Blink Security Automation — Confidential

Carlsberg — Customer Success Report

Generated 2026-09-10 | carlsberg-value-report.md
2026-09-10Report Date
102Total Playbooks
48Unique Workflows (12m)
304,727Actions Automated (12m)
$78,376Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

102
Total playbooks built
all non-deleted workflows
28
Active playbooks
currently enabled
48
Unique workflows executed (12m)
distinct workflows that ran
304,727
Actions automated (12m)
completed action steps
1,692.9h
Hours saved (12m)
@ 20s per action
$78,376
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
No automated executions were recorded in the last 12 months. The 28 playbooks below represent a fully built automation library covering identity operations, endpoint response, email security, and attack surface management. These workflows are deployed and ready but show zero execution counts in the tracking window — indicating the automation library may be in a pre-production or on-demand-only usage pattern, or that execution telemetry was not yet connected at time of export.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Identity & Access Operations0 executions
0.0%
14
14 active
Endpoint Detection & Response0 executions
0.0%
6
5 active
Email Security & Phishing Response0 executions
0.0%
4
4 active
External Attack Surface & Vulnerability Management0 executions
0.0%
4
4 active
Total0 executions100%
28
27 active

Use Case Growth Over Time

59 unique playbooks  |  4 operational use cases  |  0 total executions (12m)  |  2023-11 to 2024-11
Toggle:
Toggle:

03Integration Ecosystem

Identity & Access Operations
Microsoft Entra ID LDAP
Email Security & Phishing Response
Mimecast Microsoft Entra ID
External Attack Surface & Vulnerability Management
Qualys CyCognito Orca Security
Endpoint Detection & Response
Cortex XDR Email

04Key Observations

✓  Strengths

Strengths

  • Deep identity automation coverage. With 14 playbooks spanning Entra ID and a three-tier on-premises AD estate (T1/T2/T3), Carlsberg has built one of the more comprehensive identity response libraries seen across Blink customers. The tiered AD structure — with separate LDAP connections per tier — reflects a mature, segmented directory environment.
  • Structured EDR response chain. The Cortex XDR playbooks form a coherent response sequence: check host visibility → get last-seen info → isolate → update incident. The BDO MDR Isolate playbook adds an approval gate via email, indicating a hybrid SOC/MDR operating model with appropriate human-in-the-loop controls.
  • Email security covers the full phishing cycle. The combination of MDO analysis, Microsoft Graph bulk deletion, and Mimecast blocklist management gives analysts a complete end-to-end phishing response capability across both detection and remediation.
  • Cross-platform attack surface correlation. The CyCognito CVE playbook integrates both CyCognito and OrcaSecurity in a single workflow, enabling asset correlation across external and cloud attack surface tools — a more sophisticated pattern than single-tool lookups.

###

△  Gaps & Growth Opportunities

Gaps

  • Zero executions across all 28 playbooks. This is the most significant finding. A fully built automation library with no execution history suggests the automations are not yet integrated into active SOC workflows — whether due to a recent deployment, reliance on manual processes, or tooling not yet triggering these playbooks. The immediate priority should be wiring these playbooks into the alerting and ticketing pipeline so they run on real events.
  • No event-triggered (automated) playbooks. Every workflow in the library is automation_type: on_demand. There are no trigger-based automations — no alert-driven triage, no scheduled enrichment, no case auto-creation. On-demand playbooks require an analyst to manually initiate each run, limiting throughput and defeating the purpose of automation at scale.
  • No SIEM or ticketing integration visible. There is no ServiceNow, Jira, Splunk, Sentinel, or SOAR integration in any playbook. This means there is no automated case creation, no alert-to-action pipeline, and no ticket lifecycle management — a significant gap for a SOC operating at enterprise scale.
  • Duplicate identity playbooks. Three playbooks perform nearly identical "check user existence against EntraID" logic across two different workspaces. Consolidating these would reduce maintenance overhead and confusion.
  • No cloud security or GRC automation. Despite Carlsberg's scale as a global enterprise, there are no playbooks covering CSPM, compliance reporting, access reviews, or cloud configuration management — areas that typically carry high automation ROI at this size.

Integration Ecosystem

Tool Use Case Playbook Count
Microsoft Entra ID IAM 6
Active Directory (LDAP — T1/T2/T3) IAM 7
Cortex XDR SOC / EDR 5
CyCognito Vulnerability Mgmt 3
Microsoft Defender for Office 365 SOC / Email 1
Microsoft Graph SOC / Email 1
Mimecast SOC / Email 2
Qualys Vulnerability Mgmt 1
OrcaSecurity Vulnerability Mgmt 1 (co-used)
Email (approval gate) SOC / EDR 1
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 4 use cases | 0 executions (12m)

Business KPIs

No automated executions were recorded in the last 12 months. The 28 playbooks below represent a fully built automation library covering identity operations, endpoint response, email security, and attack surface management. These workflows are deployed and ready but show zero execution counts in the tracking window — indicating the automation library may be in a pre-production or on-demand-only usage pattern, or that execution telemetry was not yet connected at time of export.

