Blink Security Automation — Confidential

Cato Networks — Customer Success Report

Generated 2026-09-10 | cato-networks-value-report.md
2026-09-10Report Date
115Total Playbooks
52Unique Workflows (12m)
102,801Actions Automated (12m)
$26,441Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

115
Total playbooks built
all non-deleted workflows
23
Active playbooks
currently enabled
52
Unique workflows executed (12m)
distinct workflows that ran
102,801
Actions automated (12m)
completed action steps
571.1h
Hours saved (12m)
@ 20s per action
$26,441
Money saved (12m)
@ $100K avg salary
5
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 4 total
118
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 667 after-hours office access events verified with the badge holder - 424 region-aware password expiration alert sweeps delivered to employees - 397 IT support tickets enriched with device, user & network telemetry - 271 security awareness training completion checks processed - 192 security alerts auto-triaged & converted into cases - 152 inactive-user sweeps against the corporate directory - 124 ad-hoc user investigations completed from a Slack command - 93 vendor contact integrity checks performed - 69 phishing-simulation result syncs - 68 cyber-intel alerts (domain takedown + credential exposure) auto-triaged with LLM extraction - 62 weekly endpoint USB-mount threat hunts - 17 internal security-awareness scoring events processed - 11 phishing campaign summaries served on-demand from Slack - 8 laptop self-service price calculations completed - 5 office parking automations served via Slack

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
IT Helpdesk Ticket Enrichment
  • 276IT support tickets auto-enriched with device, user & network context
5.8%
3
0 active
Phishing Simulation & Awareness Training
  • 69Quarterly phishing-simulation result syncs
  • 11Phishing campaign summaries served on-demand from Slack
16.6%
10
2 active
Password Expiration Lifecycle811 executions
23.4%
4
0 active
Identity Lifecycle & Access Review
  • 152Daily inactive-user sweeps against the corporate directory
  • 2HR-source new-hire roll-ups generated (monthly)
7.4%
3
3 active
Security Alert Triage & Case Management
  • 192Security alerts (Elastic) auto-enriched and converted into cases
5.6%
4
0 active
Threat Intel Auto-Triage
  • 44Cyber-intel domain takedown alerts auto-triaged with LLM extraction
  • 24Cyber-intel credential exposure alerts auto-triaged with LLM extraction
2.9%
2
2 active
Threat Hunting & User Investigation
  • 124One-Slack-command user investigations completed
  • 62Weekly endpoint USB-mount threat hunts
3.2%
2
1 active
Workforce Physical Access Verification
  • 667After-hours office access events verified with the badge holder
1.2%
1
0 active
Vendor Risk Monitoring
  • 93Vendor contact integrity checks (cross-domain email risk)
5.5%
1
1 active
IT Self-Service & Operations
  • 10Slack-driven IT lookups for terminated-user laptop calculations
  • 8Laptop self-service price calculations completed (web form)
  • 5Office parking automation requests served via Slack
1.4%
5
3 active
Cloud Security Posture0 executions
0.0%
1
0 active
Network Infrastructure Monitoring37 executions
1.1%
1
1 active
Total2,561 executions100%
37
13 active

Use Case Growth Over Time

83 unique playbooks  |  12 operational use cases  |  3,459 total executions (12m)  |  2025-05 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Security Alert Triage & Case Management
Slack Email AbuseIPDB Microsoft Graph Cato Networks
Phishing Simulation & Awareness Training
Microsoft Graph Slack
Workforce Physical Access Verification
Slack
Threat Hunting & User Investigation
Microsoft Graph Email Slack Microsoft Defender For Endpoints Microsoft Entra ID Microsoft Intune Kandji
Cloud Security Posture
AWS Email
Threat Intel Auto-Triage
Slack Jira
Identity Lifecycle & Access Review
Microsoft Entra ID Slack HiBob
Password Expiration Lifecycle
Microsoft Entra ID Slack Microsoft Outlook
IT Self-Service & Operations
Slack HiBob Dots Web Form Apple Business Manager
IT Helpdesk Ticket Enrichment
Freshservice Microsoft Intune Kandji Agents Cato Networks Slack
Network Infrastructure Monitoring
Slack

