Executions (12 mo) | Link |
|---|---|---|
| Qualys - Scan result by IP Address | 0 | Open |
| cycognito search for assets with giving service query | 0 | Open |
| cycognito search for assets with open ports from list | 0 | Open |
| cycognito search for assets related to cve | 0 | Open |
Key Observations
Strengths
- Deep identity automation coverage. With 14 playbooks spanning Entra ID and a three-tier on-premises AD estate (T1/T2/T3), Carlsberg has built one of the more comprehensive identity response libraries seen across Blink customers. The tiered AD structure — with separate LDAP connections per tier — reflects a mature, segmented directory environment.
- Structured EDR response chain. The Cortex XDR playbooks form a coherent response sequence: check host visibility → get last-seen info → isolate → update incident. The BDO MDR Isolate playbook adds an approval gate via email, indicating a hybrid SOC/MDR operating model with appropriate human-in-the-loop controls.
- Email security covers the full phishing cycle. The combination of MDO analysis, Microsoft Graph bulk deletion, and Mimecast blocklist management gives analysts a complete end-to-end phishing response capability across both detection and remediation.
- Cross-platform attack surface correlation. The CyCognito CVE playbook integrates both CyCognito and OrcaSecurity in a single workflow, enabling asset correlation across external and cloud attack surface tools — a more sophisticated pattern than single-tool lookups.
Gaps
- Zero executions across all 28 playbooks. This is the most significant finding. A fully built automation library with no execution history suggests the automations are not yet integrated into active SOC workflows — whether due to a recent deployment, reliance on manual processes, or tooling not yet triggering these playbooks. The immediate priority should be wiring these playbooks into the alerting and ticketing pipeline so they run on real events.
- No event-triggered (automated) playbooks. Every workflow in the library is
automation_type: on_demand. There are no trigger-based automations — no alert-driven triage, no scheduled enrichment, no case auto-creation. On-demand playbooks require an analyst to manually initiate each run, limiting throughput and defeating the purpose of automation at scale.
- No SIEM or ticketing integration visible. There is no ServiceNow, Jira, Splunk, Sentinel, or SOAR integration in any playbook. This means there is no automated case creation, no alert-to-action pipeline, and no ticket lifecycle management — a significant gap for a SOC operating at enterprise scale.
- Duplicate identity playbooks. Three playbooks perform nearly identical "check user existence against EntraID" logic across two different workspaces. Consolidating these would reduce maintenance overhead and confusion.
- No cloud security or GRC automation. Despite Carlsberg's scale as a global enterprise, there are no playbooks covering CSPM, compliance reporting, access reviews, or cloud configuration management — areas that typically carry high automation ROI at this size.
Integration Ecosystem
| Tool | Use Case | Playbook Count |
|---|---|---|
| Microsoft Entra ID | IAM | 6 |
| Active Directory (LDAP — T1/T2/T3) | IAM | 7 |
| Cortex XDR | SOC / EDR | 5 |
| CyCognito | Vulnerability Mgmt | 3 |
| Microsoft Defender for Office 365 | SOC / Email | 1 |
| Microsoft Graph | SOC / Email | 1 |
| Mimecast | SOC / Email | 2 |
| Qualys | Vulnerability Mgmt | 1 |
| OrcaSecurity | Vulnerability Mgmt | 1 (co-used) |
| Email (approval gate) | SOC / EDR | 1 |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.