Day 1
SOC mandate, incident notification and digital evidence
Participants can fix the moment of awareness, calculate the notification deadlines, lawfully collect and verify digital evidence, and write a bounded, fact-based conclusion.
- Training case
- D1-BALTNET-001
- Programme topics
- 1, 2
- Assignments
- P1 · P2 · P3 · ID-01
Where this day sits in the chain
Sequence: SOC mandate, escalation of facts and impact, 24 / 72 h notification, lawful and proportionate collection, incident case, reflection and an individual decision.
Rule of the day
Legal qualification is not the SOC's call alone: technical facts are separated from the owners of the Cybersecurity Law / NIS2, GDPR and contractual decisions.
Schedule
How the day runs
| Time | Topic | Format | Output |
|---|---|---|---|
| 09:00–09:45 | SOC processes in the organisation | Theory | Mandate and escalation owner |
| 10:00–10:45 | NIS2 notification to NKSC | Theory | 24 / 72 h stages and the parallel GDPR route |
| 10:45–11:00 | Knowledge check | Kahoot | 12 questions |
| 11:00–12:00 | Completing the incident notification | Practical P1 | Fact-based draft |
| 13:00–13:45 | The law of digital evidence | Theory | Provenance, integrity, lawfulness, control |
| 13:45–15:00 | Evidence collection I | Practical P2 | Collection plan, SHA-256, PCAP |
| 15:15–16:30 | Evidence collection II | Practical P3 | Case and bounded conclusion |
| 16:30–16:55 | Review of results | Reflection | Supports / does not support / process change |
| 17:00–19:00 | Independent work | ID-01 | 2–3 page decision memo |
Learning outcomes
By the end of the day, participants can
- D1.1Explain the SOC mandate, the limits of its services, and who owns escalation.
- D1.2Fix the moment of awareness (UTC and EEST) and calculate the early-warning and notification deadlines.
- D1.3Separate the owners of Cybersecurity Law / NIS2 qualification, GDPR and contractual assessments.
- D1.4Keep known facts, hypotheses and unknowns apart in a notification draft.
- D1.5Build an evidence collection plan by priority, volatility, method and authorisation.
- D1.6Verify evidence integrity with SHA-256 hashes and complete the chain of custody.
- D1.7Correlate DNS, HTTP and endpoint events and state plainly what the data does and does not support.
Practice
Practical assignments
Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.
- P1
Incident notification
Moment of awareness, the deadline formula with its source, facts / hypotheses / unknowns, impact, actions, check owners and the next update time. No real notification is sent.- Duration:
- 60 min
- Deliverable:
- Notification draft and a traceable deadline calculation
- P2
Evidence collection plan and analysis environment
Collection plan for four artefacts; the PCAP is opened in Wireshark via File > Open only; DNS and HTTP findings cite packet number and time. The Security Onion variant adds PCAP import, Hunt and Cases with Case ID and History.- Duration:
- 75 min
- Deliverable:
- Collection plan and incident case
- P3
Analysis and conclusion
Correlating DNS, HTTP and the endpoint timeline, decoding Base64 in a local CyberChef (never executing the result), comparing hashes before and after analysis.- Duration:
- 75 min
- Deliverable:
- Conclusion and chain of custody
Extra labs
For deeper practice
The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.
LAB-4A
SIEM log normalisation and data-quality validation
Turn messy authentication logs into a normalised event set fit for SIEM analysis, find the data-quality problems, and identify a password-spraying sequence.
LAB-4B
Detection engineering: rule, tuning and regression testing
Build detection logic from the LAB-4A behaviour and prove the rule works against a defined test set, not a single example.
Carry on in your environment
Related tools
CISO.lt
ciso.ltInformation security officer's assistant
Take the notification draft and incident management plan structure further for your own organisation with the CISO.lt assistant.
- Security policy and procedures
- Incident management plan and notification
- Risk assessment
- NIS2 / GDPR compliance checklists
Full programme
Full programme