04Key Observations

✓  Strengths

Strengths

  • Mature self-service awareness program. Phishing-sim + LMS + three internal gamified-awareness apps all feed a single per-employee scorecard surfaced through Slack — this is well beyond what most security programs do for awareness analytics.
  • Region-aware lifecycle workflows. The Pass-Expiration use case is split into Americas / EMEA / APAC variants so alerts land in working hours — a small detail that drives big reductions in help-desk volume.
  • AI-assisted intel parsing. Cyber-intel auto-triage uses Azure OpenAI to extract structured indicators from unstructured alert bodies — turning what is usually 5+ minutes of analyst work into a sub-second extract.
  • First-class IT-ticket enrichment. The Freshservice ticket-enrichment workflow pulls device data from both Kandji (Mac) and Intune (Windows) plus Cato Networks SDP context, and posts a structured note back to the ticket. This is one of the highest-volume workflows in the environment.
  • Strong identity surface coverage. Microsoft Entra ID, HiBob, Slack, Kandji, and Intune are all wired into the same automation fabric — making one-Slack-command user investigations possible across all of them.

△  Gaps & Growth Opportunities

Gaps / Opportunities

  • Cloud Security Posture is under-utilized. The single AWS IAM root-MFA check is published but never executed on a schedule. There's runway here to add scheduled CSPM-style sweeps (S3 public buckets, security-group exposure, IAM key age).
  • Vulnerability Management is absent. No workflows tie scanner output (Tenable / Wiz / Qualys-style) to ticket creation or owner notification. A vuln-to-ticket pipeline would be a natural next addition.
  • EDR containment & response is observational only. The USB-mount hunt detects but does not isolate / block. A "compromised host → isolate via Defender / Kandji lock" workflow would close that loop.
  • Several "test" / draft workflows in production. Names like "Elastic Test", "TEST- Self service Portal", "Device Enrichment - Cursor Edition" are running with meaningful execution counts — they should be promoted to production names (no TEST / Cursor Edition suffixes) and the obsolete duplicates retired.
  • Many regional / backup duplicates. There are 6+ Pass Exp Alert variants (backup-with-region, backup-no-region, copy, copy-copy, 16/02). Consolidating to the live four (master + Americas/EMEA/APAC) would reduce drift risk.

Integration ecosystem

The active automations span ~25 distinct integrations: Microsoft Entra ID, Microsoft Graph, Microsoft Defender for Endpoint, Microsoft Intune, Microsoft Outlook, Kandji, Slack, Jira, Freshservice, HiBob, Cato Networks, Genea, Elastic, AbuseIPDB, Azure OpenAI, Skilljar, ZIP, Apple Business Manager, AWS, Mist (Juniper), plus the Blink-native primitives (Tables, Web Form, Case Management, Python, HTTP, Global Variables). The Microsoft stack + Slack form the backbone of most workflows.

Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 118 tasks (12m)

AI Agents

Active Agents
1
of 4 total
Tasks Executed (12m)
118
0 in last 30d
Data Usage (12m)
6,222,122
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 IT-Device-Enrichment alex.dolea@catonetworks.com 118 0 6,222,122
2 Agent Blink Information Security 0 0 0
3 Agent Blink Security Operations & Systems 0 0 0
4 Agent Blink shahar.laksman@catonetworks.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
alex.dolea@catonetworks.com118
Information Security 0
Security Operations & Systems0
shahar.laksman@catonetworks.com0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 12 use cases | 3,459 executions (12m)

