There is a time delay between the threat detection and an adequate response due to need for analysing each alert and event and the adherence to the communication workflow between the departments concerned, which manage different tools. Synapsa receives alert from detection tools and Interconnector takes all necessary steps. It automatically recognises triaged event and mitigates threat or allows for to Security Operation ‘one click’ threat blocking on devices which are not in their administration based on predefined rules. At the end, IT and Security Operation teams receive the report and forensics can be executed.