How a Global Airline Scaled Automation Across Their Security Program

For most security teams, automation is a folder of brittle scripts that one or two people know how to run. At one of the world's largest airlines, it has become the operating layer for the entire security program.

BlinkOps Team
Published on:
August 18, 2026
 • 
Updated on:
August 18, 2026
Share this post

For most security teams, automation is a folder of brittle scripts that one or two people know how to run. At one of the world's largest airlines, it has become the operating layer for the entire security program — spanning the security operations center, identity and access workflows, aircraft cybersecurity, and security engineering.

With BlinkOps, the team took their security automation from cumbersome scripts to intelligent workflows with transparent agent reasoning built in. At the customer's request, names and identifying details have been changed.

Scaling automation without scripts

Before Blink, the airline had some automation, but it depended on the security automation team to run.

"We had some different scripts that we could run, some different things that we could do," the lead security automation engineer said. "But if people didn't understand how to run the Python and all that, it was mostly on me and a couple of other people to do the work in the background."

That is the quiet tax most security teams pay and never measure: the senior engineer who becomes a human API, fielding one-off requests because of the complex nature of running scripts. Although automation existed, it wasn’t accessible to the broader security organization.

With Blink, the security automation team could not only automate workflows faster, but also could easily create dashboards and apps so that others in the organization could easily run them from a self-service portal.

"Now we can just push those things out to them in a little portal, giving anyone who needs it access," he said. "They can run a multitude of different things without even really knowing what's in the background. They can just ask for something new, and we can start building it for them."

Even with just a handful of security automation engineers, this major airline was able to create agentic workflows that spanned their entire security program

Building specialized agents across SecOps

One of the first workflows built on the platform reviews what analysts submit for firewall blocking: URLs, domains, and IP addresses. It started simple — check the formatting, flag duplicates in the block list. Then the team extended it to do more.

"The agent goes out and performs scoping to see who all is using that domain or IP address. What is the traffic? And so it's giving an assessment," the security automation engineer said.

The payoff showed up the day an analyst tried to clean up what looked like a harmless duplicate entry.

"The agent said, 'I don't recommend you remove this, because there have been all of these systems that have attempted to go to this that have been blocked by it being in there,'" he recalled. It ended up being a duplicate kept as part of a deliberate two-person integrity check — which they were able to see because of the context.

"It's providing an extra assessment, because we have a two-person integrity check," the senior security automation engineer said. "Now it's much more streamlined, because we actually get even more details than we were doing before. We're actually getting scoping that really helps to identify: is this something, or will there be a business impact if we do this?"

In another situation, the Blink agent went a step further, flagging an attempt to delete a table entry it recognized as an active malware block. "I was not expecting that kind of analysis to happen," the senior engineer admitted. The automation had moved from executing instructions to actively surfacing risk before an analyst acted on it.

The power of context

Some of the airline's toughest monitoring problems never touch a traditional endpoint at all. They live on the aircraft.

"Everything on an aircraft is a computer," the security automation engineer said. "All of the logs say they came from 'computer.' They don't have any other unique designations." His team had to write scripts long ago just to stamp a unique identifier onto logs that otherwise all looked identical.

The harder part was the math of detection. Aircraft manufacturers publish thresholds (if you see more than this, if you see that), and the team had to translate those into "hundreds of correlation rules," then wait. "It could be up to 90 days before you get a dump of the data," he said, at which point an analyst faced a giant block of telemetry to sift, often unsure whether two events even came from the same flight or different legs of one.

The team carrying that load is small. "Our aircraft cyber fusion team is made up of two people, three if you count my engineer," the security automation engineer said. "The agents are helping to actually look through and understand what's going on there." For a two-person team facing 90-day data dumps and hundreds of rules, an agent that reads first is not a convenience. It's the difference between responding and not.

A portfolio of purpose-built workflows

The security team at this major airline used Blink to automate security workflows across their organization.

"We have a collection of agents that I call the butlers," he said. "Each one has a different area that they specialize in." One owns user identity, pulling together who someone is, what machine they're on, who their manager is. Another handles network analysis. A new workflow will quarantine assets and take action.

When a new need arises in the business, the security team is easily able to spin up new workflows – a stark contrast to where they began with Python scripts.

With Blink, the team can choose where to use agents and when to rely on deterministic logic.

Their USB-exception process, for example, which is a monstrous end-to-end flow that routes approvals up the chain from manager to director to VP, runs with no agent at all. "There hasn't been a need for an agent in that flow," the security automation engineer said. "It's one of the few places where it's pretty black and white." Not every task needs a frontier model, and his team knows the difference.

The automation infrastructure across the organization

The self-service model didn't stay contained to the SOC. When the security engineering team — who had been generating automation ideas in a separate AI tool with no way to put them into production — saw the platform, they wanted in. "They got very excited, because they're like, 'I want to do basically exactly this,'" the security engineer said. "It is engaging our people. It is challenging our people."

That spread is the clearest sign the program has moved beyond a single team's tooling and become infrastructure for the security organization as a whole: the SOC, identity and access, aircraft cybersecurity, and security engineering are now all building on the same platform.

This story is based on a recorded conversation with a BlinkOps customer in the aviation industry. Details have been anonymized at the customer's request.
No items found.
No items found.