Business KPIs

Metric Count Playbook
After-hours office access events verified with the badge holder 667 Genea
IT support tickets auto-enriched with device, user & network context 276 Freshservice Ticket - Device Info
Security awareness training completion checks processed 271 Tutorials scoring – day 1 / day 2 / day 3 / day 4
Security alerts (Elastic) auto-enriched and converted into cases 192 Elastic Test
Daily inactive-user sweeps against the corporate directory 152 Inactive users- CatoAll group
One-Slack-command user investigations completed 124 One-Query User Investigator
Region-aware password expiration alert sweeps delivered 424 Pass Exp Alert (109) / Americas (107) / EMEA (101) / APAC (107)
Vendor contact integrity checks (cross-domain email risk) 93 ZIP Vendor Contact checking
Quarterly phishing-simulation result syncs 69 Phishing Simulation - Scores
Cyber-intel domain takedown alerts auto-triaged with LLM extraction 44 Cyber Intel Alerts- Domain take Down
Cyber-intel credential exposure alerts auto-triaged with LLM extraction 24 Cyber Intel Alerts- Credentials
Weekly endpoint USB-mount threat hunts 62 Detect DOK connection
Internal security-awareness scoring events (Base 44 games) 17 ObjectHunt (7) / PhraseHunt (7) / Connections Daily (3)
Phishing campaign summaries served on-demand from Slack 11 Phishing Campaign Summary
Slack-driven IT lookups for terminated-user laptop calculations 10 Slack /command trigger
Laptop self-service price calculations completed (web form) 8 Webform - Laptop Price Calculator
Office parking automation requests served via Slack 5 Slack Trigger Parking Automation
HR-source new-hire roll-ups generated (monthly) 2 Hibob New Hired Collection
In the last 12 months, Blink automated: - 667 after-hours office access events verified with the badge holder - 424 region-aware password expiration alert sweeps delivered to employees - 397 IT support tickets enriched with device, user & network telemetry - 271 security awareness training completion checks processed - 192 security alerts auto-triaged & converted into cases - 152 inactive-user sweeps against the corporate directory - 124 ad-hoc user investigations completed from a Slack command - 93 vendor contact integrity checks performed - 69 phishing-simulation result syncs - 68 cyber-intel alerts (domain takedown + credential exposure) auto-triaged with LLM extraction - 62 weekly endpoint USB-mount threat hunts - 17 internal security-awareness scoring events processed - 11 phishing campaign summaries served on-demand from Slack - 8 laptop self-service price calculations completed - 5 office parking automations served via Slack

Use Case Summary

# Use Case Category Playbooks
1 IT Helpdesk Ticket Enrichment Other 6
2 Phishing Simulation & Awareness Training SOC 10
3 Password Expiration Lifecycle IAM 4
4 Identity Lifecycle & Access Review IAM 3
5 Security Alert Triage & Case Management SOC 4
6 Threat Intel Auto-Triage SOC 2
7 Threat Hunting & User Investigation SOC 3
8 Workforce Physical Access Verification SOC 1
9 Vendor Risk Monitoring GRC 1
10 IT Self-Service & Operations Other 5
11 Cloud Security Posture Cloud Security 1
12 Network Infrastructure Monitoring Other 1

Use Cases

1. IT Helpdesk Ticket Enrichment

Description. When a Freshservice ticket is opened, Blink automatically classifies the request, identifies the requester's primary device across Kandji (Mac) and Intune (Windows), looks up Cato Networks SDP/Socket connection data, and posts a structured enrichment note back onto the ticket so the IT analyst has the full context without manual data-gathering.

Business problem. IT analysts spend the first minutes of every ticket pivoting between Freshservice, the MDM (Kandji/Intune), the directory, and the SD-WAN. Blink collapses that into a single enrichment note — cutting mean-time-to-first-response and reducing the back-and-forth with the requester.

