01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Automated Alert Ticketing & SOAR |
| 0.0% | 1 0 active |
| SOC Incident Investigation — Identity Threats |
| 0.0% | 10 0 active |
| SOC Incident Investigation — Malware |
| 0.0% | 3 0 active |
| Asset Health Escalation | 0 executions | 0.0% | 1 0 active |
| Total | 0 executions | 100% | 15 0 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Active SOC automation is producing real throughput. The Orion SOC Workspace is handling 251 automated actions per year across alert ticketing and incident investigations — a meaningful operational foundation for a managed SOC model.
- Structured investigation methodology is in place. The three investigation playbook types (malware, brute force, account lockout) represent a complete SOC runbook set covering the most common incident categories in a financial services environment.
- Alert Logic integration is proven. The Alert Logic ticketing pipeline (132 executions) demonstrates a reliable, event-driven path from detection to case creation. This is the highest-volume automation in the environment and validates the integration architecture.
###
Gaps & Opportunities
- Significant playbook duplication across workspaces. The same investigation playbooks exist in both the main workspace and the Orion SOC Workspace, with additional "Backup" variants in the Orion SOC Workspace carrying all the actual execution volume. This fragmentation creates maintenance overhead and obscures true utilization. Consolidating to a single canonical set per use case would simplify operations and reduce the risk of running outdated logic.
- CrowdStrike ticketing pipeline has zero executions. A second
PRD - ILC - Ticketingplaybook configured for CrowdStrike webhooks exists but has never run. If CrowdStrike is an active detection source, activating this pipeline could meaningfully increase automated alert intake. - UAT playbooks carrying production-level traffic.
UAT - Account Brute Force - Backuplogged 49 executions — the same volume as the production account lockout investigation. UAT workflows in production use creates risk around stability and change management. These should be promoted or retired. - Asset health escalation is not yet active. The Alert Logic unhealthy asset escalation workflow remains in UAT with no executions. Given that Alert Logic is already integrated and generating alerts, this is a natural next activation step to extend coverage from reactive incident response into proactive vulnerability management.
- No cloud or GRC automation present. The current automation portfolio is exclusively SOC-focused. For a financial services institution subject to regulatory requirements (BSP, ISO 27001, etc.), GRC automation — compliance monitoring, access review, RBAC lifecycle — represents a significant untapped opportunity to reduce manual audit and control testing effort.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 4 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-converted to tickets from Alert Logic | 132 | PRD - ILC - Ticketing |
| Account lockout incidents investigated & responded to | 49 | PRD - Windows Account Lockout Investigation - Backup (Orion SOC Workspace) |
| Account brute force incidents investigated & responded to | 49 | UAT - Account Brute Force - Backup (Orion SOC Workspace) |
| Service brute force incidents investigated & responded to | 20 | PRD - Service Brute Force Investigation - Backup (Orion SOC Workspace) |
| Malware incidents investigated & responded to | 1 | PRD - Malware Generic Investigation - Backup (Orion SOC Workspace) |
Use Case Summary
| # | Use Case | Category | Playbook Count | Active Playbooks |
|---|---|---|---|---|
| 1 | Automated Alert Ticketing & SOAR | SOC | 2 | 1 |
| 2 | SOC Incident Investigation — Identity Threats | SOC | 9 | 3 |
| 3 | SOC Incident Investigation — Malware | SOC | 3 | 1 |
| 4 | Asset Health Escalation | Vulnerability Mgmt | 1 | 0 |
| Total | 15 | 5 |
Use Cases
1. Automated Alert Ticketing & SOAR
Description: Ingests webhook events from external security detection platforms and automatically converts them into structured tickets within the SOC workflow. Enables event-driven, zero-touch alert intake across both Alert Logic and CrowdStrike.
Business problem: SOC analysts at Insular Life Corporation rely on managed detection services (Alert Logic, CrowdStrike) that generate high volumes of security events. Without automation, these events require manual review before they can enter the case management queue, increasing mean time to acknowledge (MTTA) and creating analyst bottlenecks. This use case closes that gap by ingesting alerts at machine speed and creating tickets automatically.
Integrations: Alert Logic, CrowdStrike
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| PRD - ILC - Ticketing | Orion SOC | 132 | SOC | Case mgmt & SOAR, Alert enrichment / IOC lookup |
| PRD - ILC - Ticketing | CrowdStrike WS | 0 | SOC | Case mgmt & SOAR, Alert enrichment / IOC lookup |
2. SOC Incident Investigation — Identity Threats
Description: On-demand investigation workflows that guide SOC analysts through structured response procedures for identity-based attack patterns — specifically account brute force attempts and Windows account lockouts. Each workflow provides a repeatable, documented investigation path from initial signal to resolution.
