Skip to content

Day 1

SOC mandate, incident notification and digital evidence

Participants can fix the moment of awareness, calculate the notification deadlines, lawfully collect and verify digital evidence, and write a bounded, fact-based conclusion.

Training case
D1-BALTNET-001
Programme topics
1, 2
Assignments
P1 · P2 · P3 · ID-01

Where this day sits in the chain

Sequence: SOC mandate, escalation of facts and impact, 24 / 72 h notification, lawful and proportionate collection, incident case, reflection and an individual decision.

Rule of the day

Legal qualification is not the SOC's call alone: technical facts are separated from the owners of the Cybersecurity Law / NIS2, GDPR and contractual decisions.

Schedule

How the day runs

TimeTopicFormatOutput
09:00–09:45SOC processes in the organisationTheoryMandate and escalation owner
10:00–10:45NIS2 notification to NKSCTheory24 / 72 h stages and the parallel GDPR route
10:45–11:00Knowledge checkKahoot12 questions
11:00–12:00Completing the incident notificationPractical P1Fact-based draft
13:00–13:45The law of digital evidenceTheoryProvenance, integrity, lawfulness, control
13:45–15:00Evidence collection IPractical P2Collection plan, SHA-256, PCAP
15:15–16:30Evidence collection IIPractical P3Case and bounded conclusion
16:30–16:55Review of resultsReflectionSupports / does not support / process change
17:00–19:00Independent workID-012–3 page decision memo
Breaks: 09:45–10:00, 12:00–13:00 (lunch) and 15:00–15:15. Sessions run online.

Learning outcomes

By the end of the day, participants can

  1. D1.1Explain the SOC mandate, the limits of its services, and who owns escalation.
  2. D1.2Fix the moment of awareness (UTC and EEST) and calculate the early-warning and notification deadlines.
  3. D1.3Separate the owners of Cybersecurity Law / NIS2 qualification, GDPR and contractual assessments.
  4. D1.4Keep known facts, hypotheses and unknowns apart in a notification draft.
  5. D1.5Build an evidence collection plan by priority, volatility, method and authorisation.
  6. D1.6Verify evidence integrity with SHA-256 hashes and complete the chain of custody.
  7. D1.7Correlate DNS, HTTP and endpoint events and state plainly what the data does and does not support.

Practice

Practical assignments

Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.

  1. P1

    Incident notification

    Moment of awareness, the deadline formula with its source, facts / hypotheses / unknowns, impact, actions, check owners and the next update time. No real notification is sent.
    Duration:
    60 min
    Deliverable:
    Notification draft and a traceable deadline calculation
  2. P2

    Evidence collection plan and analysis environment

    Collection plan for four artefacts; the PCAP is opened in Wireshark via File > Open only; DNS and HTTP findings cite packet number and time. The Security Onion variant adds PCAP import, Hunt and Cases with Case ID and History.
    Duration:
    75 min
    Deliverable:
    Collection plan and incident case
  3. P3

    Analysis and conclusion

    Correlating DNS, HTTP and the endpoint timeline, decoding Base64 in a local CyberChef (never executing the result), comparing hashes before and after analysis.
    Duration:
    75 min
    Deliverable:
    Conclusion and chain of custody

Extra labs

For deeper practice

The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.

  • LAB-4A

    SIEM log normalisation and data-quality validation

    Turn messy authentication logs into a normalised event set fit for SIEM analysis, find the data-quality problems, and identify a password-spraying sequence.

  • LAB-4B

    Detection engineering: rule, tuning and regression testing

    Build detection logic from the LAB-4A behaviour and prove the rule works against a defined test set, not a single example.

Carry on in your environment

Related tools

  • CISO.lt

    ciso.lt

    Information security officer's assistant

    Take the notification draft and incident management plan structure further for your own organisation with the CISO.lt assistant.

    • Security policy and procedures
    • Incident management plan and notification
    • Risk assessment
    • NIS2 / GDPR compliance checklists

Full programme

Full programme

Next day

Day 2: Security policy and SOC technical architecture

Day 2