Integrations. Freshservice · Kandji · Microsoft Intune · Microsoft Entra ID · Cato Networks · HiBob · Agents (LLM classifier) · Slack

Playbook Executions (12mo) Trigger
Freshservice Ticket - Device Info 276 Freshservice webhook
Device Enrichment - Main 121 Webhook
Device Enrichment - Cursor Edition 51 Webhook
List Users' Kandji Device 86 Subflow (on-demand)
List Users' Intune Devices 0 Subflow (on-demand)
Find Employee Manager 0 Subflow (on-demand)

2. Phishing Simulation & Awareness Training

Description. A full security-awareness scoring program: Microsoft Defender phishing-simulation results are pulled quarterly, Skilljar tutorial completions are checked every 4 hours across all 4 onboarding days, and three internal gamified-awareness apps (Base 44 — ObjectHunt, PhraseHunt, Connections) score employees in real time. A self-service Slack portal surfaces an employee's combined awareness scorecard.

Business problem. Security awareness programs typically suffer from siloed scoring across the phishing-sim platform, the LMS, and any custom training. Blink consolidates all of it into a single per-employee score, surfaced on-demand via Slack — and keeps a historical record for trend analysis.

Integrations. Microsoft Graph (Defender / Attack Simulator) · Skilljar (HTTP) · Slack · Tables · HiBob · Web Form

Playbook Executions (12mo) Trigger
Tutorials scoring- day 1 70 Scheduled (every 4h)
Tutorials scoring- day 2 67 Scheduled (every 4h)
Tutorials scoring- day 3 67 Scheduled (every 4h)
Tutorials scoring- day 4 67 Scheduled (every 4h)
Phishing Simulation - Scores 69 Scheduled (quarterly)
Phishing Simulation - Update Table - Subflow 2 Subflow
Phishing Simulation - Init Table from CSV 1 On-demand
Phishing Campaign Summary 11 Slack webhook
Base 44- ObjectHunt Scoring 7 Webhook
Base 44- PhraseHunt Scoring 7 Webhook
Base 44- Connections Daily Scoring 3 Webhook
TEST- Self service Portal 6 Webhook
Upload BOB excel to table 4 Web form

3. Password Expiration Lifecycle

Description. Four daily scheduled workflows (global + three regional variants — Americas, EMEA, APAC) query Microsoft Entra ID for accounts whose password is approaching expiration, then send personalized reminders via Outlook and Slack in the recipient's working hours.

Business problem. Mass-emailing 6 a.m. "your password expires soon" reminders results in service disruptions when employees miss them. Splitting the run by region ensures the alert lands during the employee's workday and dramatically cuts help-desk volume around password resets.

Integrations. Microsoft Entra ID · Microsoft Outlook · Slack · Tables · Python

Playbook Executions (12mo) Trigger
Pass Exp Alert 109 Scheduled (daily)
Pass Exp Alert 2 - Americas 107 Scheduled (daily)
Pass Exp Alert 2 - EMEA 101 Scheduled (daily)
Pass Exp Alert 2 - APAC 107 Scheduled (daily)

4. Identity Lifecycle & Access Review

Description. Joiner-mover-leaver oversight: a daily sweep flags accounts inactive for 35+ days that are still members of the all-employees group, a monthly HR sync pulls last month's new hires from HiBob, and a directory helper resolves an employee's manager on demand.

Business problem. Stale accounts in critical groups expand the attack surface and break the principle of least privilege. Blink keeps inactive-user identification continuous instead of quarterly, and keeps HR & directory views aligned.

Integrations. Microsoft Entra ID · HiBob · Slack · Tables · Python

Playbook Executions (12mo) Trigger
Inactive users- CatoAll group 152 Scheduled (daily)
Hibob New Hired Collection 2 Scheduled (monthly)
Find Employee Manager 0 Subflow

5. Security Alert Triage & Case Management

Description. Inbound security alerts (currently from an Elastic detection pipeline) trigger a Blink flow that enriches source IPs with AbuseIPDB, opens a Blink-native case with severity & vendor metadata, and notifies the case owner by email. Jira-driven incident workflows spin up dedicated Slack incident-response channels for higher-severity cases.

Business problem. Most SIEM detections never reach an analyst with enough context to act on them. Blink standardizes the first-pass triage — IP reputation, structured case creation, ownership routing — so alerts arrive already enriched and assigned.

