Skip to main content

Goals and KPIs

The IDR measures accepted evidence, not raw course hours.

KPI90-day target12-month targetEvidence
Sprint execution≥10/12 weeks acceptedN/AWeekly artefacts
Investigation quality3 reviewed cases8 reviewed casesTimelines, conclusions, review notes
Wazuh/SIEM capability3 triage cases + 1 tuning idea3+ tested detections and tuning historyDetection pack
Incident response1 tabletop3 scenarios / one polished runbookRunbook and decision logs
Networking/telemetryEvent-source map completeMulti-source investigation evidenceLab notes
Cloud securityBaseline control mapOne cloud-security portfolio artefactControl matrix/diagram
AutomationPlan selected2 small SOC utilitiesCode + tests + README
GitHub professionalism3 clean repos/PRsFull portfolio indexGit history and README quality
Communication3 reviewed summaries6 reviewed technical/non-technical briefsMentor notes
Interview readiness3 evidence-backed stories2 mock interviews + 6 strong storiesInterview notes

Formal scorecard

Score each dimension from 1–5.

Dimension135
Investigation logicJumps to conclusionsUses evidence and a repeatable processCorrelates multiple sources and explains uncertainty
SIEM/detectionTool navigation onlyCan triage and describe logicCan test, tune and defend detection choices
Networking/telemetryLimited protocol/event understandingCorrectly interprets common evidenceSelects the right telemetry for hypotheses
Incident responseUnstructured reactionUses severity/escalation/runbook logicMakes clear, risk-aware response decisions
CommunicationRaw technical notesClear structured summaryAudience-specific, concise and decision-ready
Evidence qualityScreenshots without contextReproducible README/evidenceProfessional portfolio-quality case study
Security/privacyInconsistent handlingSafe synthetic/sanitised evidenceProactively designs privacy/security boundaries

Day-30 gate

  • first two investigations use a consistent method;
  • Wazuh lab inventory and alert flow are understood;
  • GitHub evidence workflow is in place;
  • learning schedule is sustainable.

Day-60 gate

  • one detection has been tested/tuned;
  • incident-response tabletop is complete;
  • communication improvement is visible in at least two revised summaries;
  • at least two portfolio artefacts are mentor-review ready.

Day-90 gate

  • at least 10 sprint weeks accepted or a documented recovery plan exists;
  • three portfolio artefacts are review-ready;
  • one clear next specialisation direction is selected;
  • CV/LinkedIn/GitHub claims are linked to evidence.

Annual completion gate

Nkateko should be able to explain and defend six portfolio artefacts, complete a realistic SOC case study and demonstrate readiness for junior SOC/security-operations interviews without relying on course-completion claims alone.