Blink Security Automation — Confidential

Insular-Life-Corporation — Customer Success Report

Generated 2026-08-30 | Insular-Life-Corporation-value-report.md
2026-08-30Report Date
37Total Playbooks
5Unique Workflows (12m)
25,937Actions Automated (12m)
$6,671Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

37
Total playbooks built
all non-deleted workflows
0
Active playbooks
currently enabled
5
Unique workflows executed (12m)
distinct workflows that ran
25,937
Actions automated (12m)
completed action steps
144.1h
Hours saved (12m)
@ 20s per action
$6,671
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 132 security alerts auto-converted to tickets from Alert Logic without analyst touch - 98 identity-based incidents (account lockout + brute force) investigated and responded to - 20 service brute force attacks investigated and responded to - 1 malware incident investigated and responded to

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Automated Alert Ticketing & SOAR
  • 132Security alerts auto-converted to tickets from Alert Logic
0.0%
1
0 active
SOC Incident Investigation — Identity Threats
  • 49Account lockout incidents investigated & responded to
  • 49Account brute force incidents investigated & responded to
  • 20Service brute force incidents investigated & responded to
0.0%
10
0 active
SOC Incident Investigation — Malware
  • 1Malware incidents investigated & responded to
0.0%
3
0 active
Asset Health Escalation0 executions
0.0%
1
0 active
Total0 executions100%
15
0 active

Use Case Growth Over Time

24 unique playbooks  |  4 operational use cases  |  0 total executions (12m)  |  2024-04 to 2025-02
Toggle:
Toggle:

03Integration Ecosystem

SOC Incident Investigation — Identity Threats
Alert Logic AbuseIPDB VirusTotal Email
SOC Incident Investigation — Malware
Alert Logic VirusTotal Hybrid Analysis Email
Automated Alert Ticketing & SOAR
Zendesk Email
Asset Health Escalation
Alert Logic Email

04Key Observations

✓  Strengths

Strengths

  • Active SOC automation is producing real throughput. The Orion SOC Workspace is handling 251 automated actions per year across alert ticketing and incident investigations — a meaningful operational foundation for a managed SOC model.
  • Structured investigation methodology is in place. The three investigation playbook types (malware, brute force, account lockout) represent a complete SOC runbook set covering the most common incident categories in a financial services environment.
  • Alert Logic integration is proven. The Alert Logic ticketing pipeline (132 executions) demonstrates a reliable, event-driven path from detection to case creation. This is the highest-volume automation in the environment and validates the integration architecture.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Significant playbook duplication across workspaces. The same investigation playbooks exist in both the main workspace and the Orion SOC Workspace, with additional "Backup" variants in the Orion SOC Workspace carrying all the actual execution volume. This fragmentation creates maintenance overhead and obscures true utilization. Consolidating to a single canonical set per use case would simplify operations and reduce the risk of running outdated logic.
  • CrowdStrike ticketing pipeline has zero executions. A second PRD - ILC - Ticketing playbook configured for CrowdStrike webhooks exists but has never run. If CrowdStrike is an active detection source, activating this pipeline could meaningfully increase automated alert intake.
  • UAT playbooks carrying production-level traffic. UAT - Account Brute Force - Backup logged 49 executions — the same volume as the production account lockout investigation. UAT workflows in production use creates risk around stability and change management. These should be promoted or retired.
  • Asset health escalation is not yet active. The Alert Logic unhealthy asset escalation workflow remains in UAT with no executions. Given that Alert Logic is already integrated and generating alerts, this is a natural next activation step to extend coverage from reactive incident response into proactive vulnerability management.
  • No cloud or GRC automation present. The current automation portfolio is exclusively SOC-focused. For a financial services institution subject to regulatory requirements (BSP, ISO 27001, etc.), GRC automation — compliance monitoring, access review, RBAC lifecycle — represents a significant untapped opportunity to reduce manual audit and control testing effort.
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 4 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-converted to tickets from Alert Logic 132 PRD - ILC - Ticketing
Account lockout incidents investigated & responded to 49 PRD - Windows Account Lockout Investigation - Backup (Orion SOC Workspace)
Account brute force incidents investigated & responded to 49 UAT - Account Brute Force - Backup (Orion SOC Workspace)
Service brute force incidents investigated & responded to 20 PRD - Service Brute Force Investigation - Backup (Orion SOC Workspace)
Malware incidents investigated & responded to 1 PRD - Malware Generic Investigation - Backup (Orion SOC Workspace)
In the last 12 months, Blink automated: - 132 security alerts auto-converted to tickets from Alert Logic without analyst touch - 98 identity-based incidents (account lockout + brute force) investigated and responded to - 20 service brute force attacks investigated and responded to - 1 malware incident investigated and responded to
Note: The majority of the automation suite (11 of 16 workflows) currently registers zero executions. Several PRD-environment variants appear superseded by active "Backup" variants running in the Orion SOC Workspace, while the CrowdStrike ticketing pipeline and UAT playbooks are deployed but not yet in production volume. Consolidating these parallel variants would simplify operations and make execution data more legible.