Integrations. Elastic (webhook) · AbuseIPDB · Blink Case Management · Slack · Jira · Email

Playbook Executions (12mo) Trigger
Elastic Test 192 Webhook
Incident Management- Slack Channel 1 Jira polling
Cato Networks - CMA Analysis 0 On-demand
Risky Users - Scores 0 Scheduled

6. Threat Intel Auto-Triage

Description. External cyber-intel feeds push two categories of alert into Blink: domain-takedown candidates and credential-exposure events. An Azure-hosted LLM extracts the structured indicators (domains, emails) from the free-text alert body, the workflow opens a Jira ticket for action, and Slack notifies the responder.

Business problem. Cyber-intel vendors deliver alerts as unstructured text that an analyst has to parse and tabulate before any takedown or password-reset action can be taken. The LLM extraction step removes that manual parsing entirely, dropping triage time per alert from minutes to seconds.

Integrations. Azure OpenAI · Jira · Slack · Python · HTTP

Playbook Executions (12mo) Trigger
Cyber Intel Alerts- Domain take Down 44 Webhook
Cyber Intel Alerts- Credentials 24 Webhook

7. Threat Hunting & User Investigation

Description. A weekly Microsoft Defender hunt queries DeviceEvents and DeviceFileEvents looking for USB drives that mounted in the past 7 days and then wrote files within minutes of the mount — a classic data-exfiltration / unsanctioned-storage signal. Separately, a Slack slash command lets any analyst paste a @user and immediately get a consolidated profile across Slack, Entra ID, Intune & Kandji.

Business problem. Manual user investigations require swiveling between 4–5 admin consoles. Blink turns it into a one-line Slack command. And periodic EDR hunts ensure storage-device risk doesn't accumulate silently between alert-driven workflows.

Integrations. Microsoft Defender for Endpoint · Microsoft Graph · Microsoft Entra ID · Intune · Kandji · Slack · Python

Playbook Executions (12mo) Trigger
Detect DOK connection 62 Scheduled (weekly)
One-Query User Investigator 124 Slack slash command

8. Workforce Physical Access Verification

Description. Genea (physical access control system) emits an event whenever a covered employee badges into the office. Blink writes the event to a tracking table and, for after-hours entries, sends the badge holder a Slack confirmation prompt — "was this you?" — converting denials into a security review.

Business problem. Badge-cloning and tailgating attacks usually go unnoticed because no one reviews after-hours physical-access events. A direct ask-the-user workflow turns every entry into a self-attesting control with zero analyst overhead.

Integrations. Genea (webhook) · Slack · Tables

Playbook Executions (12mo) Trigger
Genea 667 Webhook

9. Vendor Risk Monitoring

Description. A daily sweep of the procurement platform's vendor records (ZIP) finds vendors whose listed contacts use email addresses across multiple unrelated domains — a structural integrity signal that frequently indicates an impersonation or compromised-vendor risk.

Business problem. Vendor-master records degrade over time as contacts change, get added by ad-hoc users, or get spoofed. Continuous validation of contact-domain consistency surfaces TPRM red flags well before they show up in an invoice-fraud incident.

Integrations. ZIP · Python · HTTP

Playbook Executions (12mo) Trigger
ZIP Vendor Contact checking 93 Scheduled (daily)

10. IT Self-Service & Operations

Description. Employee-facing self-service automations: a web form / Slack chatbot that calculates a laptop's residual price using live FX rates, an Apple Business Manager pull for serial-lookup, and a Slack-driven parking-spot reservation system. Exchange rates are cached weekly to keep the calculator resilient when the FX API is unavailable.

Business problem. Routine IT/HR requests (laptop pricing, parking) sit in a help-desk queue for hours when they could be answered in seconds. Self-service workflows cut ticket volume and improve employee experience.

