How Coterie Insurance Cut SOC Incident Resolution Time by 50%

See how Coterie Insurance used BlinkOps to cut SOC incident resolution time by about 50% and triage 600 vulnerability alerts weekly without adding headcount.

BlinkOps Team
Published
August 31, 2026
 • 
Updated
September 15, 2026
Share this post

Coterie Insurance used BlinkOps to scale security operations without adding headcount. The team reduced mean time to resolve (MTTR) security operations center (SOC) incidents by approximately 50%.

Workflows and agents now handle recurring tasks across incident response, identity and access management (IAM) offboarding, and vulnerability management.

Company: Coterie Insurance 
Industry:
Insurance
Location: Appleton, WI
Challenge: Scaling security operations without adding headcount

Key results

  • Approximately 50% lower mean time to resolve SOC incidents
  • About 600 vulnerability alerts automatically triaged each week
  • An efficiency gain equivalent to one full-time employee

The Challenge: A small security team with a wide range of responsibilities

Coterie Insurance is a technology-enabled company that helps small businesses find the right insurance coverage. It helps eligible businesses get bindable quotes far faster than traditional carriers. Speed, simplicity, and service guide its work.

Its security team wanted to work with the same speed and simplicity. Instead, manual reviews, handoffs, and investigations across multiple systems took time away from larger projects.

The team covers security operations, security engineering, architecture, and identity and access management.

"We're a lean team and have to focus on many different areas of security."
Brandon Kern, Senior Director of Information Security and Technology Operations, Coterie Insurance

Many processes required the same steps. The team collected data from one source, checked it against another, and validated the results before deciding what to do next. This work took hours and required frequent repetition.

Coterie wanted to save time and maintain the quality of its work.

"When we thought about evolving our security with automation and agents, we wanted to focus on quality and not just the fact that we needed to automate something," Kern said.

Why Coterie chose BlinkOps

The limits of its existing tools

Coterie started with in-house tools, including Azure Logic Apps. The team could build automation, but testing workflows was difficult.

"Not being able to test specific steps within a workflow was very difficult," said Sean Lee, Security Engineer at Coterie Insurance.

A step that failed at the end required the team to run the whole workflow again. Each attempt could take two hours to provide one answer.

What the team needed

Coterie set three requirements for a solution:

  • Integrate with the tools the team already used.
  • Support both deterministic workflows and agents.
  • Let engineers work quickly and keep control of decisions.

Building workflows and agents on day one

With BlinkOps, Coterie started building on day one. Workflows and agents took on recurring tasks across incident response, IAM, offboarding, and vulnerability management.

This gave the team more time to focus on the quality of its decisions.

How Coterie reduced SOC incident resolution time by approximately 50%

An agent now handles initial triage in the SOC. It collects the required logs, adds historical context, and prepares notes before a person reviews the incident.

Analysts receive a case with this initial work already complete. Mean time to resolve SOC incidents dropped by approximately 50%. The triage agent runs on the BlinkOps AI SOC.

How Coterie triages about 600 vulnerability alerts each week

Each week, about 600 vulnerability alerts go through automatic triage, research, and categorization. The process routes each alert to the team responsible for the fix.

Identifying the responsible team used to take hours. Engineering teams now receive a clear action item with these details:

  • The repository
  • The Common Vulnerabilities and Exposures (CVE) identifier
  • The affected package
  • The recommended update

What Coterie found in its conditional access review

Coterie also used an agent to review conditional access policies against actual authentication activity.

The agent found approximately 12,000 login attempts that would have been blocked under the recommended policy configurations. This review covered work that the team did not have time to do manually.

"The agents are almost like having another person on our team." Sean Lee, Security Engineer, Coterie Insurance

Keeping control in a regulated industry

Coterie expanded its security operations without hiring. The team maintained quality and control as it automated more work.

"The biggest benefit I've seen from working with BlinkOps comes down to control with speed," Kern said.
"Insurance is a highly regulated industry, and now, anytime an auditor comes in, we're able to point back to exactly what was done with our automated processes and our agents and have full control over that."

The team gained more time for governance, architecture, and improvements to its security operations program. Daily security work continued.

How BlinkOps helps Coterie expand its security program

BlinkOps gave Coterie a place to build lasting solutions as new needs appeared. It also helped improve communication between teams.

"Having a system that automates those communications and allows higher fidelity alerts to come out has increased the trust and the reliability between our teams," Lee said.
"The teams know that we are trying to build out solutions that are ultimately going to make everybody's lives easier."

Coterie can build on its existing workflows and agents to expand the work that security supports.

"The value of BlinkOps is that it elevates the team. BlinkOps allowed us to move with speed and simplicity to ultimately provide better service for our company." Brandon Kern, Senior Director of Information Security and Technology Operations, Coterie Insurance

Frequently asked questions

How did Coterie reduce SOC incident resolution time?

Coterie built an agent with BlinkOps to handle initial SOC triage. It collects logs, adds historical context, and prepares notes for analysts. Mean time to resolve SOC incidents fell by approximately 50%.

How does Coterie scale security operations without adding headcount?

Agents handle recurring triage, routing, and review work across several security domains. The team reports an efficiency gain equivalent to one full-time employee.

How does Coterie handle vulnerability alerts?

Agents triage about 600 vulnerability alerts each week. Each alert is researched, categorized, and routed to the owning team with the repository, CVE, affected package, and recommended update.

Explore BlinkOps for your security team

See how BlinkOps can help your team automate recurring security work and give analysts more time for other priorities.

Request a demo

No items found.
No items found.