Blink Security Automation — Confidential

Amount — Customer Success Report

Generated 2026-09-10 | amount-value-report.md
2026-09-10Report Date
13Total Playbooks
2Unique Workflows (12m)
285Actions Automated (12m)
$73Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

13
Total playbooks built
all non-deleted workflows
4
Active playbooks
currently enabled
2
Unique workflows executed (12m)
distinct workflows that ran
285
Actions automated (12m)
completed action steps
1.6h
Hours saved (12m)
@ 20s per action
$73
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - No automations have completed execution yet — all workflows are in early deployment or pilot stage. The environment has functional automation logic in place but has not yet been operationalized.

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Phishing Detection & Response0 executions
0.0%
2
2 active
Threat Intel Ingest & IOC Lookup0 executions
0.0%
2
1 active
Vulnerability Lifecycle Management0 executions
0.0%
1
0 active
Total0 executions100%
5
3 active

Use Case Growth Over Time

7 unique playbooks  |  3 operational use cases  |  0 total executions (12m)  |  2025-02 to 2025-08
Toggle:
Toggle:

03Integration Ecosystem

Threat Intel Ingest & IOC Lookup
Coralogix
Phishing Detection & Response
Google Workspace Gmail Google Drive String Utilities Coralogix
Vulnerability Lifecycle Management
Rapid7 Jira

04Key Observations

✓  Strengths

Strengths

  • FS-ISAC TAXII integration is a differentiated capability. Most security teams rely on generic threat intel sources (VirusTotal, Shodan, etc.). A direct TAXII integration with FS-ISAC is specific to the financial services sector and positions the SOC to act on threats before they are broadly published.
  • Phishing workflow is architecturally complete. The Main flow covers the full response chain: trigger → email retrieval → IOC/attachment extraction → TAXII enrichment → evidence storage → SIEM logging. The logic is ready to operationalize — it has not yet been exercised, not redesigned.
  • Coralogix plays a dual role. It serves as both the TAXII gateway and the SIEM logging target, which keeps the integration surface area small and avoids context-switching between platforms during incident response.
  • Vulnerability → Jira ticketing is scoped correctly. The prototype filters by severity before creating tickets, avoiding alert noise and ensuring Jira receives actionable, prioritized work items.

###

△  Gaps & Growth Opportunities

Gaps

  • No automations have executed. All workflows are in pre-operational state. The primary gap is activation and go-live, not design quality. Identifying the blocker to first execution is the critical next step.
  • Phishing flow has no analyst routing. Enrichment results are logged to Coralogix but not surfaced in a case management system or sent to analysts via Slack/email/ticketing. Without a notification or escalation path, findings are silently accumulated in the SIEM.
  • Vulnerability Management and TAXII ingestion are inactive prototypes. Rapid7 and Jira connections are not yet established in the prototype workspace, and the scheduled TAXII ingestion job (New Workflow) has never run.
  • No coverage in Cloud Security, IAM, or GRC. The current automation footprint is limited to SOC and early-stage Vulnerability Management. Access reviews, cloud configuration monitoring, and compliance workflows are not yet in scope.

Integration Ecosystem

Integration Used In Status
Google Workspace (Gmail) Phishing Detection Active
Google Drive Phishing Detection Active
Coralogix Phishing Detection · Threat Intel Active
Rapid7 InsightVM Vulnerability Mgmt Prototype (not connected)
Jira Vulnerability Mgmt Prototype (not connected)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 3 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
— — No executions recorded in the last 12 months
In the last 12 months, Blink automated: - No automations have completed execution yet — all workflows are in early deployment or pilot stage. The environment has functional automation logic in place but has not yet been operationalized.

Use Case Summary

Use Case Category Subcategory Playbooks Status
Phishing Detection & Response SOC Phishing detection & response 2 Active — not yet triggered
Threat Intel Ingest & IOC Lookup SOC Threat intel ingest & curation · Alert enrichment / IOC lookup 2 1 active, 1 prototype
Vulnerability Lifecycle Management Vulnerability Mgmt Vuln lifecycle prioritize & ticket 1 Prototype

Total operational playbooks: 4 active · 2 prototype · 5 onboarding templates (excluded from analysis)

Use Cases

1. Phishing Detection & Response

Description: End-to-end automation for user-reported phishing emails surfaced via Gmail. When a phishing alert fires, the workflow retrieves the email, parses it for IOCs and attachments, enriches each indicator against the FS-ISAC TAXII threat intelligence database, stores artifacts in Google Drive, and logs all findings to Coralogix for retention and correlation.