Integrations. Web Form · Slack · HTTP (Exchange-rate API) · Apple Business Manager · HiBob · Tables · Global Variables

Playbook Executions (12mo) Trigger
Webform - Laptop Price Calculator 8 Web form
Slack /command trigger 10 Slack slash command
Slack - Laptop Price Calculator 0 Subflow
Slack Trigger Parking Automation 5 Slack slash command
Exchange rate 9 Scheduled (weekly)

11. Cloud Security Posture

Description. A point-in-time AWS audit playbook that lists IAM accounts that do not have MFA configured on the root user — published but not yet on a regular schedule.

Business problem. Root-without-MFA is one of the highest-impact misconfigurations on AWS. Automating the check converts it from a periodic-audit finding into a continuous control.

Integrations. AWS

Playbook Executions (12mo) Trigger
Get AWS IAM Accounts Without Root Mfa 0 On-demand

12. Network Infrastructure Monitoring

Description. Listens for site-level alerts from the Juniper Mist wireless platform and posts a structured summary into Slack so the network team can triage from chat.

Business problem. Mist's native alerts are noisy and email-based. Routing them through Blink lets the team filter, format, and consolidate them in Slack — the same channel they use for everything else.

Integrations. Mist (Juniper) · Slack

Playbook Executions (12mo) Trigger
Mist - Site Alerts to Slack 0 Webhook

Key Observations

Strengths

  • Mature self-service awareness program. Phishing-sim + LMS + three internal gamified-awareness apps all feed a single per-employee scorecard surfaced through Slack — this is well beyond what most security programs do for awareness analytics.
  • Region-aware lifecycle workflows. The Pass-Expiration use case is split into Americas / EMEA / APAC variants so alerts land in working hours — a small detail that drives big reductions in help-desk volume.
  • AI-assisted intel parsing. Cyber-intel auto-triage uses Azure OpenAI to extract structured indicators from unstructured alert bodies — turning what is usually 5+ minutes of analyst work into a sub-second extract.
  • First-class IT-ticket enrichment. The Freshservice ticket-enrichment workflow pulls device data from both Kandji (Mac) and Intune (Windows) plus Cato Networks SDP context, and posts a structured note back to the ticket. This is one of the highest-volume workflows in the environment.
  • Strong identity surface coverage. Microsoft Entra ID, HiBob, Slack, Kandji, and Intune are all wired into the same automation fabric — making one-Slack-command user investigations possible across all of them.

Gaps / Opportunities

  • Cloud Security Posture is under-utilized. The single AWS IAM root-MFA check is published but never executed on a schedule. There's runway here to add scheduled CSPM-style sweeps (S3 public buckets, security-group exposure, IAM key age).
  • Vulnerability Management is absent. No workflows tie scanner output (Tenable / Wiz / Qualys-style) to ticket creation or owner notification. A vuln-to-ticket pipeline would be a natural next addition.
  • EDR containment & response is observational only. The USB-mount hunt detects but does not isolate / block. A "compromised host → isolate via Defender / Kandji lock" workflow would close that loop.
  • Several "test" / draft workflows in production. Names like "Elastic Test", "TEST- Self service Portal", "Device Enrichment - Cursor Edition" are running with meaningful execution counts — they should be promoted to production names (no TEST / Cursor Edition suffixes) and the obsolete duplicates retired.
  • Many regional / backup duplicates. There are 6+ Pass Exp Alert variants (backup-with-region, backup-no-region, copy, copy-copy, 16/02). Consolidating to the live four (master + Americas/EMEA/APAC) would reduce drift risk.

Integration ecosystem

The active automations span ~25 distinct integrations: Microsoft Entra ID, Microsoft Graph, Microsoft Defender for Endpoint, Microsoft Intune, Microsoft Outlook, Kandji, Slack, Jira, Freshservice, HiBob, Cato Networks, Genea, Elastic, AbuseIPDB, Azure OpenAI, Skilljar, ZIP, Apple Business Manager, AWS, Mist (Juniper), plus the Blink-native primitives (Tables, Web Form, Case Management, Python, HTTP, Global Variables). The Microsoft stack + Slack form the backbone of most workflows.

E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.