Use Case Summary

# Use Case Category Playbook Count Active Playbooks
1 Automated Alert Ticketing & SOAR SOC 2 1
2 SOC Incident Investigation — Identity Threats SOC 9 3
3 SOC Incident Investigation — Malware SOC 3 1
4 Asset Health Escalation Vulnerability Mgmt 1 0
Total 15 5

Use Cases

1. Automated Alert Ticketing & SOAR

Description: Ingests webhook events from external security detection platforms and automatically converts them into structured tickets within the SOC workflow. Enables event-driven, zero-touch alert intake across both Alert Logic and CrowdStrike.

Business problem: SOC analysts at Insular Life Corporation rely on managed detection services (Alert Logic, CrowdStrike) that generate high volumes of security events. Without automation, these events require manual review before they can enter the case management queue, increasing mean time to acknowledge (MTTA) and creating analyst bottlenecks. This use case closes that gap by ingesting alerts at machine speed and creating tickets automatically.

Integrations: Alert Logic, CrowdStrike

Playbook Workspace Executions (12mo) Category Subcategory
PRD - ILC - Ticketing Orion SOC 132 SOC Case mgmt & SOAR, Alert enrichment / IOC lookup
PRD - ILC - Ticketing CrowdStrike WS 0 SOC Case mgmt & SOAR, Alert enrichment / IOC lookup

2. SOC Incident Investigation — Identity Threats

Description: On-demand investigation workflows that guide SOC analysts through structured response procedures for identity-based attack patterns — specifically account brute force attempts and Windows account lockouts. Each workflow provides a repeatable, documented investigation path from initial signal to resolution.

Business problem: Identity attacks (credential stuffing, brute force, account lockouts) are among the most frequent incident types in financial services SOC environments. Manual, ad-hoc investigation is inconsistent and slow. These playbooks enforce a standardized investigation methodology, reduce analyst decision fatigue, and ensure every incident is handled with the same rigor regardless of shift or analyst experience level.

Integrations: Zendesk (ticket-driven intake)

Playbook Workspace Executions (12mo) Category Subcategory
PRD - Windows Account Lockout Investigation - Backup (Orion SOC Workspace) Orion SOC 49 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
UAT - Account Brute Force - Backup (Orion SOC Workspace) Orion SOC 49 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
PRD - Service Brute Force Investigation - Backup (Orion SOC Workspace) Orion SOC 20 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
PRD - Service Brute Force Investigation Main 0 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
PRD - Windows Account Lockout Investigation Main 0 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
PRD - Service Brute Force Investigation (Orion SOC Workspace) Orion SOC 0 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
PRD - Windows Account Lockout Investigation (Orion SOC Workspace) Orion SOC 0 SOC Agentic SOC, Identity threat response, Case mgmt & SOAR
UAT - Account Brute Force (1) Main 0 SOC Agentic SOC, Identity threat response
UAT - Account Brute Force Main 0 SOC Agentic SOC, Identity threat response
UAT - Account Brute Force (Orion SOC Workspace) Orion SOC 0 SOC Agentic SOC, Identity threat response

3. SOC Incident Investigation — Malware

Description: On-demand investigation workflow for generic malware incidents, providing a standardized triage and response procedure for endpoint and file-based malware detections surfaced through the SOC.

