Templates

30-60-90 day plan for cybersecurity analysts

On this page
  1. Start with the map, not the alert queue
  2. Why escalation rules matter beyond the SOC
  3. The 30-60-90 day plan
  4. What to measure
  5. A filled example
  6. What "on track" looks like
  7. What the team owes the new analyst
  8. Common mistakes
  9. Shift handoffs
  10. Adapting the plan
  11. Questions people ask

A cybersecurity analyst is hired to notice what others miss. In the first weeks, they will notice very little, because they do not yet know what normal looks like in your environment: which logins are routine, which servers talk to which, which alerts fire every day for harmless reasons. The danger in the early weeks runs both ways. An analyst who escalates everything wears out the team; one who closes alerts they do not understand can miss the one that matters. A 30-60-90 day plan for cybersecurity analysts should build that sense of normal deliberately and only then hand over shifts and detections.

This plan is for the security operations manager, security lead or CISO hiring an analyst into a security operations center (SOC) or a small internal security team. The general structure is in the 30-60-90 day plan template for new hires.

Start with the map, not the alert queue

Ask the new analyst to build a written map of the environment in the first month. It doubles as a check on the team's own documentation, which is often out of date.

AreaWhat to captureUsual source
Critical systems and dataWhere sensitive data lives; systems the business cannot run withoutAsset inventory, data owners, IT
Log coverageWhich sources reach the SIEM or detection tools, and which do notSecurity tooling configuration
DetectionsRules that fire most often, rules that never fire, rules nobody ownsDetection platform reports
IdentityPrivileged accounts, service accounts, MFA coverageIdentity provider and IT
ResponseRunbooks, escalation contacts, the incident response plan and when it was last testedSecurity team documentation

Many teams organize this work around the NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, whose six functions are Govern, Identify, Protect, Detect, Respond and Recover. An analyst's first 90 days sit mainly in Identify, Detect and Respond.

Why escalation rules matter beyond the SOC

An analyst's escalation can start legal clocks. The SEC's 2023 cybersecurity disclosure rules require a public company to file a Form 8-K under Item 1.05 generally within four business days after it determines that a cybersecurity incident is material. All 50 states also have laws requiring notification of individuals after certain breaches of personal information; NCSL keeps a list of state breach notification laws. Sector rules such as HIPAA add more. Analysts do not decide materiality or notification, but the speed and quality of their escalation and notes feed those decisions. These points are current as of October 2026 and are not legal advice; the incident response plan and counsel set the process.

The 30-60-90 day plan

30-60-90 day plan — [Name], Cybersecurity Analyst, [team]
Reports to: [SOC manager / security lead]    Start: [date]
Tools: [SIEM], [EDR], [identity provider], [ticketing]
Shift pattern: [hours / rotation]    Alert volume: [per day]
Incident response plan last tested: [date]

DAYS 1-30 — Learn normal
Goals:
- Get read access to the security tools; complete tool training
- Shadow triage across the main alert types on several shifts
- Build the environment map: critical systems, log coverage,
  detections, identity, response contacts
- Read every runbook; mark the ones that are missing or wrong
- Learn the escalation rules and the incident response plan
Deliverables by day 30:
- Environment map with log coverage gaps listed
- Runbook review with fixes proposed
Check-in: day 30, with SOC manager

DAYS 31-60 — Triage with review
Goals:
- Triage alerts in the queue, with a senior analyst reviewing
  closures and escalations (example: all of them for two weeks,
  then a sample)
- Work shifts alone once escalation rules are signed off
- Update [example: 2-3] runbooks from what they learned
- Take ownership of one noisy detection and tune it
Deliverables by day 60:
- Weekly review of their closures and escalations
- Tuned detection with before-and-after alert volume
Check-in: day 60

DAYS 61-90 — Own a piece of the program
Goals:
- Own a detection area or log source (example: identity alerts)
- Run or help run a tabletop exercise on a likely scenario
- Close one log coverage gap with the system owner
Deliverables by day 90:
- Tabletop findings with owners and dates
- Coverage gap closed or scheduled
Check-in: day 90 — full review

What to measure

Speed matters, but in the first months it should not be bought at the cost of investigation. Measure both, and read a sample of the analyst's closed alerts each week. Standards are examples; use your team's own.

