Blink Security Automation — Confidential

Nexus — Customer Success Report

Generated 2026-08-30 | nexus-value-report.md
2026-08-30Report Date
199Total Playbooks
3Unique Workflows (12m)
1,584Actions Automated (12m)
$407Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

199
Total playbooks built
all non-deleted workflows
29
Active playbooks
currently enabled
3
Unique workflows executed (12m)
distinct workflows that ran
1,584
Actions automated (12m)
completed action steps
8.8h
Hours saved (12m)
@ 20s per action
$407
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
3
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 6 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 9,108 CrowdStrike endpoint alerts auto-triaged, IOC-enriched, and routed without analyst involvement - 11,533 Microsoft Defender endpoint alerts processed and conditionally filtered at machine speed - 20,641 total security events handled end-to-end by automation

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
EDR Alert Processing & Automated Triage
  • 11,533Microsoft Defender endpoint alerts processed and filtered automatically
  • 9,108CrowdStrike endpoint alerts auto-triaged & enriched with threat intelligence
100.0%
5
4 active
IOC Lookup & Threat Enrichment0 executions
0.0%
4
4 active
Phishing & Email Security Response1 executions
0.0%
3
3 active
Security Incident Investigation0 executions
0.0%
3
3 active
Endpoint Containment0 executions
0.0%
2
2 active
Network Security Policy Automation0 executions
0.0%
1
0 active
SIEM & Infrastructure Monitoring0 executions
0.0%
2
2 active
DevOps & Utility0 executions
0.0%
2
1 active
Total42,779 executions100%
22
19 active

Use Case Growth Over Time

139 unique playbooks  |  8 operational use cases  |  42,779 total executions (12m)  |  2023-10 to 2026-01
Toggle:
Toggle:

03Integration Ecosystem

EDR Alert Processing & Automated Triage
VMware vSphere CrowdStrike VirusTotal Email Microsoft Defender For Endpoints Zendesk Hybrid Analysis Qualys Tenable
Network Security Policy Automation
Palo Alto Firewall Email
IOC Lookup & Threat Enrichment
VirusTotal Email Hybrid Analysis
Phishing & Email Security Response
Zendesk VirusTotal Hybrid Analysis Email CrowdStrike Trellix Email Security AbuseIPDB
DevOps & Utility
ServiceNow SentinelOne Jenkins Discord Email Zendesk
Security Incident Investigation
Alert Logic Email
SIEM & Infrastructure Monitoring
Alert Logic Zendesk Email
Endpoint Containment
CrowdStrike

04Key Observations

✓  Strengths

Strengths

  • High-volume EDR automation is delivering real value. Two playbooks — CS EDR and Defender For Endpoint — together processed over 20,600 events in 12 months. This is among the clearest proof points of automation ROI in the portfolio: the same analyst workflow executing thousands of times without human intervention.
  • Broad security stack coverage. Nexus has connected or attempted to connect a wide range of enterprise security tools: CrowdStrike, Microsoft Defender, Palo Alto PAN-OS, VirusTotal, Hybrid Analysis, Trellix ETP, Alert Logic, Check Point Harmony, AbuseIPDB, and Zendesk. This integration breadth reflects a mature, multi-vendor security environment and positions Nexus to expand automation across all these platforms.
  • Tiered investigation architecture. The confidence-tier subflows (low / medium / high) indicate architectural intent: Nexus is building a structured, policy-driven triage model rather than ad hoc response scripts. This is a strong foundation for Agentic SOC patterns.
  • Policy-aware containment. The non-containment allowlist check in the Containment playbooks shows operational maturity — Nexus has encoded business context into automated response logic, reducing the risk of disruptive false-positive containment actions.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • 27 of 29 playbooks have zero executions. The active automation footprint is limited to two workflows. Most playbooks appear to be in testing, development, or abandoned states. Activating even a subset of the investigation and enrichment workflows could multiply the automation impact significantly.
  • Duplicate and fragmented workspaces. The Containment playbook exists across two separate workspaces, and multiple CrowdStrike workflows exist in different workspaces with overlapping logic. Consolidating the workspace architecture would reduce maintenance overhead and make it easier to scale active workflows.
  • Investigation workflows are built but not running. Windows Account Lockout, Malware Investigation, and Service Brute Force playbooks are fully scoped — inputs are defined and logic is structured — but show zero executions. These are prime candidates for activation, particularly given the active EDR alert volume these incident types likely generate.
  • Phishing response pipeline is incomplete. Trellix and Alert Logic workflows exist but are inactive. With an active email security connection and a structured Email Investigation subflow already built, completing the trigger-to-response loop would directly support a measurable phishing response KPI.
  • No IAM or GRC automation present. The current portfolio is entirely SOC and infrastructure focused. Common adjacent use cases — employee onboarding/offboarding, access reviews, and vulnerability management ticketing — are not represented and represent natural expansion opportunities.