Business problem: Malware incidents require rapid, consistent investigation to determine scope, contain the threat, and document findings. A structured playbook prevents investigation steps from being skipped under time pressure and creates an auditable record for each malware event handled by the team.

Integrations: Zendesk (ticket-driven intake)

Playbook Workspace Executions (12mo) Category Subcategory
PRD - Malware Generic Investigation - Backup (Orion SOC Workspace) Orion SOC 1 SOC Agentic SOC, EDR containment & response, Case mgmt & SOAR
PRD - Malware Generic Investigation Main 0 SOC Agentic SOC, EDR containment & response, Case mgmt & SOAR
PRD - Malware Generic Investigation (Orion SOC Workspace) Orion SOC 0 SOC Agentic SOC, EDR containment & response, Case mgmt & SOAR

4. Asset Health Escalation

Description: Escalates unhealthy or exposed assets detected by Alert Logic through Blink Ops, routing remediation assignments to responsible teams with full context on the asset, exposure impact, and recommended resolution.

Business problem: Vulnerability and exposure findings from Alert Logic are only actionable if they reach the right remediation owner quickly and with enough context to act. Without automation, asset health findings can stall in a queue, leaving exposure windows open longer than necessary.

Integrations: Alert Logic

Playbook Workspace Executions (12mo) Category Subcategory
UAT - AL Unhealthy Asset Escalation via Blink Ops Main 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket, Vuln scanning ingest & report

Key Observations

Strengths

  • Active SOC automation is producing real throughput. The Orion SOC Workspace is handling 251 automated actions per year across alert ticketing and incident investigations — a meaningful operational foundation for a managed SOC model.
  • Structured investigation methodology is in place. The three investigation playbook types (malware, brute force, account lockout) represent a complete SOC runbook set covering the most common incident categories in a financial services environment.
  • Alert Logic integration is proven. The Alert Logic ticketing pipeline (132 executions) demonstrates a reliable, event-driven path from detection to case creation. This is the highest-volume automation in the environment and validates the integration architecture.

Gaps & Opportunities

  • Significant playbook duplication across workspaces. The same investigation playbooks exist in both the main workspace and the Orion SOC Workspace, with additional "Backup" variants in the Orion SOC Workspace carrying all the actual execution volume. This fragmentation creates maintenance overhead and obscures true utilization. Consolidating to a single canonical set per use case would simplify operations and reduce the risk of running outdated logic.
  • CrowdStrike ticketing pipeline has zero executions. A second PRD - ILC - Ticketing playbook configured for CrowdStrike webhooks exists but has never run. If CrowdStrike is an active detection source, activating this pipeline could meaningfully increase automated alert intake.
  • UAT playbooks carrying production-level traffic. UAT - Account Brute Force - Backup logged 49 executions — the same volume as the production account lockout investigation. UAT workflows in production use creates risk around stability and change management. These should be promoted or retired.
  • Asset health escalation is not yet active. The Alert Logic unhealthy asset escalation workflow remains in UAT with no executions. Given that Alert Logic is already integrated and generating alerts, this is a natural next activation step to extend coverage from reactive incident response into proactive vulnerability management.
  • No cloud or GRC automation present. The current automation portfolio is exclusively SOC-focused. For a financial services institution subject to regulatory requirements (BSP, ISO 27001, etc.), GRC automation — compliance monitoring, access review, RBAC lifecycle — represents a significant untapped opportunity to reduce manual audit and control testing effort.
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.