Information & Communications Technology

Security Operations Centre Design and Alert Triage Workflows

Covers SOC operating models, detection use case development and alert triage workflow design that reduce false positives and analyst fatigue.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

A security operations centre that drowns analysts in unfiltered alerts detects less than a smaller team working well-tuned, prioritised queues. This course teaches security operations centre design and alert triage workflow development from staffing model through to detection tuning and performance measurement. Participants learn to choose between in-house, co-managed and outsourced SOC models, prioritise detection use case development against MITRE ATT&CK coverage gaps, and build triage workflows with clear escalation criteria and investigation playbooks. Sessions address the practical problem of alert fatigue directly: tuning detections against real false positive rates, rotating analyst workload, and tracking mean time to detect, acknowledge and resolve as evidence of improvement. Exercises include drafting a triage decision tree for a sample alert set, writing a detection use case with defined triggering logic, and designing a purple team exercise that feeds findings back into the detection backlog. Participants leave with playbook templates, a metrics dashboard structure and a SOC maturity self-assessment.

Expected Learning Outcomes

01

Select a security operations centre model and staffing rota matched to coverage and budget.

02

Prioritise detection use case development using MITRE ATT&CK technique coverage gaps.

03

Build alert triage workflows with defined escalation criteria and investigation playbooks.

04

Tune detection rules to reduce false positives without losing genuine alert coverage.

05

Apply workload rotation and caseload monitoring to reduce analyst fatigue and attrition.

06

Track mean time to detect, acknowledge and resolve as core security operations metrics.

07

Run purple team exercises that feed validated findings into the detection content backlog.

Who Should Attend

01

Security operations centre managers designing or restructuring their analyst team.

02

Tier one and tier two analysts moving into triage workflow design and detection engineering.

03

Detection engineers building and tuning SIEM and SOAR use cases.

04

Chief information security officers scoping SOC staffing and tooling investment.

05

Incident response leads coordinating escalation between the SOC and response teams.

06

Managed security service provider staff standardising triage across client accounts.

Course Modules

Select any module to see its sessions and points.

01

Designing the Security Operations Centre Model

2 sessions · 8 points

Session 1Choosing a SOC Operating Model

  • Compare in-house, co-managed and fully outsourced SOC models against coverage and cost.
  • Define analyst tiers and the escalation path connecting each tier to the next.
  • Plan follow-the-sun staffing or on-call rotas that deliver continuous coverage.
  • Size the SOC team against expected alert volume and organisational risk appetite.

Session 2Selecting and Integrating the Detection Toolset

  • Define requirements for SIEM, SOAR, endpoint detection and case management platforms before selection.
  • Plan log source onboarding priority based on asset criticality and threat exposure.
  • Integrate threat intelligence feeds into detection and alert enrichment workflows.
  • Document data retention and licensing constraints that affect achievable detection coverage.
02

Building Detection Content and Triage Workflows

2 sessions · 8 points

Session 1Developing Detection Use Cases

  • Prioritise detection use case development using MITRE ATT&CK technique coverage gaps.
  • Write detection logic with clearly defined triggering conditions and expected false positive rate.
  • Peer review new detection rules before promoting them into production alerting.
  • Retire or tune detections that generate disproportionate noise relative to true positives.

Session 2Structuring Alert Triage Workflows

  • Define a triage decision tree that routes alerts to escalation, investigation or dismissal within set targets.
  • Write playbooks that standardise the investigation steps for common alert categories.
  • Set escalation criteria between tier one, tier two and incident response teams.
  • Capture triage decisions and rationale in the case management system for later review.
03

Reducing Noise and Analyst Fatigue

2 sessions · 8 points

Session 1Tuning Detections Against Real Alert Volume

  • Analyse alert volume and false positive rate by detection rule to prioritise tuning effort.
  • Apply suppression and grouping logic to reduce duplicate alerts from the same root cause.
  • Validate that tuning changes do not silently remove genuine detection coverage.
  • Schedule regular detection health reviews with the analysts who work the alerts daily.

Session 2Supporting Analyst Wellbeing and Retention

  • Rotate analysts between triage, threat hunting and detection engineering to vary workload.
  • Monitor caseload and shift handover quality as leading indicators of burnout risk.
  • Build a clear career progression from tier one triage into specialist security roles.
  • Run blameless reviews of missed or mishandled alerts focused on process, not individuals.
04

Measuring and Maturing SOC Performance

2 sessions · 8 points

Session 1Defining SOC Metrics and Service Levels

  • Track mean time to detect, acknowledge and resolve as core security operations indicators.
  • Set internal service level targets by alert severity and communicate them to stakeholders.
  • Report false positive and false negative trends to justify tooling and staffing investment.
  • Benchmark SOC performance against a recognised maturity model to identify capability gaps.

Session 2Continuous Improvement Through Purple Teaming

  • Run purple team exercises pairing detection engineers with red team activity to validate coverage.
  • Feed exercise findings directly into the detection use case backlog for action.
  • Update playbooks and triage workflows based on lessons drawn from real incidents.
  • Present a SOC improvement roadmap that sequences investment by risk reduction impact.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course