Integration Ecosystem

Integration Use Cases Status
CrowdStrike EDR triage, alert enrichment Active
Microsoft Defender for Endpoints EDR triage, alert filtering Active
VirusTotal IOC enrichment, URL scanning Configured
Hybrid Analysis IOC enrichment, URL scanning Configured
Palo Alto Networks (PAN-OS) Firewall rule management Inactive
Trellix ETP Email security response Inactive
Alert Logic SIEM monitoring, phishing alerts Inactive
Check Point Harmony Network block enforcement Inactive
Google Workspace / Gmail Email trigger for phishing flows Inactive
Zendesk Incident ticket linkage Inactive
Jenkins CI/CD log forwarding Inactive
Discord DevOps notifications Inactive
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
3
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
acatienza@nexustech.com.ph 2 0 0 N/A
Nexus Orion Workspace 1 0 0 N/A
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 6 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink acatienza@nexustech.com.ph 0 0 0
2 Agent Blink lcaquino@nexustech.com.ph 0 0 0
3 Agent Blink Nexus Orion Workspace 0 0 0
4 Agent Blink nbmolejon@nexustech.com.ph 0 0 0
5 Agent Blink jsgalleno@nexustech.com.ph 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
acatienza@nexustech.com.ph0
lcaquino@nexustech.com.ph0
Nexus Orion Workspace0
nbmolejon@nexustech.com.ph0
jsgalleno@nexustech.com.ph0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 whitelisted URL 00
2 Sub-Tenant Reporting 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 8 use cases | 42,779 executions (12m)

Business KPIs

Metric Count Playbook
CrowdStrike endpoint alerts auto-triaged & enriched with threat intelligence 9,108 CS EDR
Microsoft Defender endpoint alerts processed and filtered automatically 11,533 Defender For Endpoint
Total security events handled without manual intervention 20,641
In the last 12 months, Blink automated: - 9,108 CrowdStrike endpoint alerts auto-triaged, IOC-enriched, and routed without analyst involvement - 11,533 Microsoft Defender endpoint alerts processed and conditionally filtered at machine speed - 20,641 total security events handled end-to-end by automation

Use Case Summary

# Use Case Category Playbooks Active Executions (12mo)
1 EDR Alert Processing & Automated Triage SOC 5 2 20,641
2 IOC Lookup & Threat Enrichment SOC 4 0 0
3 Phishing & Email Security Response SOC 4 0 0
4 Security Incident Investigation SOC 7 0 0
5 Endpoint Containment SOC 2 0 0
6 Network Security Policy Automation Cloud Security 2 0 0
7 SIEM & Infrastructure Monitoring SOC 2 0 0
8 DevOps & Utility Other 3 0 0
Total 29 2 20,641

Use Cases

1. EDR Alert Processing & Automated Triage

Description: Nexus's highest-volume automation area. Blink ingests alerts from CrowdStrike and Microsoft Defender for Endpoint in real time, automatically retrieves detection details and IOC data, enriches findings with external threat intelligence (VirusTotal), and delivers analyst-ready summaries — eliminating manual triage for more than 20,000 events per year.

Business problem solved: SOC analysts were manually pulling detection context from two separate EDR platforms and cross-referencing external threat feeds. Blink closes that loop automatically, reducing mean time to triage and freeing analyst capacity for true escalations.

Integrations: CrowdStrike, Microsoft Defender for Endpoints, VirusTotal, Email (Blink core)

Taxonomy: SOC → EDR containment & response, Alert enrichment / IOC lookup

Playbook Executions (12mo) Workflow ID
CS EDR 9,108 ea7783ed
Defender For Endpoint 11,533 e1e09e33
MS Defender EDR 0 8d251fff
CrowdStrike 0 786030e5
New Automation 0 d8223cd4

2. IOC Lookup & Threat Enrichment

Description: A suite of on-demand playbooks that automate indicator-of-compromise lookups against VirusTotal and Hybrid Analysis. Analysts can submit a URL for scanning, check an existing scan's status, or trigger a combined multi-source lookup that queries both threat intel platforms and delivers a consolidated email report.

