Skip to content

Kit · Leadership

Team & competency kit

A small SOC is one resignation away from a capability gap. This kit covers the tiers and what each must be able to do, the segregation the law requires, and how to find your single points of failure before they find you.

Minimum viable team
4–7 for extended-hours cover
Hard rule
Detection is separate from administration
All kits

The separation that is not negotiable

Lithuanian law prohibits the cybersecurity manager and the system security officer from performing network or information system administration, or any role involving the maintenance and management of hardware or software. The SOC itself must be independent of those responsible for the proper operation of the systems it monitors.

In a small organisation this is uncomfortable — the person who knows the estate best is usually the person who runs it. Solve it with roles and review, not by quietly merging them.

Tiers and minimum capability

TierMust be able toFails when
L1 — triageApply a playbook accurately, recognise when one does not fit, and write a decision record someone else can followJudged on volume closed rather than on decision quality
L2 — investigatorEstablish scope and impact, collect artefacts soundly, choose a containment strategy and justify itPulled back into the alert queue mid-investigation
L3 — specialistForensic analysis, malicious code analysis, and translating technical findings into a business recommendationTreated as an escalation dumping ground rather than a scarce resource with entry criteria
Detection engineeringBuild, test and retire detections against a threat model, and measure their qualityGiven no protected time; the queue always wins
SOC OfficerHold the mandate, own the evidence trail, run the cadence, and speak to a board without translating badlyAbsorbed into being the most senior analyst

Find the single points of failure

Run this deliberately. Key-person risk is invisible until the person is unavailable, and then it is the only thing that matters.

Quarterly
0/8

Training plan that survives budget review

Tie every training item to a capability gap or a statutory obligation. Training justified by interest gets cut first.

Annual
0/7

Next kit

SOC build kit

The programme work breakdown for standing up a SOC — organisational measures, technical measures, detection scenarios and staffing.

Open SOC build kit