No KPI table is generated because all executions_last_12_months values are 0. Once executions are flowing, this section will surface metrics such as:

  • Accounts disabled or suspended automatically
  • Password resets completed without helpdesk involvement
  • Endpoints isolated in response to threats
  • Phishing emails identified and deleted at scale
  • Attack surface assets inventoried by CVE exposure

Use Case Summary

# Use Case Category Subcategories Playbook Count
1 Identity & Access Operations IAM Password & credential lifecycle, Identity sync & directory mgmt, Access review & group mgmt 14
2 Endpoint Detection & Response SOC EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR 6
3 Email Security & Phishing Response SOC Phishing detection & response, Alert enrichment / IOC lookup 4
4 External Attack Surface & Vulnerability Management Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation 4

Total: 28 playbooks across 4 use cases

Use Cases

1. Identity & Access Operations

Category: IAM

Subcategories: Password & credential lifecycle · Identity sync & directory mgmt · Access review & group mgmt

Description:

Carlsberg operates a dual-domain on-premises Active Directory estate (T1/T2/T3 tiers) alongside Microsoft Entra ID (formerly Azure AD). This use case covers the full spectrum of day-to-day identity operations: account lookups, enable/disable actions, password resets, and bulk user existence checks across both directory stacks.

Business problem solved:

Identity operations are among the highest-volume, most repetitive tasks for SOC and IT teams. Manual AD and Entra ID actions are slow, error-prone, and require privileged access. These playbooks automate the response tier — enabling analysts to execute identity actions from a single interface without direct directory access, reducing MTTR on account-based incidents and eliminating helpdesk bottlenecks.

Integrations: Microsoft Entra ID · Active Directory (LDAP T1, T2, T3) · Microsoft Graph

Playbook Executions (12 mo) Link
Microsoft Entra ID - Get User 0 Open
Microsoft Entra ID - Revoke User Session 0 Open
Microsoft Entra ID - Enable/Disable User 0 Open
Microsoft Entra ID - Password Reset 0 Open
Microsoft EntraID - Check users list existence 0 Open
Microsoft Entra ID - Manually Checking multi users existence against EntraID 0 Open
Manually Checking multi users existence against EntraID 0 Open
AD T1 - Reset Password 0 Open
AD T2 - Reset Password 0 Open
AD T3 - Get User Info 0 Open
AD T1 - Disable one or more users 0 Open
AD T2 - Disable one or more users 0 Open
AD T1 - Enable User 0 Open
AD T2 - Enable User 0 Open

2. Endpoint Detection & Response

Category: SOC

Subcategories: EDR containment & response · Alert enrichment / IOC lookup · Case mgmt & SOAR

Description:

A set of Cortex XDR–driven response playbooks enabling analysts to contain threats at the endpoint layer — including device isolation by hostname, hash blocklisting, host visibility checks, last-seen lookups, and incident status updates. The BDO MDR Isolate playbook adds an approval-gated isolation workflow with email confirmation, supporting a managed detection and response handoff model.

Business problem solved:

Endpoint containment decisions are time-critical but carry blast-radius risk. These playbooks enforce a consistent, auditable response path: look up the host, confirm visibility in XDR, isolate if needed, and update the incident record — reducing the window between detection and containment while maintaining human control over high-impact actions.

Integrations: Cortex XDR · Email (approval gate)

Playbook Executions (12 mo) Link
Cortex XDR - Isolate Devices by Hostnames 0 Open
Cortex XDR - Add Hash to Block List 0 Open
Cortex XDR - Get Last Seen host Info 0 Open
Cortex XDR - Update Incident 0 Open
Cortex XDR - Check host Visible in XDR 0 Open
BDO MDR Isolate 0 Open

3. Email Security & Phishing Response

Category: SOC

Subcategories: Phishing detection & response · Alert enrichment / IOC lookup

Description:

Playbooks covering the full phishing response chain via Microsoft Defender for Office 365 (MDO) and Mimecast: analyze suspicious emails by recipient and subject, delete confirmed malicious messages at scale via Microsoft Graph, and manage Mimecast blocklist entries for sender addresses.

