capacitybuilders.substack.com/p/capacity-modeling-enhancing-analyst/comment/43688715

Preview meta tags from the capacitybuilders.substack.com website.

Linked Hostnames

2

Thumbnail

Search Engine Appearance

Google

https://capacitybuilders.substack.com/p/capacity-modeling-enhancing-analyst/comment/43688715

Travis Romero on Capacity Builders

Thank you for the article! Agree with you that you have to start having this conversation at some point, especially when you reach the point of making decisions on what % of MITRE ATT&CK ttps you are going to translate to alerts. It's super easy to default to 100% coverage mode and want to alert on everything, but capacity models like this can really highlight how effective your team will be mapped to the budget allocated to SOC staffing. It's a simple message to leadership - if you want fast response time SLA's to all threats, here's how many people you will need.



Bing

Travis Romero on Capacity Builders

https://capacitybuilders.substack.com/p/capacity-modeling-enhancing-analyst/comment/43688715

Thank you for the article! Agree with you that you have to start having this conversation at some point, especially when you reach the point of making decisions on what % of MITRE ATT&CK ttps you are going to translate to alerts. It's super easy to default to 100% coverage mode and want to alert on everything, but capacity models like this can really highlight how effective your team will be mapped to the budget allocated to SOC staffing. It's a simple message to leadership - if you want fast response time SLA's to all threats, here's how many people you will need.



DuckDuckGo

https://capacitybuilders.substack.com/p/capacity-modeling-enhancing-analyst/comment/43688715

Travis Romero on Capacity Builders

Thank you for the article! Agree with you that you have to start having this conversation at some point, especially when you reach the point of making decisions on what % of MITRE ATT&CK ttps you are going to translate to alerts. It's super easy to default to 100% coverage mode and want to alert on everything, but capacity models like this can really highlight how effective your team will be mapped to the budget allocated to SOC staffing. It's a simple message to leadership - if you want fast response time SLA's to all threats, here's how many people you will need.

  • General Meta Tags

    16
    • title
      Comments - Capacity Modeling: Enhancing Analyst Well-being & SOC Efficiency
    • title
    • title
    • title
    • title
  • Open Graph Meta Tags

    7
    • og:url
      https://capacitybuilders.substack.com/p/capacity-modeling-enhancing-analyst/comment/43688715
    • og:image
      https://substackcdn.com/image/fetch/$s_!RvKZ!,f_auto,q_auto:best,fl_progressive:steep/https%3A%2F%2Fcapacitybuilders.substack.com%2Ftwitter%2Fsubscribe-card.jpg%3Fv%3D-266565806%26version%3D9
    • og:type
      article
    • og:title
      Travis Romero on Capacity Builders
    • og:description
      Thank you for the article! Agree with you that you have to start having this conversation at some point, especially when you reach the point of making decisions on what % of MITRE ATT&CK ttps you are going to translate to alerts. It's super easy to default to 100% coverage mode and want to alert on everything, but capacity models like this can really highlight how effective your team will be mapped to the budget allocated to SOC staffing. It's a simple message to leadership - if you want fast response time SLA's to all threats, here's how many people you will need.
  • Twitter Meta Tags

    8
    • twitter:image
      https://substackcdn.com/image/fetch/$s_!RvKZ!,f_auto,q_auto:best,fl_progressive:steep/https%3A%2F%2Fcapacitybuilders.substack.com%2Ftwitter%2Fsubscribe-card.jpg%3Fv%3D-266565806%26version%3D9
    • twitter:card
      summary_large_image
    • twitter:label1
      Likes
    • twitter:data1
      0
    • twitter:label2
      Replies
  • Link Tags

    31
    • alternate
      /feed
    • apple-touch-icon
      https://substackcdn.com/image/fetch/$s_!znEr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a567243-aa9b-448c-b10a-3408d0fe804b%2Fapple-touch-icon-57x57.png
    • apple-touch-icon
      https://substackcdn.com/image/fetch/$s_!I5sm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a567243-aa9b-448c-b10a-3408d0fe804b%2Fapple-touch-icon-60x60.png
    • apple-touch-icon
      https://substackcdn.com/image/fetch/$s_!3evp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a567243-aa9b-448c-b10a-3408d0fe804b%2Fapple-touch-icon-72x72.png
    • apple-touch-icon
      https://substackcdn.com/image/fetch/$s_!rOKT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a567243-aa9b-448c-b10a-3408d0fe804b%2Fapple-touch-icon-76x76.png

Links

13