Objective 1.5 · Lesson 1 of 2

Make investigation work repeatable

Efficiency means reaching sound decisions with less avoidable work. Standardisation helps when it preserves judgement at important points and removes ambiguity from routine steps.

Write down decisions and procedures differently

A playbook guides a team through a class of security situation: what evidence to gather, how to classify it, when to escalate, and which response options need approval. A runbook provides the detailed procedure for a repeatable task, such as collecting a defined audit export. The playbook can reference several runbooks without burying the decision process in interface instructions.

Both need an owner, a version, prerequisites, expected outputs, and a review trigger. Explain what to do when a step fails or evidence is unavailable. Avoid a process that requires a conclusion before allowing the analyst to collect the evidence needed for it. Leave room to record justified deviations and improve the guidance after real cases.

Make coordination visible in the case record

A shared case record should identify the current owner, impact assessment, evidence locations, actions already taken, and the next decision. Assign supporting tasks explicitly so two people do not repeat the same lookup while another important task is missed. Use a consistent time reference and distinguish planned actions from completed actions and verified results.

Shift handovers are tests of process quality. The receiving analyst should be able to explain the hypothesis, remaining uncertainty, and next action without replaying the whole investigation. Define who can authorise disruptive measures and how to contact service owners. A response deadline without a named owner or escalation path is a wish rather than an operational control.

Measure decision quality as well as speed

Track queue age, time to meaningful triage, repeated manual work, false-positive burden, and response completion where those measurements support decisions. Define the start and end of each measure. A falling average closure time can hide old unresolved cases or encourage premature closure. Break down results by case type and inspect the distribution, not just one headline number.

Dashboards should lead to action: show freshness, ownership, exceptions, and trends against a defined baseline. Pair speed measures with quality checks such as reopened cases, missed escalation criteria, and verified containment. Review representative cases with the team. The aim is to discover friction and improve the process, not reward analysts for making inconvenient alerts disappear.

Keep these points in mind

  • Use playbooks for decisions and runbooks for repeatable procedures.
  • A handover must expose uncertainty, ownership, and unfinished verification.
  • Pair efficiency measures with evidence of response quality.

Pause and practise

A team halves average closure time, but reopened cases double. What would you investigate before calling the change a success?

Show a worked response

Compare case types, queue age, closure reasons, and whether required verification was completed. Sample reopened cases to identify rushed decisions or missing evidence. Check whether the metric’s definitions changed. Faster closure is valuable only if the team still reaches reliable outcomes and does not transfer unfinished work into future cases.

Next lesson →
← Module overview