Case Study
VodafoneThree

VodafoneThree Automates Cybersecurity with Low-Code Workflows

Telecom Leader Transforms Threat Management Under New Compliance Mandates

VodafoneThree needed to modernise its cybersecurity operations in response to rising alert volumes and the expanded logging and monitoring requirements introduced by the UK’s Telecoms Security Act (TSA). With over 485 billion security events per month, the manual triage process was unsustainable. VodafoneThree partnered with Bounteous and low-code platform provider n8n to build an automation programme that would accelerate detection, reduce compliance risk, and lay the foundation for future AI integrations.

Download Case Study
  • Digital Product & Platform Engineering
  • Enterprise Digital Transformation

Bounteous listened and understood our requirements. They provided flexibility and took ownership from discovery through to solution delivery.

Claire Van Hinsbergh

Head of Cyber Prevent Engineering, VodafoneThree

By The Numbers

  • 95%Reduction in threat detection and response times
  • £5M+In cost savings achieved within ten months
  • 11,500Person-days saved by eliminating manual processes

The Challenge

VodafoneThree's cybersecurity operations centre (CSOC) and engineering teams were under growing pressure. The introduction of TSA expanded the number of assets requiring logging and generated more alerts. Analysts were spending valuable time on manual triage, increasing the risk of delayed detection and regulatory non-compliance.  

Traditional SOAR platforms lacked the flexibility to support a scalable, modular approach across teams. VodafoneThree needed a solution that could automate threat workflows while remaining adaptable to future needs, including AI-driven threat detection.

The Solution

VodafoneThree partnered with Bounteous and n8n to co-create a low-code automation framework. A cross-functional team of specialists worked in agile sprints to design and deploy 33 reusable workflows across key use cases, including:

  • SIEM alert extraction and categorization  
  • Automated notifications to route critical issues in real time  
  • Feed health monitoring and triage  
  • Threat recurrence scoring and impact analysis  

n8n's platform enabled technical and non-technical users to contribute, while Bounteous led infrastructure, workflow optimization, and delivery. The result was a flexible, modular system that could scale across CSOC, engineering, and platform teams—reducing manual effort and increasing resilience.

The Results

With more than 50 SIEM feeds now monitored every five minutes automatically, the program significantly improved visibility and reduced response time. It also achieved full ROI within six months.

The automation framework also sets VodafoneThree up for the future. The team is now exploring integrations with large language models to automate playbook creation, enrich alerts with contextual data, and scale adaptive response strategies across the wider Vodafone Group.

An alert that once took 15 minutes to action now resolves in seconds. Automation has freed our analysts to focus on higher-value work and strengthened our ability to protect critical infrastructure.

Claire Van Hinsbergh

Head of Cyber Prevent Engineering, VodafoneThree