Goals and KPIs
The IDR measures accepted evidence, not raw course hours.
| KPI | 90-day target | 12-month target | Evidence |
|---|---|---|---|
| Sprint execution | ≥10/12 weeks accepted | N/A | Weekly artefacts |
| Investigation quality | 3 reviewed cases | 8 reviewed cases | Timelines, conclusions, review notes |
| Wazuh/SIEM capability | 3 triage cases + 1 tuning idea | 3+ tested detections and tuning history | Detection pack |
| Incident response | 1 tabletop | 3 scenarios / one polished runbook | Runbook and decision logs |
| Networking/telemetry | Event-source map complete | Multi-source investigation evidence | Lab notes |
| Cloud security | Baseline control map | One cloud-security portfolio artefact | Control matrix/diagram |
| Automation | Plan selected | 2 small SOC utilities | Code + tests + README |
| GitHub professionalism | 3 clean repos/PRs | Full portfolio index | Git history and README quality |
| Communication | 3 reviewed summaries | 6 reviewed technical/non-technical briefs | Mentor notes |
| Interview readiness | 3 evidence-backed stories | 2 mock interviews + 6 strong stories | Interview notes |
Formal scorecard
Score each dimension from 1–5.
| Dimension | 1 | 3 | 5 |
|---|---|---|---|
| Investigation logic | Jumps to conclusions | Uses evidence and a repeatable process | Correlates multiple sources and explains uncertainty |
| SIEM/detection | Tool navigation only | Can triage and describe logic | Can test, tune and defend detection choices |
| Networking/telemetry | Limited protocol/event understanding | Correctly interprets common evidence | Selects the right telemetry for hypotheses |
| Incident response | Unstructured reaction | Uses severity/escalation/runbook logic | Makes clear, risk-aware response decisions |
| Communication | Raw technical notes | Clear structured summary | Audience-specific, concise and decision-ready |
| Evidence quality | Screenshots without context | Reproducible README/evidence | Professional portfolio-quality case study |
| Security/privacy | Inconsistent handling | Safe synthetic/sanitised evidence | Proactively designs privacy/security boundaries |
Day-30 gate
- first two investigations use a consistent method;
- Wazuh lab inventory and alert flow are understood;
- GitHub evidence workflow is in place;
- learning schedule is sustainable.
Day-60 gate
- one detection has been tested/tuned;
- incident-response tabletop is complete;
- communication improvement is visible in at least two revised summaries;
- at least two portfolio artefacts are mentor-review ready.
Day-90 gate
- at least 10 sprint weeks accepted or a documented recovery plan exists;
- three portfolio artefacts are review-ready;
- one clear next specialisation direction is selected;
- CV/LinkedIn/GitHub claims are linked to evidence.
Annual completion gate
Nkateko should be able to explain and defend six portfolio artefacts, complete a realistic SOC case study and demonstrate readiness for junior SOC/security-operations interviews without relying on course-completion claims alone.