Business problem solved: Manual IOC lookups across multiple threat intelligence platforms are slow and inconsistent. These playbooks standardize the enrichment workflow and return structured results to the analyst inbox.

Integrations: VirusTotal, Hybrid Analysis, Email (Blink core)

Taxonomy: SOC → Alert enrichment / IOC lookup, Threat intel ingest & curation

Playbook Executions (12mo) Workflow ID
URL Lookup 0 018f7fba
Scan URL with VirusTotal and Send Results via Email 0 c16e7522
Scan URL with Hybrid Analysis and Send Results via Email 0 801d55c1
Check Scan Status with Hybrid Analysis and Send Results via Email 0 6753e763

3. Phishing & Email Security Response

Description: Automated workflows that monitor for malicious email alerts from Trellix Email Security and Alert Logic. On detection, the playbooks retrieve alert details, identify related delivered emails (including by SMTP sender), loop over affected recipients, and send coordinated response notifications. Includes a dedicated email-investigation subflow used as a reusable component.

Business problem solved: Responding to malicious email campaigns requires correlating alerts across email security platforms, identifying all exposed recipients, and notifying stakeholders — a multi-step process that Blink collapses into a single automated response.

Integrations: Trellix ETP, Alert Logic, Google Workspace / Gmail, Email (Blink core), Check Point Harmony

Taxonomy: SOC → Phishing detection & response, Alert enrichment / IOC lookup

Playbook Executions (12mo) Workflow ID
Trellix Alert Workflow 2 0 536622ae
Trellix Test 0 e5364b7f
On Alert Logic Alert 0 2b82ff02
Subflow — Email Investigation 0 bc461470

4. Security Incident Investigation

Description: A structured set of investigation playbooks covering the most common SOC incident types: account lockouts, malware detections, and service brute-force attacks. Each playbook pulls incident context, sets enrichment variables, and routes response via conditional logic. Three confidence-tier subflows (low / medium / high) implement a tiered triage model — evaluating Tor/VPN/proxy signals and non-containment list membership before escalating or blocking. A block-sequence subflow integrates Check Point Harmony for automated network enforcement.

Business problem solved: Incident investigation workflows are frequently ad hoc, inconsistent, and undocumented. This use case formalizes a repeatable response playbook for the most common incident types, ensuring every analyst follows the same enrichment and decision logic.

Integrations: Check Point Harmony, AbuseIPDB (implied via subflow inputs), Zendesk, Microsoft Active Directory (implied), HTTP/custom APIs

Taxonomy: SOC → Case mgmt & SOAR, EDR containment & response, Alert enrichment / IOC lookup

Playbook Executions (12mo) Workflow ID
Windows Account Lockout Investigation 0 463a5fc6
Malware Generic Investigation 0 cca586ae
Service Brute Force Investigation 0 174e2d22
Subflow — Investigate Low Confidence 0 f9e618fa
Subflow — Investigate Medium Confidence 0 739a5696
Subflow — Investigate High Confidence 0 1a0612ff
Subflow — Block Sequence 0 4933dcd5

5. Endpoint Containment

Description: On-demand containment playbooks that query a non-containment allowlist before isolating a host, ensuring safe and policy-aware endpoint isolation decisions. A duplicate of the workflow exists across two separate workspaces, indicating multi-team rollout or workspace segmentation.

Business problem solved: Uncontrolled endpoint containment can disrupt legitimate business operations. These playbooks enforce a policy check — blocking containment for allowlisted hosts — before taking action, reducing the risk of erroneous isolation.

Integrations: Blink HTTP Tables (non-containment list lookup)

Taxonomy: SOC → EDR containment & response

Playbook Executions (12mo) Workflow ID
Containment 0 f4e02c15
Containment (Nexus Orion Workspace) 0 935ba91d

6. Network Security Policy Automation

Description: On-demand automation for creating security rules on Palo Alto firewalls and delivering results by email. Parameterized with full rule inputs (source, destination, application, service, zone, VSYS), enabling repeatable, auditable firewall policy changes without direct console access.

Business problem solved: Firewall rule creation is error-prone when done manually. These playbooks standardize the request-to-creation process and deliver a confirmation trail to the requesting engineer, improving both accuracy and audit readiness.

Integrations: Palo Alto Networks (PAN-OS), Email (Blink core)

Taxonomy: Cloud Security → Config audit & remediation

Playbook Executions (12mo) Workflow ID
Create Security Rule with Palo Alto Firewall and Send Results via Email 0 1efd2e2a
Create Security Rule with Palo Alto Firewall and Send Results via Email (Personalized) 0 1564e5ef

7. SIEM & Infrastructure Monitoring

Description: Scheduled monitoring of Alert Logic service status, with conditional alerting on state changes. Includes a simulation playbook for testing Alert Logic list-append behavior. Together these represent Nexus's tooling for verifying the health of their SIEM pipeline.

