Skill readiness

How skill readiness scoring works

Every investigation you complete feeds a skill profile across eight SOC skill areas. Here is what is measured, how it is scored and how to use it to improve.

Your profile

One score. Eight skill areas. A clear next step.

Your SOC readiness score summarises how consistently you investigate like a working analyst. Underneath it, each skill area shows where you are strong and where to focus.

What each investigation is scored on

Investigations are not multiple-choice quizzes. Your score reflects how you reached your conclusion, not only whether the conclusion was right. Each investigation is assessed on five parts:

PartWhat it checks
Evidence coverageDid you review the evidence that matters, and did you tag the artefacts that support your decision?
ClassificationDid you correctly identify the alert as a true positive, false positive or benign activity?
SeverityDid you assign a severity that matches the impact and scope of the incident?
Response decisionsDid you choose sensible containment, escalation and remediation steps — and avoid unnecessary ones?
DocumentationAre your notes clear enough for another analyst or a manager to understand what happened and what you did?

The eight skill areas

Each scenario contributes to one or more skill areas. Over time, your profile shows a balanced picture of your strengths.

  • Identity security — sign-in anomalies, MFA events, impossible travel and account compromise.
  • Phishing analysis — email headers, sender reputation, links, attachments and user reports.
  • Networking — IP addresses, ports, protocols, DNS and suspicious connections.
  • Threat analysis — mapping activity to attacker techniques and judging intent.
  • Incident response — containment, escalation and remediation decisions.
  • Windows security — event logs, processes, PowerShell and persistence.
  • SIEM investigation — searching, filtering and correlating log data across sources.
  • Documentation — writing clear investigation notes and incident summaries.

Readiness levels

Your overall SOC readiness score places you in one of four levels. They are a guide to your progress, not a certification.

ScoreLevelWhat it means
0–39%Getting startedYou are learning the investigation workflow and core concepts.
40–59%Building foundationsYou handle common alerts but miss evidence or misjudge severity at times.
60–79%Junior SOC AnalystYou investigate most entry-level alerts methodically and document them clearly.
80–100%Job-readyYou work consistently across all skill areas, including harder, multi-source incidents.

How to use your profile

Your profile always highlights your weakest area and recommends a scenario to practise next. A practical routine is to complete one new investigation, then one recommended scenario that targets your weakest skill. If documentation is your weak spot, slow down and write notes as if your manager will read them — because on the job, they will.

Readiness scores are designed to guide practice. They do not replace professional certifications, but they give you concrete examples of investigations to discuss in interviews. See our guide to cybersecurity certifications for how the two fit together.

FAQ

Frequently asked questions

Is the readiness score a certification?

No. It is a practice measure that shows how consistently you investigate. It complements certifications rather than replacing them.

Can my score go down?

Yes. Your profile reflects recent performance, so it updates as you complete more investigations. That keeps it an honest picture of your current skill.

How many investigations does it take to get an accurate profile?

Your profile becomes more reliable as you complete scenarios across all eight skill areas. Aim to cover each area at least a few times before relying on it.

Know where you stand

Find out your SOC readiness score.

Complete your first investigation and get a starting profile across all eight skill areas.

Start free. No experience required.