Warden
Window: last 30 daysScope: CISOData as of 21 Aug 2026 16:40 UTC

Open vs contained

Click a slice to drill into the cases behind it

Open 3Contained 3
SourcesTicketing / SOAR

NIST phase distribution

Where the active caseload sits

SourcesTicketing / SOARSIEM
MTTD
16min
-12 min vs 4 weeks ago
SourcesSIEMTicketing / SOAR
MTTR
63min
-54 min vs 4 weeks ago
SourcesTicketing / SOAR
Alert volume
11,419/week
61 in the live queue
SourcesSIEMEDR / XDR
Automation rate
64%
24% required human approval
SourcesTicketing / SOAR
Benign-closed
16%
Verified, not suppressed
SourcesTicketing / SOARCloud

Detection & response trend

Twelve weeks, derived from case timestamps

SourcesTicketing / SOARSIEM

ATT&CK coverage summary

70% average technique coverage · 7 techniques below 60%

SourcesSIEMEDR / XDRFirewall / NDRCloud

Outcomes

What the governed agent changed

Faster detection

MTTD down from 45 to 16 minutes

Analyst productivity

64% of low/medium work automated

Consistent response

3 destructive actions held at the gate right now

Risk reduction

Residual risk 58 → 30

Audit trail

Everything the agent saw, decided and executed

Declined containment recommendation48m ago

Decision Gate · INC-2046 · Insufficient evidence confidence (0.66) — monitoring raised instead

SourcesEDR / XDRFirewall / NDRIAM
Executed allowlisted non-destructive actions2h ago

Response Agent · INC-2041 · Enrichment, log collection, ticket created

SourcesThreat IntelEDR / XDRTicketing / SOAR
Withheld destructive action pending approval2h ago

Decision Gate · INC-2041 / ACT-ISOLATE · Approval requested from Authorized Approver

SourcesTicketing / SOAR
Computed deterministic risk score2h ago

Risk Assessment Agent · INC-2041 · Score 81 → Critical

SourcesCMDBVuln MgmtThreat IntelEDR / XDR
Mapped observed behaviour to ATT&CK2h ago

ATT&CK Mapping Agent · INC-2041 · T1566.002, T1078.002, T1059.001, T1003.001

SourcesEDR / XDRIAMEmail
Correlated 4 alerts into incident2h ago

Evidence Correlation Agent · INC-2041 · Incident created, severity Critical

SourcesEDR / XDRIAMEmailThreat Intel
Approved perimeter block1d ago

CISO / SOC Manager · INC-2042 / ACT-BLOCK-IP · Approved — 24h TTL deny rule

SourcesFirewall / NDRThreat Intel
Refused out-of-allowlist action2d ago

Response Agent · INC-2044 / wipe-and-reimage · Refused: action not on the response allowlist

SourcesTicketing / SOAR
Approved endpoint isolation2d ago

On-call Approver · INC-2044 / ACT-ISOLATE · Approved — executed via scoped EDR API

SourcesEDR / XDRSIEMIAMThreat Intel
Closed case as verified benign3d ago

Reporting Agent · INC-2045 · Closed-Benign with rationale retained

SourcesCloudIAMTicketing / SOAR