Business problem solved:

Phishing is Carlsberg's highest-volume threat vector. Manual email investigation and deletion across a large user base is labor-intensive and slow. These playbooks automate the triage-to-remediation pipeline — allowing an analyst to confirm a phishing campaign and trigger bulk deletion and blocklisting in a single workflow run, cutting remediation time from hours to minutes.

Integrations: Microsoft Defender for Office 365 (MDO) · Microsoft Graph · Mimecast

Playbook Executions (12 mo) Link
MDO - Analyze email 0 Open
Microsoft Graph - Delete Email 0 Open
Mimecast - Add to Block List 0 Open
Mimecast - Remove From Block List 0 Open

4. External Attack Surface & Vulnerability Management

Category: Vulnerability Mgmt

Subcategories: Vuln scanning ingest & report · CVE lookup & remediation

Description:

Playbooks integrating Qualys and CyCognito to surface vulnerability and asset exposure data on demand. Analysts can query Qualys detection results by IP address, and query the CyCognito external attack surface platform for assets matching a service, assets with specific open ports, or assets exposed to a given CVE.

Business problem solved:

Carlsberg has a broad external attack surface that requires continuous monitoring. These playbooks give analysts a fast, repeatable way to pivot from an IOC or CVE advisory to a scoped asset list — without navigating multiple consoles. The CyCognito CVE workflow also correlates against OrcaSecurity asset data, enabling cross-platform exposure correlation.

Integrations: Qualys · CyCognito · OrcaSecurity

Playbook Executions (12 mo) Link
Qualys - Scan result by IP Address 0 Open
cycognito search for assets with giving service query 0 Open
cycognito search for assets with open ports from list 0 Open
cycognito search for assets related to cve 0 Open

Key Observations

Strengths

  • Deep identity automation coverage. With 14 playbooks spanning Entra ID and a three-tier on-premises AD estate (T1/T2/T3), Carlsberg has built one of the more comprehensive identity response libraries seen across Blink customers. The tiered AD structure — with separate LDAP connections per tier — reflects a mature, segmented directory environment.
  • Structured EDR response chain. The Cortex XDR playbooks form a coherent response sequence: check host visibility → get last-seen info → isolate → update incident. The BDO MDR Isolate playbook adds an approval gate via email, indicating a hybrid SOC/MDR operating model with appropriate human-in-the-loop controls.
  • Email security covers the full phishing cycle. The combination of MDO analysis, Microsoft Graph bulk deletion, and Mimecast blocklist management gives analysts a complete end-to-end phishing response capability across both detection and remediation.
  • Cross-platform attack surface correlation. The CyCognito CVE playbook integrates both CyCognito and OrcaSecurity in a single workflow, enabling asset correlation across external and cloud attack surface tools — a more sophisticated pattern than single-tool lookups.

Gaps

  • Zero executions across all 28 playbooks. This is the most significant finding. A fully built automation library with no execution history suggests the automations are not yet integrated into active SOC workflows — whether due to a recent deployment, reliance on manual processes, or tooling not yet triggering these playbooks. The immediate priority should be wiring these playbooks into the alerting and ticketing pipeline so they run on real events.
  • No event-triggered (automated) playbooks. Every workflow in the library is automation_type: on_demand. There are no trigger-based automations — no alert-driven triage, no scheduled enrichment, no case auto-creation. On-demand playbooks require an analyst to manually initiate each run, limiting throughput and defeating the purpose of automation at scale.
  • No SIEM or ticketing integration visible. There is no ServiceNow, Jira, Splunk, Sentinel, or SOAR integration in any playbook. This means there is no automated case creation, no alert-to-action pipeline, and no ticket lifecycle management — a significant gap for a SOC operating at enterprise scale.
  • Duplicate identity playbooks. Three playbooks perform nearly identical "check user existence against EntraID" logic across two different workspaces. Consolidating these would reduce maintenance overhead and confusion.
  • No cloud security or GRC automation. Despite Carlsberg's scale as a global enterprise, there are no playbooks covering CSPM, compliance reporting, access reviews, or cloud configuration management — areas that typically carry high automation ROI at this size.

Integration Ecosystem

Tool Use Case Playbook Count
Microsoft Entra ID IAM 6
Active Directory (LDAP — T1/T2/T3) IAM 7
Cortex XDR SOC / EDR 5
CyCognito Vulnerability Mgmt 3
Microsoft Defender for Office 365 SOC / Email 1
Microsoft Graph SOC / Email 1
Mimecast SOC / Email 2
Qualys Vulnerability Mgmt 1
OrcaSecurity Vulnerability Mgmt 1 (co-used)
Email (approval gate) SOC / EDR 1
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.