An auditor asks what your 9,000 unopened medium-severity detections since March contained. What do you say?
answer
- you cannot vouch for what nobody read
- describe the population before estimating it
- random beats convenient, always
- report an interval, not a comfort number
- the risk owner is not the analyst
basics
~20 sNever assert an unworked backlog was benign. Characterise the population, work a random sample to full verdicts, report the estimated true-positive rate with its uncertainty, and state how many items can no longer be adjudicated at all.
solid answer
~50 sThe one answer you cannot give is that they were probably noise — that is a claim about a population nobody sampled, and an auditor is entitled to ask how you know. Give three things instead. **Characterise** the band: which rules produced it, which accounts and providers, the date range, and how many items still have evidence inside retention. **Estimate** its content by drawing a genuinely random sample — a hundred items across the band, stratified by rule family if it is heterogeneous — and working each to the same standard as a live alert, then reporting the true-positive rate with its uncertainty rather than a single reassuring number. **State the loss**: the count that has already passed its evidence horizon and can never be adjudicated. Then put the decision where it belongs. At 40 worked against 300 arriving, this tail is a structural output of the SOC's capacity, and whether to fund it, shrink it or accept it is a decision an executive owns, not an analyst.
go deeper
Be ready to say that you cannot vouch for detections nobody opened, and that the honest first move is to describe what the band contains — which rules, which accounts, what date range — rather than to characterise its risk.
Expect to explain why the worked set's false-positive rate does not transfer to the unopened band, since items go unopened non-randomly, and why any sample drawn from it must be random rather than convenient.
Demonstrate the estimation properly: stratified random sampling, sampled items worked to full verdicts including an undetermined disposition for expired evidence, and a result reported as an interval with the unadjudicable count broken out.
Own the governance. Frame the tail as the arithmetic of capacity against arrivals, name who is entitled to accept that exposure, and hand them a decision with numbers attached rather than absorbing an organisational risk inside the SOC.
## Why the easy answers fail Three responses come naturally and all of them collapse under one follow-up question. *They were mediums, so low risk.* Severity was assigned by the rule author before the rule knew which account, identity or data set it would fire on. A medium-severity detection covering a sanctioned cloud primitive — a snapshot shared outward, a role trusted from a new account — is exactly where a competent adversary prefers to operate, precisely because it does not look like malware. *Nothing escalated, so nothing was malicious.* Nothing escalated because nobody opened them. This is circular, and an auditor will notice. *Those rules are historically noisy.* The historical rate was measured over items that were worked. The unopened band was selected non-randomly — by severity, by which accounts are busiest, by what arrived while the single analyst was mid-investigation — so the worked-set rate does not transfer to it. ## The defensible construction ### Characterise the population Before any estimate, describe what the 9,000 actually are: which rules and rule families, which accounts and which of the three providers, the date span, the distribution of ages, and — critically — how many still sit inside their evidence retention window and how many do not. That last split determines what is even recoverable and it is the number most likely to be missing from the auditor's mental model. ### Sample it properly You cannot work 9,000 with one analyst. You can work a hundred. The sample must be **random within the band**, not convenience-drawn: not the newest hundred, not the ones with interesting-looking rule names, not the ones from the accounts you know well. A convenience sample produces a number you cannot extrapolate, and it will be the first thing an auditor probes. If the band is heterogeneous — one rule family contributing 6,000 of the 9,000 — stratify, sample within each stratum, and weight the result. Work each sampled item to the same standard you would apply to a live alert, and record the dispositions properly: true positive, benign true positive, false positive, or undetermined because the evidence had expired. That last category is a result, not a gap in the exercise. ### Report an estimate, with its uncertainty The output is a sentence of this shape: *we drew 100 at random from the 9,000; three were true positives, one of which warranted escalation and has been opened as an incident; the rest split between benign true positives and false positives; eleven could not be adjudicated because their evidence had expired.* Extrapolate with an explicit interval and say plainly that the interval is wide because the sample is small. A number with an honest interval survives scrutiny; a point estimate presented as fact does not. ### Decide in advance what happens to a hit Sampling an unworked backlog can find a real intrusion, and it sometimes does. Agree before you start who declares an incident, what the trigger is, and that the sampling exercise pauses if the estimate demands a broader look. Discovering that mid-exercise, in front of an auditor, is a bad time to invent the process. ## The organisational half, which is the actual question An auditor asking about 9,000 unopened items is not really asking an analyst to do statistics. They are asking whether the organisation knows what it is not looking at, and whether anyone with authority has been told. So present the tail as arithmetic, not as a lapse: at a capacity of roughly 40 items a day against roughly 300 arriving, an unworked band is the guaranteed output of the system as funded. Then be explicit about ownership. An analyst cannot accept this risk on the organisation's behalf; the person who owns the SOC's budget and coverage can. Your obligation is to make the tail measurable and to put the choice in front of them with the numbers attached — the estimated true-positive rate in the band, the count already past adjudication, and what a given amount of extra capacity would recover. What they then decide to do about it — fund more capacity, change what is collected, deliberately narrow coverage — is their call to make and to sign. ## What separates a strong answer The candidate who says *I would sample it* is halfway there. The one who says *randomly, stratified, worked to full verdicts, reported as an interval with the unadjudicable count broken out, and escalated as a capacity decision to the person who owns it* has understood that the auditor's question is about governance and that the statistics are how you answer it honestly rather than reassuringly.
- Your random sample of 100 turns up one genuine intrusion. What changes?It becomes an incident immediately and is handled as one, independently of the sampling exercise. It also changes the estimate's meaning: one hit in a hundred implies roughly ninety in the band, which is no longer a reporting question but a scoping question about how much of the tail must now be worked. Agree the trigger and the escalation path before sampling starts, not after a hit.
- Why not simply bulk-close the 9,000 with an explanatory note?Because a bulk close writes a disposition nobody reached, and the field will be read later as a verdict. If the items must leave the queue, they leave with an explicit undetermined disposition, the reason, and the count preserved as a reported number. Whether to close a whole unworkable band, and on what criteria, is a decision with a named owner and a sign-off, not a queue-tidying action.
- The auditor asks for a single number for the risk in the tail. What do you give?The estimated count of true positives implied by the sample, stated with its interval, alongside the count of items already past adjudication. Refuse to compress those into one figure: the first is an estimate you can defend and revise with more sampling, the second is a permanent loss of knowledge, and collapsing them hides the part that cannot be fixed by working harder.
A warehouse cannot certify 9,000 unopened cartons as undamaged. It can open a random hundred, report the damage rate with an error bar, and say how many are already past the point where damage could be assessed.
saying these in an interview costs you the question
- Asserting the unworked band was mostly noise
- Arguing nothing escalated so nothing was malicious
- Extrapolating from the newest or most interesting items
- Presenting a point estimate with no uncertainty
- An analyst accepting the risk on the organisation's behalf