Blink Security Automation — Confidential

Nexus Orion MSSP — Customer Success Report

Generated 2026-08-30 | nexus-orion-mssp-value-report.md
2026-08-30Report Date
33Total Playbooks
3Unique Workflows (12m)
72,581Actions Automated (12m)
$18,668Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

33
Total playbooks built
all non-deleted workflows
8
Active playbooks
currently enabled
3
Unique workflows executed (12m)
distinct workflows that ran
72,581
Actions automated (12m)
completed action steps
403.2h
Hours saved (12m)
@ 20s per action
$18,668
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
1
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 1 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 3,815 client CrowdStrike incidents automatically ticketed without analyst intervention - 42 SOC-level security incidents auto-ticketed from CrowdStrike webhook events - 42 malware EDR detections automatically investigated end-to-end

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Automated Incident Ticketing
  • 3,815Client CrowdStrike incidents automatically ticketed (ILC)
  • 42CrowdStrike security incidents auto-ticketed (SOC)
99.5%
2
2 active
Malware EDR Investigation
  • 42Malware EDR detections auto-investigated
0.5%
5
5 active
Total8,801 executions100%
7
7 active

Use Case Growth Over Time

18 unique playbooks  |  2 operational use cases  |  8,801 total executions (12m)  |  2024-01 to 2025-01
Toggle:
Toggle:

03Integration Ecosystem

Malware EDR Investigation
VirusTotal CrowdStrike Hybrid Analysis Email
Automated Incident Ticketing
CrowdStrike Zendesk Email

04Key Observations

✓  Strengths

Strengths

  • High-volume incident ticketing at scale: The ILC client ticketing automation alone processed 3,815 incidents in 12 months — demonstrating the MSSP's ability to handle enterprise-scale alert volume for managed clients without linear analyst headcount growth.
  • Dual-workspace architecture: Nexus Orion MSSP operates a dedicated production SOC workspace and a separate dev/UAT workspace, indicating a mature deployment practice with proper staging and promotion controls.
  • Integrated malware investigation pipeline: The malware EDR investigation use case spans CrowdStrike, VirusTotal, Hybrid Analysis, and Zendesk in a single automated workflow — covering the full detection-to-verdict-to-ticket lifecycle.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Low utilization of dev-workspace playbooks: Five of eight playbooks have zero executions and all reside in the dev/UAT workspace. The production version of PRD - Malware Generic Investigation EDR in the dev workspace has never run, suggesting it may be a staging copy that was superseded by the Orion SOC workspace version. These should either be promoted or retired to reduce maintenance surface.
  • No active threat intel tooling: VT File Hash Search and CSV Output and HA Hash Search with Output Checks are standalone helper playbooks with zero executions. If these are subflows consumed by the malware investigation workflow, they should be confirmed as such; if they are standalone, activating them for on-demand analyst use could increase threat intel coverage.
  • Single active use case category: All active automation falls within SOC / Case mgmt & SOAR and EDR response. There is no coverage yet for vulnerability management, IAM, or GRC — areas where MSSP clients commonly have automation needs and where Blink can expand the engagement.
  • No phishing or identity threat coverage: Given the MSSP context and CrowdStrike-centric environment, phishing detection and identity threat response workflows (e.g., auto-isolating compromised accounts) are natural next use cases to build out.

Integration Ecosystem

Integration Role Active Workflows
CrowdStrike Webhook event trigger for incident intake 2
VirusTotal File hash threat intel enrichment 0 (defined, not active)
Hybrid Analysis File hash sandbox verdict 0 (defined, not active)
Zendesk Ticket creation and case management 1 (implied via inputs)
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
1
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Orion SOC Workspace 1 0 0 N/A
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 1 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink Orion SOC Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Orion SOC Workspace0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 2 use cases | 8,801 executions (12m)

Business KPIs

Metric Count Playbook
Client CrowdStrike incidents automatically ticketed (ILC) 3,815 PRD - ILC - Ticketing
CrowdStrike security incidents auto-ticketed (SOC) 42 PRD - Ticketing
Malware EDR detections auto-investigated 42 PRD - Malware Generic Investigation EDR (Orion SOC Workspace)
In the last 12 months, Blink automated: - 3,815 client CrowdStrike incidents automatically ticketed without analyst intervention - 42 SOC-level security incidents auto-ticketed from CrowdStrike webhook events - 42 malware EDR detections automatically investigated end-to-end

Use Case Summary

Use Case Category Subcategory Total Playbooks Active Playbooks Executions (12mo)
Automated Incident Ticketing SOC Case mgmt & SOAR 3 2 3,857
Malware EDR Investigation SOC EDR containment & response, Alert enrichment / IOC lookup 5 1 42

Use Cases

1. Automated Incident Ticketing

Description: Listens for CrowdStrike webhook events and automatically creates service tickets for incoming security incidents. Supports both the primary SOC environment and the ILC managed-client environment, enabling the MSSP to scale incident intake across tenants without manual triage overhead.