Business problem: Identity attacks (credential stuffing, brute force, account lockouts) are among the most frequent incident types in financial services SOC environments. Manual, ad-hoc investigation is inconsistent and slow. These playbooks enforce a standardized investigation methodology, reduce analyst decision fatigue, and ensure every incident is handled with the same rigor regardless of shift or analyst experience level.
Integrations: Zendesk (ticket-driven intake)
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| PRD - Windows Account Lockout Investigation - Backup (Orion SOC Workspace) | Orion SOC | 49 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| UAT - Account Brute Force - Backup (Orion SOC Workspace) | Orion SOC | 49 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| PRD - Service Brute Force Investigation - Backup (Orion SOC Workspace) | Orion SOC | 20 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| PRD - Service Brute Force Investigation | Main | 0 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| PRD - Windows Account Lockout Investigation | Main | 0 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| PRD - Service Brute Force Investigation (Orion SOC Workspace) | Orion SOC | 0 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| PRD - Windows Account Lockout Investigation (Orion SOC Workspace) | Orion SOC | 0 | SOC | Agentic SOC, Identity threat response, Case mgmt & SOAR |
| UAT - Account Brute Force (1) | Main | 0 | SOC | Agentic SOC, Identity threat response |
| UAT - Account Brute Force | Main | 0 | SOC | Agentic SOC, Identity threat response |
| UAT - Account Brute Force (Orion SOC Workspace) | Orion SOC | 0 | SOC | Agentic SOC, Identity threat response |
3. SOC Incident Investigation — Malware
Description: On-demand investigation workflow for generic malware incidents, providing a standardized triage and response procedure for endpoint and file-based malware detections surfaced through the SOC.
Business problem: Malware incidents require rapid, consistent investigation to determine scope, contain the threat, and document findings. A structured playbook prevents investigation steps from being skipped under time pressure and creates an auditable record for each malware event handled by the team.
Integrations: Zendesk (ticket-driven intake)
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| PRD - Malware Generic Investigation - Backup (Orion SOC Workspace) | Orion SOC | 1 | SOC | Agentic SOC, EDR containment & response, Case mgmt & SOAR |
| PRD - Malware Generic Investigation | Main | 0 | SOC | Agentic SOC, EDR containment & response, Case mgmt & SOAR |
| PRD - Malware Generic Investigation (Orion SOC Workspace) | Orion SOC | 0 | SOC | Agentic SOC, EDR containment & response, Case mgmt & SOAR |
4. Asset Health Escalation
Description: Escalates unhealthy or exposed assets detected by Alert Logic through Blink Ops, routing remediation assignments to responsible teams with full context on the asset, exposure impact, and recommended resolution.
Business problem: Vulnerability and exposure findings from Alert Logic are only actionable if they reach the right remediation owner quickly and with enough context to act. Without automation, asset health findings can stall in a queue, leaving exposure windows open longer than necessary.
Integrations: Alert Logic
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| UAT - AL Unhealthy Asset Escalation via Blink Ops | Main | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket, Vuln scanning ingest & report |
Key Observations
Strengths
- Active SOC automation is producing real throughput. The Orion SOC Workspace is handling 251 automated actions per year across alert ticketing and incident investigations — a meaningful operational foundation for a managed SOC model.
- Structured investigation methodology is in place. The three investigation playbook types (malware, brute force, account lockout) represent a complete SOC runbook set covering the most common incident categories in a financial services environment.
- Alert Logic integration is proven. The Alert Logic ticketing pipeline (132 executions) demonstrates a reliable, event-driven path from detection to case creation. This is the highest-volume automation in the environment and validates the integration architecture.
Gaps & Opportunities
- Significant playbook duplication across workspaces. The same investigation playbooks exist in both the main workspace and the Orion SOC Workspace, with additional "Backup" variants in the Orion SOC Workspace carrying all the actual execution volume. This fragmentation creates maintenance overhead and obscures true utilization. Consolidating to a single canonical set per use case would simplify operations and reduce the risk of running outdated logic.
- CrowdStrike ticketing pipeline has zero executions. A second
PRD - ILC - Ticketingplaybook configured for CrowdStrike webhooks exists but has never run. If CrowdStrike is an active detection source, activating this pipeline could meaningfully increase automated alert intake. - UAT playbooks carrying production-level traffic.
UAT - Account Brute Force - Backuplogged 49 executions — the same volume as the production account lockout investigation. UAT workflows in production use creates risk around stability and change management. These should be promoted or retired. - Asset health escalation is not yet active. The Alert Logic unhealthy asset escalation workflow remains in UAT with no executions. Given that Alert Logic is already integrated and generating alerts, this is a natural next activation step to extend coverage from reactive incident response into proactive vulnerability management.
- No cloud or GRC automation present. The current automation portfolio is exclusively SOC-focused. For a financial services institution subject to regulatory requirements (BSP, ISO 27001, etc.), GRC automation — compliance monitoring, access review, RBAC lifecycle — represents a significant untapped opportunity to reduce manual audit and control testing effort.
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.