
FICO Cuts MTTR by 99.4% and Beats Automation Target With Torq



Case Study Contents
Get a Personalized Demo
See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster.
![]()
A SOAR That Wasn’t Actually Automating Anything
FICO’s SOC ran on a legacy SOAR platform, but the platform’s role had become largely cosmetic. Playbooks existed, but 90-95% of the work inside them was still being done by hand. The SOAR was a system of record for manual work, not a system that reduced it.
Three structural issues compounded the problem. The first was an integration ceiling — each use case was tied to a single integration or a small handful of them, with no way to engage multiple tools through a single workflow. The second was support cadence. Vendor touch-points came monthly at best, and tickets weren’t always tracked proactively. The third was maintenance load. Workflows had grown to dozens of steps each, many of them legacy or redundant, and the cost of keeping them up to date had become a drag on the detection engineering team.
By late 2024, the question wasn’t whether the SOAR was working. It was whether the SOC could keep scaling with it.
Torq is NOT a SOAR. Torq is an AI SOC platform that uses agentic AI and automation to expose the weaknesses of legacy SOAR and render it obsolete.
![]()
The Torq AI SOC Platform for Integration Depth and Automation Reach
When FICO evaluated alternatives, three criteria mattered most: integration breadth, automation depth, and support partnership. The Torq AI SOC Platform met all three.
Integration depth came first. Torq’s full-stack of integrations enabled FICO to engage multiple tools through a single agentic workflow. Where an integration didn’t already exist, the team could easily build one. The ceiling from legacy SOAR’s limitations was gone.
Second came automation reach. Torq could fully automate the manual steps in XSOAR — extracting phishing headers, enriching alerts with VirusTotal, sending notification emails, opening and closing cases — without an analyst in the middle.
Third was the support model. Torq committed to weekly support touchpoints and proactive ticket tracking — a sharp contrast to the monthly cadence FICO had been working with in XSOAR. The difference compounded across the migration and the operational rollout that followed. During the migration itself, Torq support helped the team consolidate playbooks, collapsing 10-step workflows into single-step automations that produced the same output. Once FICO was operational on Torq, the weekly cadence kept delivering: feature requests, like bulk case closure, were shipped as the SOC requested.
“Torq has a full stack of integrations, and if an integration isn’t there, we can build it from scratch. There’s no stopping point on integrations.”
Ernesto Ugalde, Senior Manager, Detection Engineering, FICO
![]()
A 45-Day Migration, 100+ Playbooks Moved
The migration was scoped at 90 days and delivered in half the expected time. The team approached it in two passes. First, they assessed compatibility — which XSOAR workflows could move to Torq as-is, and which needed rework. Second, they used the migration as a chance to consolidate. Playbooks that had grown to 10 steps on the legacy platform were redesigned in Torq to do the same work in a single step.
The integration side moved faster than expected. More than half of the API keys in use in XSOAR were directly compatible with Torq. The team brought in some new keys but didn’t have to rebuild the integration layer from scratch.
Integration priorities were sequenced by alert volume. EDR, firewalls, and phishing came first — the three highest-frequency alert sources on the legacy platform. Lower-volume tooling came in after.
“Management wanted to convert as soon as possible,” said Veeresh Kencharaddi, Senior Cybersecurity Manager at FICO. “The Torq team really helped us in converting all the workflows. It was challenging, but we got there.”
![]()
How FICO’s SOC Operates Today
FICO’s SOC runs on the Torq AI SOC Platform end-to-end — from automated phishing investigation and response follow-up to 24/7 monitoring across teams worldwide and compliance evidence packaging for every workflow.
Phishing auto triage at 95% automation:
Before Torq, phishing investigation meant pulling the .eml file, sending it to a header-extraction tool, running manual reputation lookups, and deciding whether to escalate. Now Torq grabs the alert, extracts headers, runs analysis through VirusTotal, and automatically hands the SOC analyst a complete evidence package — flags, errors, and a verdict. Average response time dropped from roughly three days to under 30 minutes.
Phishing click follow-up: 30 hours → Sub 30 minutes:
When FICO runs an internal phishing test, more than 100 employees typically click. Recording each click, sending the training assignment, and tracking completion used to take 30 hours of analyst time per campaign. Torq runs the entire follow-up in less than 30 minutes — the same way every time, across every clicker, with a full audit trail.
A 24/7 global SOC operating together:
Ernesto Ugalde’s detection engineering team builds and maintains workflows from North America. The SOC team — analysts split across North America and Asia — runs continuous monitoring against those workflows. When the SOC identifies a gap, detection engineering closes it.
Compliance built in:
Torq produces an auditable record of who did what, when, and why. Across PCI DSS and country-specific audit cycles since the migration, FICO hasn’t encountered a single instance in which Torq didn’t have the documentation an auditor requested.
“When the SOC team identifies a gap — ‘this step is taking too much time’ — we work to enhance it by adding automation or removing steps that aren’t being used. It’s a collaborative effort, and that’s why the numbers look the way they do.”
Ernesto Ugalde, Senior Manager, Detection Engineering, FICO
![]()
A 99.4% Drop in MTTR and Target Beaten by 15 Points
In nine months on the Torq AI SOC Platform, FICO’s SOC went from an MTTR of more than 150 hours to under an hour, exceeded its automation target by 15%, and started handling nearly 13,000 cases a month as routine — with the CISO showcasing the results to the entire company at an internal all-hands.
MTTR dropped 99.4%:
The team reduced MTTR from over 150 hours in January to under 55 minutes in September, with the steepest drop coming in the first 90 days as workflows came online and manual handoffs were replaced.
75% of cases closed by automation
This exceeded its FY25 goal by 15 percentage points, a huge accomplishment.
13K cases a month, handled as “business as usual”:
By September, the volume that would have overwhelmed the legacy SOAR had become routine, with 75% of cases closing by automation, and analyst time concentrated on cases that required human judgment.
Phishing: 3 days to under 30 minutes:
Phishing workflow automation went from 60% to 95%, and the click follow-up process for 100-plus employees per phishing test campaign dropped from roughly three days of manual work to under 30 minutes automated — 100% time savings per campaign.
52% growth in Case Operators on Torq:
The number of Case Operations grew across the year as more of the SOC moved its day-to-day work onto the platform. The workflow count actually went down as the team consolidated — a signal of operational maturity.
Compliance audits without a single evidence gap:
Across PCI DSS and country-specific audit cycles since the move, FICO hasn’t encountered a situation where Torq didn’t have sufficient documentation to support an audit request.
“When another security leader asks me whether the move from XSOAR was worth it, I tell them three things. We have the integrations we need — and when we don’t, we build them. We can run our own AI models inside our own workflows. And the support. The Torq team is in our standup every single week. That’s what made the difference for our SOC.”
Ernesto Ugalde, Senior Manager, Detection Engineering, FICO
FICO is a leading analytics software company, helping businesses in 80+ countries make better decisions that drive higher levels of growth, profitability, and customer satisfaction.