Business problem: Manual phishing triage is time-consuming and inconsistent. This automation standardizes the response, reduces analyst toil, and creates a complete evidence trail for every reported email — at machine speed.

Integrations: Google Workspace (Gmail), Google Drive, Coralogix

Playbook Category Subcategory Type Executions (12 mo) Status
Main SOC Phishing detection & response Event-triggered 0 Active
Retrieve Gmail Message Based on Message ID in rfc822msgid Format SOC Phishing detection & response Utility subflow 0 Active

2. Threat Intel Ingest & IOC Lookup

Description: Operationalizes FS-ISAC financial-sector threat intelligence through two complementary workflows. An on-demand lookup checks any indicator — MD5/SHA256 hash, IP address, domain, URL, or email address — against the FS-ISAC TAXII database and returns a malicious/clean verdict. A companion prototype ingests all TAXII 2 feeds on a daily schedule and indexes the raw data into Coralogix for persistent search and correlation.

Business problem: Financial institutions face threats tracked specifically by FS-ISAC. By integrating TAXII feeds directly into the SOC workflow, analysts can enrich indicators in real time without switching to a separate portal — and historical feed data accumulates in the SIEM automatically.

Integrations: Coralogix (TAXII gateway + SIEM)

Playbook Category Subcategory Type Executions (12 mo) Status
Search IOC in FS-ISAC TAXI SOC Alert enrichment / IOC lookup · Threat intel ingest & curation On-demand 0 Active
New Workflow SOC Threat intel ingest & curation Scheduled (daily, 12:00 UTC) 0 Prototype

3. Vulnerability Lifecycle Management

Description: Prototype workflow that retrieves vulnerability data from Rapid7 InsightVM, filters findings by analyst-selected severity (Critical, Severe, or Moderate), and automatically creates a Jira ticket for each matching vulnerability, pre-populated with CVE identifiers, CVSS v3 score, risk score, description, and labels.

Business problem: The handoff from vulnerability scanner to remediation ticketing is a manual bottleneck. This automation ensures every high-priority finding is tracked in Jira without analyst intervention, reducing time-to-ticket and preventing findings from being dropped.

Integrations: Rapid7 InsightVM, Jira

Playbook Category Subcategory Type Executions (12 mo) Status
New Workflow 1 Vulnerability Mgmt Vuln lifecycle prioritize & ticket On-demand 0 Prototype

Key Observations

Strengths

  • FS-ISAC TAXII integration is a differentiated capability. Most security teams rely on generic threat intel sources (VirusTotal, Shodan, etc.). A direct TAXII integration with FS-ISAC is specific to the financial services sector and positions the SOC to act on threats before they are broadly published.
  • Phishing workflow is architecturally complete. The Main flow covers the full response chain: trigger → email retrieval → IOC/attachment extraction → TAXII enrichment → evidence storage → SIEM logging. The logic is ready to operationalize — it has not yet been exercised, not redesigned.
  • Coralogix plays a dual role. It serves as both the TAXII gateway and the SIEM logging target, which keeps the integration surface area small and avoids context-switching between platforms during incident response.
  • Vulnerability → Jira ticketing is scoped correctly. The prototype filters by severity before creating tickets, avoiding alert noise and ensuring Jira receives actionable, prioritized work items.

Gaps

  • No automations have executed. All workflows are in pre-operational state. The primary gap is activation and go-live, not design quality. Identifying the blocker to first execution is the critical next step.
  • Phishing flow has no analyst routing. Enrichment results are logged to Coralogix but not surfaced in a case management system or sent to analysts via Slack/email/ticketing. Without a notification or escalation path, findings are silently accumulated in the SIEM.
  • Vulnerability Management and TAXII ingestion are inactive prototypes. Rapid7 and Jira connections are not yet established in the prototype workspace, and the scheduled TAXII ingestion job (New Workflow) has never run.
  • No coverage in Cloud Security, IAM, or GRC. The current automation footprint is limited to SOC and early-stage Vulnerability Management. Access reviews, cloud configuration monitoring, and compliance workflows are not yet in scope.

Integration Ecosystem

Integration Used In Status
Google Workspace (Gmail) Phishing Detection Active
Google Drive Phishing Detection Active
Coralogix Phishing Detection · Threat Intel Active
Rapid7 InsightVM Vulnerability Mgmt Prototype (not connected)
Jira Vulnerability Mgmt Prototype (not connected)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.