Response actions are run by hand across tools, so containment is slow and playbook success is never measured. When automation does run, failures go unexplained.
"How much of our response is actually automated, and when a playbook fails, do we know why?"
Time to contain
Automation coverage
To first outcomes