Business problem solved: Undetected SIEM outages create coverage gaps that go unnoticed until an incident. Scheduled Blink monitoring closes that loop with automated health checks and alerts.

Integrations: Alert Logic, HTTP

Taxonomy: SOC → SIEM & log pipeline monitoring

Playbook Executions (12mo) Workflow ID
AlertLogic Status Monitoring 0 7233e02b
Alert Logic Append to List Simulation 0 64280393

8. DevOps & Utility

Description: Supporting workflows not tied to security operations. Includes a Jenkins build log forwarder to Discord for CI/CD visibility, a getting-started Hello World template, and an untitled test automation. These are infrastructure or exploratory in nature.

Business problem solved: Build log visibility in a developer communication channel reduces the friction of tracking CI/CD pipeline status without leaving Slack/Discord.

Integrations: Jenkins, Discord, Email (Blink core)

Taxonomy: Other → DevOps & release automation

Playbook Executions (12mo) Workflow ID
Send Jenkins Build Logs to Discord 0 612f35b5
Getting Started — Hello World 0 28c22706
New Automation 1 0 238256b9

Key Observations

Strengths

  • High-volume EDR automation is delivering real value. Two playbooks — CS EDR and Defender For Endpoint — together processed over 20,600 events in 12 months. This is among the clearest proof points of automation ROI in the portfolio: the same analyst workflow executing thousands of times without human intervention.
  • Broad security stack coverage. Nexus has connected or attempted to connect a wide range of enterprise security tools: CrowdStrike, Microsoft Defender, Palo Alto PAN-OS, VirusTotal, Hybrid Analysis, Trellix ETP, Alert Logic, Check Point Harmony, AbuseIPDB, and Zendesk. This integration breadth reflects a mature, multi-vendor security environment and positions Nexus to expand automation across all these platforms.
  • Tiered investigation architecture. The confidence-tier subflows (low / medium / high) indicate architectural intent: Nexus is building a structured, policy-driven triage model rather than ad hoc response scripts. This is a strong foundation for Agentic SOC patterns.
  • Policy-aware containment. The non-containment allowlist check in the Containment playbooks shows operational maturity — Nexus has encoded business context into automated response logic, reducing the risk of disruptive false-positive containment actions.

Gaps & Opportunities

  • 27 of 29 playbooks have zero executions. The active automation footprint is limited to two workflows. Most playbooks appear to be in testing, development, or abandoned states. Activating even a subset of the investigation and enrichment workflows could multiply the automation impact significantly.
  • Duplicate and fragmented workspaces. The Containment playbook exists across two separate workspaces, and multiple CrowdStrike workflows exist in different workspaces with overlapping logic. Consolidating the workspace architecture would reduce maintenance overhead and make it easier to scale active workflows.
  • Investigation workflows are built but not running. Windows Account Lockout, Malware Investigation, and Service Brute Force playbooks are fully scoped — inputs are defined and logic is structured — but show zero executions. These are prime candidates for activation, particularly given the active EDR alert volume these incident types likely generate.
  • Phishing response pipeline is incomplete. Trellix and Alert Logic workflows exist but are inactive. With an active email security connection and a structured Email Investigation subflow already built, completing the trigger-to-response loop would directly support a measurable phishing response KPI.
  • No IAM or GRC automation present. The current portfolio is entirely SOC and infrastructure focused. Common adjacent use cases — employee onboarding/offboarding, access reviews, and vulnerability management ticketing — are not represented and represent natural expansion opportunities.

Integration Ecosystem

Integration Use Cases Status
CrowdStrike EDR triage, alert enrichment Active
Microsoft Defender for Endpoints EDR triage, alert filtering Active
VirusTotal IOC enrichment, URL scanning Configured
Hybrid Analysis IOC enrichment, URL scanning Configured
Palo Alto Networks (PAN-OS) Firewall rule management Inactive
Trellix ETP Email security response Inactive
Alert Logic SIEM monitoring, phishing alerts Inactive
Check Point Harmony Network block enforcement Inactive
Google Workspace / Gmail Email trigger for phishing flows Inactive
Zendesk Incident ticket linkage Inactive
Jenkins CI/CD log forwarding Inactive
Discord DevOps notifications Inactive
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.