Business problem solved: MSSP analysts were spending significant time manually logging CrowdStrike detections into the ticketing system. This automation converts every webhook-triggered event into a structured ticket instantly, ensuring nothing is missed and SLA timers start immediately.

Category: SOC

Subcategory: Case mgmt & SOAR

Integrations: CrowdStrike (webhook trigger)

Playbook Workspace Executions (12mo) Status
PRD - Ticketing Orion SOC 42 Active
PRD - ILC - Ticketing Orion SOC 3,815 Active
PRD - ILC - Ticketing Dev/UAT 0 Inactive

2. Malware EDR Investigation

Description: Provides automated malware investigation for CrowdStrike EDR detections. Takes a detection ID and file hash as inputs, runs the hash against VirusTotal and Hybrid Analysis for threat intelligence enrichment, and produces a consolidated investigation summary linked to a Zendesk ticket.

Business problem solved: Malware triage requires analysts to manually pivot across multiple threat intel platforms (VirusTotal, Hybrid Analysis) for every file hash. This use case automates the full investigation chain — from EDR detection to enriched verdict — freeing analysts to focus on response decisions rather than data collection.

Category: SOC

Subcategory: EDR containment & response, Alert enrichment / IOC lookup

Integrations: CrowdStrike (EDR), VirusTotal, Hybrid Analysis, Zendesk

Playbook Workspace Executions (12mo) Status
PRD - Malware Generic Investigation EDR (Orion SOC Workspace) Orion SOC 42 Active
PRD - Malware Generic Investigation EDR Dev/UAT 0 Inactive
UAT - Malware Generic Investigation EDR Dev/UAT 0 UAT
VT File Hash Search and CSV Output Dev/UAT 0 Inactive
HA Hash Search with Output Checks Dev/UAT 0 Inactive

Key Observations

Strengths

  • High-volume incident ticketing at scale: The ILC client ticketing automation alone processed 3,815 incidents in 12 months — demonstrating the MSSP's ability to handle enterprise-scale alert volume for managed clients without linear analyst headcount growth.
  • Dual-workspace architecture: Nexus Orion MSSP operates a dedicated production SOC workspace and a separate dev/UAT workspace, indicating a mature deployment practice with proper staging and promotion controls.
  • Integrated malware investigation pipeline: The malware EDR investigation use case spans CrowdStrike, VirusTotal, Hybrid Analysis, and Zendesk in a single automated workflow — covering the full detection-to-verdict-to-ticket lifecycle.

Gaps & Opportunities

  • Low utilization of dev-workspace playbooks: Five of eight playbooks have zero executions and all reside in the dev/UAT workspace. The production version of PRD - Malware Generic Investigation EDR in the dev workspace has never run, suggesting it may be a staging copy that was superseded by the Orion SOC workspace version. These should either be promoted or retired to reduce maintenance surface.
  • No active threat intel tooling: VT File Hash Search and CSV Output and HA Hash Search with Output Checks are standalone helper playbooks with zero executions. If these are subflows consumed by the malware investigation workflow, they should be confirmed as such; if they are standalone, activating them for on-demand analyst use could increase threat intel coverage.
  • Single active use case category: All active automation falls within SOC / Case mgmt & SOAR and EDR response. There is no coverage yet for vulnerability management, IAM, or GRC — areas where MSSP clients commonly have automation needs and where Blink can expand the engagement.
  • No phishing or identity threat coverage: Given the MSSP context and CrowdStrike-centric environment, phishing detection and identity threat response workflows (e.g., auto-isolating compromised accounts) are natural next use cases to build out.

Integration Ecosystem

Integration Role Active Workflows
CrowdStrike Webhook event trigger for incident intake 2
VirusTotal File hash threat intel enrichment 0 (defined, not active)
Hybrid Analysis File hash sandbox verdict 0 (defined, not active)
Zendesk Ticket creation and case management 1 (implied via inputs)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.