
Inside SOC: Triage Smarter, Not Harder w/ Tom DeJong
Source: YouTube · Black Hills Information Security · published Dec 19, 2025 · 1:20:51
Tom from BHIS's SOC presents a comprehensive guide to security alert triage, covering the fundamentals, mindset, process, and practical tips to help analysts work smarter rather than harder 0:35.
Key Takeaways:
• Triage is the process of evaluating and prioritizing security alerts to determine if they require immediate action, further investigation, or can be safely closed, with goals including identifying real threats, documenting findings, and filtering false positives 2:00
• The triage mindset rests on three pillars: being efficient and decisive, analytic and context-aware, and clear and communicative—always answering the "five W's" to turn data into insight 4:45
• The four-step triage process involves reviewing the alert, gathering context through enrichment and internal documentation, making a confident decision to escalate, investigate further, or close, and thoroughly documenting the outcome 9:30
• Common mistakes include escalating without evidence, over-investigating low-risk alerts, skipping context checks, writing weak documentation, and not asking for help when needed 17:00
• Managing alert fatigue requires leveraging internal documentation, using enrichments wisely, tuning detections, taking mental breaks, and leaning on team collaboration 26:30
Mastering triage is a journey that requires consistency, patience, and continuous learning—analysts should trust their process, use their team for support, and treat every alert as an opportunity to improve.
Sources:
- 0:35 Tom's background and presentation introduction
- [2:00](https://www.youtube.com/watch?v=A-vPjP69qgU&t=120
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
If you don't know how these webcasts begin, it's we reach out to people on the team who are good at sharing their knowledge and we say, "Hey, would you like to?" And they say, "Sure, but I'm not sure what I should talk about." And then we talk it over and then Tom settled on this and it is a fantastic topic. Tom is a part of our sock that we have for our clients and for our own internal use and so Tom's going to give you like he does this every day. Like this is what he does and so if you're here to learn from Tom, maybe as you're watching you're like, "Why does he do it that way?" There might be a little bit of like, "Why does he do it that way?" But as you're watching it's like, "Is there something I can use to help improve the work that I do or the work that our team does?" And so we ap…