← All Case Studies
Case study 02 · SOC workflow optimization

Reducing incident response time by 63%

A healthcare SOC was taking roughly 24 hours to respond to incidents. I helped close telemetry gaps, improve asset classification, and connect NDR data to the team’s investigation workflow.

ExtraHopNDRHealthcareSix months
The goal

Turn more security data into faster decisions

The platform was producing value, but missing telemetry and inconsistent asset classification slowed investigations.

The customer needed a tighter path from network evidence to analyst action. The goal was to reduce friction in the SOC workflow and create a stronger foundation for future AI-assisted detection.

01

Close telemetry gaps

Improve the evidence available to analysts during an investigation.

02

Fix asset context

Make classification more consistent so alerts could be interpreted faster.

03

Fit the workflow

Connect NDR data to the way the SOC actually investigated incidents.

The strategy

Improve the operating system around the platform

The response-time problem crossed product usage, data quality, and team workflow. I worked across those layers so analysts could move from signal to action with less friction.

Mapped the sources of delay

Focused on the points that slowed investigations: incomplete telemetry, inconsistent asset context, and a gap between NDR evidence and established SOC processes.

Improved data and classification

Worked to close telemetry gaps and correct asset classification so analysts had more reliable context when triaging and investigating alerts.

Connected data to the investigation path

Integrated NDR insights into the SOC’s working process, turning platform data into a more direct input for incident response.

Measured the operational outcome

Tracked the change in mean time to respond over six months, keeping the work tied to analyst performance rather than feature adoption alone.

The result

Fifteen hours removed from the response cycle

Mean time to respond fell from 24 hours to 9 hours in six months—a 63% improvement.

The improved telemetry, asset context, and workflow also prepared the SOC for AI-assisted detection by strengthening the underlying data and operating discipline.

63%

Faster mean time to respond

15h

Removed from the average response cycle

6 mo.

From baseline to measured result

What this case demonstrates

Customer success can change an operational metric when adoption work reaches beyond feature usage. The leverage came from connecting platform data, asset context, and the team’s real investigation process.

Customer name and sensitive implementation details are withheld. Results are drawn from my portfolio performance.

Continue exploring

See how a $27M SIEM portfolio reached 100% renewal

Next: risk discipline, stakeholder alignment, and forecast accuracy.