MeasureWhy it mattersExample standard (example only)
Time to acknowledge and triageReduces dwell timeWithin the team's service level by severity
Escalations confirmed as realShows judgment, in both directionsReviewed weekly with the senior analyst
Closure notesEvidence for the next analyst and for any later investigationEvery closure states what was checked and why it was benign
False positive rate on owned detectionsNoise wears down the whole teamFalling after tuning, without losing true positives
Runbooks updatedTeam knowledge improvesEach update reviewed by a senior analyst

A filled example

Cybersecurity analyst: Rafael Santos (invented), two years on a managed security provider's SOC, joining a mid-size healthcare company's internal security team.

Day 30: His environment map found that logs from two clinical applications did not reach the SIEM, and that one detection for impossible travel fired dozens of times a day on staff using a company VPN. Three runbooks referred to a tool the team had retired.

Day 60: Working shifts alone. Tuned the impossible-travel detection to exclude the company's VPN ranges, which cut its alert volume sharply while it still caught a test login from an unexpected country. Rewrote the three outdated runbooks.

Day 90: Owned identity alerts. Helped run a tabletop on a compromised clinician account, which found the after-hours contact for the electronic health record vendor was out of date. Worked with IT to schedule the onboarding of one clinical application's logs.

What "on track" looks like

CheckpointOn trackWorth a direct conversation
Day 30Specific map with gaps; runbook issues found; escalation rules understoodMap copied from old documentation; has not shadowed enough shifts
Day 60Solo shifts with sound closures; one detection tuned with evidenceClosures without notes; detection silenced rather than tuned
Day 90Owns an area; tabletop run; coverage gap movingStill escalates routine alerts; no ownership of anything

What the team owes the new analyst

  • Tool access on day one, at least read-only, so the first week is not spent waiting.
  • A senior analyst assigned to review their work, with time for it.
  • Clear escalation rules, including who to call at night and what counts as urgent.
  • Permission to raise gaps, including in tools or decisions made before they joined.

Common mistakes

MistakeResultFix
Straight onto the queueAlerts judged without contextEnvironment map and shadowing first
Rewarding fast closuresShallow investigationReview closure notes along with speed
Tuning by turning rules offBlind spotsTune with evidence and keep a test case
Incident response plan never testedConfusion in a real incidentTabletop by day 90

Shift handoffs

In a team that runs shifts, the handoff is where investigations get lost. Ask the new analyst to use the team's handoff format from their first shadowed shift, and to include for each open item what was checked, what is still unknown and what the next step is. Reviewing a week of their handoff notes at the day-30 check-in shows quickly whether they understand what they are looking at, and whether the next analyst could pick up their work without a phone call.

Adapting the plan

  • Junior or career-change analysts: extend the shadowing period and add structured training on networking, identity and the main attack techniques.
  • One-person security teams: add vulnerability management, security awareness and vendor risk to the plan, and weight the first month toward the map and the incident response plan.
  • Cloud-heavy environments: add the cloud provider's logging, identity and configuration findings to the map, and work closely with the platform team.

If you are still hiring, the cybersecurity analyst screening questions cover triage judgment and investigation habits, and the Boolean search strings for cybersecurity roles help with sourcing. Analysts work closely with infrastructure teams; see the 30-60-90 day plan for IT managers and the 30-60-90 day plan for DevOps engineers.

Questions people ask

When should a new security analyst triage alerts alone?

After they have shadowed triage across the main alert types, worked through the runbooks and handled a set of alerts with a senior analyst reviewing each decision. For many teams that is somewhere in the second month; it depends on the quality of the runbooks and how much context the alerts carry. Escalation rules should be clear before they work any shift alone.

What should a new cybersecurity analyst learn first?

What the organization has and where it is: the main systems, where sensitive data lives, which logs reach the security tools and which do not. Alerts only make sense against that map. The escalation and incident response procedure comes next, because it decides what the analyst does when something is real.

Do public companies have deadlines for reporting cyber incidents?

Yes. Under the SEC's 2023 rules, a public company generally must file a Form 8-K under Item 1.05 within four business days after it determines that a cybersecurity incident is material, and the materiality determination must be made without unreasonable delay. Analysts do not make that call, but their escalation speed and notes feed it. Other rules, such as state breach notification laws, may apply. This is not legal advice.

What metrics fit a security analyst's first 90 days?

Time to acknowledge and triage alerts, the share of escalations confirmed as real, documentation quality on closed alerts, and false positive rates on the detections they tune. Use them to coach in the first two months; avoid targets that reward closing alerts quickly over investigating them properly.