How Coterie Insurance Cut SOC Incident Resolution Time by 50%
See how Coterie Insurance used BlinkOps to cut SOC incident resolution time by about 50% and triage 600 vulnerability alerts weekly without adding headcount.
See how Coterie Insurance used BlinkOps to cut SOC incident resolution time by about 50% and triage 600 vulnerability alerts weekly without adding headcount.

Coterie Insurance used BlinkOps to scale security operations without adding headcount. The team reduced mean time to resolve (MTTR) security operations center (SOC) incidents by approximately 50%.
Workflows and agents now handle recurring tasks across incident response, identity and access management (IAM) offboarding, and vulnerability management.
Company: Coterie Insurance
Industry: Insurance
Location: Appleton, WI
Challenge: Scaling security operations without adding headcount
Key results
Coterie Insurance is a technology-enabled company that helps small businesses find the right insurance coverage. It helps eligible businesses get bindable quotes far faster than traditional carriers. Speed, simplicity, and service guide its work.
Its security team wanted to work with the same speed and simplicity. Instead, manual reviews, handoffs, and investigations across multiple systems took time away from larger projects.
The team covers security operations, security engineering, architecture, and identity and access management.
"We're a lean team and have to focus on many different areas of security."
Brandon Kern, Senior Director of Information Security and Technology Operations, Coterie Insurance
Many processes required the same steps. The team collected data from one source, checked it against another, and validated the results before deciding what to do next. This work took hours and required frequent repetition.
Coterie wanted to save time and maintain the quality of its work.
"When we thought about evolving our security with automation and agents, we wanted to focus on quality and not just the fact that we needed to automate something," Kern said.
Coterie started with in-house tools, including Azure Logic Apps. The team could build automation, but testing workflows was difficult.
"Not being able to test specific steps within a workflow was very difficult," said Sean Lee, Security Engineer at Coterie Insurance.
A step that failed at the end required the team to run the whole workflow again. Each attempt could take two hours to provide one answer.
Coterie set three requirements for a solution:
With BlinkOps, Coterie started building on day one. Workflows and agents took on recurring tasks across incident response, IAM, offboarding, and vulnerability management.
This gave the team more time to focus on the quality of its decisions.
An agent now handles initial triage in the SOC. It collects the required logs, adds historical context, and prepares notes before a person reviews the incident.
Analysts receive a case with this initial work already complete. Mean time to resolve SOC incidents dropped by approximately 50%. The triage agent runs on the BlinkOps AI SOC.
Each week, about 600 vulnerability alerts go through automatic triage, research, and categorization. The process routes each alert to the team responsible for the fix.
Identifying the responsible team used to take hours. Engineering teams now receive a clear action item with these details:
Coterie also used an agent to review conditional access policies against actual authentication activity.
The agent found approximately 12,000 login attempts that would have been blocked under the recommended policy configurations. This review covered work that the team did not have time to do manually.
"The agents are almost like having another person on our team." Sean Lee, Security Engineer, Coterie Insurance
Coterie expanded its security operations without hiring. The team maintained quality and control as it automated more work.
"The biggest benefit I've seen from working with BlinkOps comes down to control with speed," Kern said.
"Insurance is a highly regulated industry, and now, anytime an auditor comes in, we're able to point back to exactly what was done with our automated processes and our agents and have full control over that."
The team gained more time for governance, architecture, and improvements to its security operations program. Daily security work continued.
BlinkOps gave Coterie a place to build lasting solutions as new needs appeared. It also helped improve communication between teams.
"Having a system that automates those communications and allows higher fidelity alerts to come out has increased the trust and the reliability between our teams," Lee said.
"The teams know that we are trying to build out solutions that are ultimately going to make everybody's lives easier."
Coterie can build on its existing workflows and agents to expand the work that security supports.
"The value of BlinkOps is that it elevates the team. BlinkOps allowed us to move with speed and simplicity to ultimately provide better service for our company." Brandon Kern, Senior Director of Information Security and Technology Operations, Coterie Insurance
Coterie built an agent with BlinkOps to handle initial SOC triage. It collects logs, adds historical context, and prepares notes for analysts. Mean time to resolve SOC incidents fell by approximately 50%.
Agents handle recurring triage, routing, and review work across several security domains. The team reports an efficiency gain equivalent to one full-time employee.
Agents triage about 600 vulnerability alerts each week. Each alert is researched, categorized, and routed to the owning team with the repository, CVE, affected package, and recommended update.
Blink is secure, decentralized, and cloud-native. Get modern cloud and security operations today.