30-60-90 day plan for cybersecurity analysts
On this page
A cybersecurity analyst is hired to notice what others miss. In the first weeks, they will notice very little, because they do not yet know what normal looks like in your environment: which logins are routine, which servers talk to which, which alerts fire every day for harmless reasons. The danger in the early weeks runs both ways. An analyst who escalates everything wears out the team; one who closes alerts they do not understand can miss the one that matters. A 30-60-90 day plan for cybersecurity analysts should build that sense of normal deliberately and only then hand over shifts and detections.
This plan is for the security operations manager, security lead or CISO hiring an analyst into a security operations center (SOC) or a small internal security team. The general structure is in the 30-60-90 day plan template for new hires.
Start with the map, not the alert queue
Ask the new analyst to build a written map of the environment in the first month. It doubles as a check on the team's own documentation, which is often out of date.
| Area | What to capture | Usual source |
|---|---|---|
| Critical systems and data | Where sensitive data lives; systems the business cannot run without | Asset inventory, data owners, IT |
| Log coverage | Which sources reach the SIEM or detection tools, and which do not | Security tooling configuration |
| Detections | Rules that fire most often, rules that never fire, rules nobody owns | Detection platform reports |
| Identity | Privileged accounts, service accounts, MFA coverage | Identity provider and IT |
| Response | Runbooks, escalation contacts, the incident response plan and when it was last tested | Security team documentation |
Many teams organize this work around the NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, whose six functions are Govern, Identify, Protect, Detect, Respond and Recover. An analyst's first 90 days sit mainly in Identify, Detect and Respond.
Why escalation rules matter beyond the SOC
An analyst's escalation can start legal clocks. The SEC's 2023 cybersecurity disclosure rules require a public company to file a Form 8-K under Item 1.05 generally within four business days after it determines that a cybersecurity incident is material. All 50 states also have laws requiring notification of individuals after certain breaches of personal information; NCSL keeps a list of state breach notification laws. Sector rules such as HIPAA add more. Analysts do not decide materiality or notification, but the speed and quality of their escalation and notes feed those decisions. These points are current as of October 2026 and are not legal advice; the incident response plan and counsel set the process.
The 30-60-90 day plan
30-60-90 day plan — [Name], Cybersecurity Analyst, [team]
Reports to: [SOC manager / security lead] Start: [date]
Tools: [SIEM], [EDR], [identity provider], [ticketing]
Shift pattern: [hours / rotation] Alert volume: [per day]
Incident response plan last tested: [date]
DAYS 1-30 — Learn normal
Goals:
- Get read access to the security tools; complete tool training
- Shadow triage across the main alert types on several shifts
- Build the environment map: critical systems, log coverage,
detections, identity, response contacts
- Read every runbook; mark the ones that are missing or wrong
- Learn the escalation rules and the incident response plan
Deliverables by day 30:
- Environment map with log coverage gaps listed
- Runbook review with fixes proposed
Check-in: day 30, with SOC manager
DAYS 31-60 — Triage with review
Goals:
- Triage alerts in the queue, with a senior analyst reviewing
closures and escalations (example: all of them for two weeks,
then a sample)
- Work shifts alone once escalation rules are signed off
- Update [example: 2-3] runbooks from what they learned
- Take ownership of one noisy detection and tune it
Deliverables by day 60:
- Weekly review of their closures and escalations
- Tuned detection with before-and-after alert volume
Check-in: day 60
DAYS 61-90 — Own a piece of the program
Goals:
- Own a detection area or log source (example: identity alerts)
- Run or help run a tabletop exercise on a likely scenario
- Close one log coverage gap with the system owner
Deliverables by day 90:
- Tabletop findings with owners and dates
- Coverage gap closed or scheduled
Check-in: day 90 — full review
What to measure
Speed matters, but in the first months it should not be bought at the cost of investigation. Measure both, and read a sample of the analyst's closed alerts each week. Standards are examples; use your team's own.
| Measure | Why it matters | Example standard (example only) |
|---|---|---|
| Time to acknowledge and triage | Reduces dwell time | Within the team's service level by severity |
| Escalations confirmed as real | Shows judgment, in both directions | Reviewed weekly with the senior analyst |
| Closure notes | Evidence for the next analyst and for any later investigation | Every closure states what was checked and why it was benign |
| False positive rate on owned detections | Noise wears down the whole team | Falling after tuning, without losing true positives |
| Runbooks updated | Team knowledge improves | Each update reviewed by a senior analyst |
A filled example
Cybersecurity analyst: Rafael Santos (invented), two years on a managed security provider's SOC, joining a mid-size healthcare company's internal security team.
Day 30: His environment map found that logs from two clinical applications did not reach the SIEM, and that one detection for impossible travel fired dozens of times a day on staff using a company VPN. Three runbooks referred to a tool the team had retired.
Day 60: Working shifts alone. Tuned the impossible-travel detection to exclude the company's VPN ranges, which cut its alert volume sharply while it still caught a test login from an unexpected country. Rewrote the three outdated runbooks.
Day 90: Owned identity alerts. Helped run a tabletop on a compromised clinician account, which found the after-hours contact for the electronic health record vendor was out of date. Worked with IT to schedule the onboarding of one clinical application's logs.
What "on track" looks like
| Checkpoint | On track | Worth a direct conversation |
|---|---|---|
| Day 30 | Specific map with gaps; runbook issues found; escalation rules understood | Map copied from old documentation; has not shadowed enough shifts |
| Day 60 | Solo shifts with sound closures; one detection tuned with evidence | Closures without notes; detection silenced rather than tuned |
| Day 90 | Owns an area; tabletop run; coverage gap moving | Still escalates routine alerts; no ownership of anything |
What the team owes the new analyst
- Tool access on day one, at least read-only, so the first week is not spent waiting.
- A senior analyst assigned to review their work, with time for it.
- Clear escalation rules, including who to call at night and what counts as urgent.
- Permission to raise gaps, including in tools or decisions made before they joined.
Common mistakes
| Mistake | Result | Fix |
|---|---|---|
| Straight onto the queue | Alerts judged without context | Environment map and shadowing first |
| Rewarding fast closures | Shallow investigation | Review closure notes along with speed |
| Tuning by turning rules off | Blind spots | Tune with evidence and keep a test case |
| Incident response plan never tested | Confusion in a real incident | Tabletop by day 90 |
Shift handoffs
In a team that runs shifts, the handoff is where investigations get lost. Ask the new analyst to use the team's handoff format from their first shadowed shift, and to include for each open item what was checked, what is still unknown and what the next step is. Reviewing a week of their handoff notes at the day-30 check-in shows quickly whether they understand what they are looking at, and whether the next analyst could pick up their work without a phone call.
Adapting the plan
- Junior or career-change analysts: extend the shadowing period and add structured training on networking, identity and the main attack techniques.
- One-person security teams: add vulnerability management, security awareness and vendor risk to the plan, and weight the first month toward the map and the incident response plan.
- Cloud-heavy environments: add the cloud provider's logging, identity and configuration findings to the map, and work closely with the platform team.
If you are still hiring, the cybersecurity analyst screening questions cover triage judgment and investigation habits, and the Boolean search strings for cybersecurity roles help with sourcing. Analysts work closely with infrastructure teams; see the 30-60-90 day plan for IT managers and the 30-60-90 day plan for DevOps engineers.
Questions people ask
When should a new security analyst triage alerts alone?
After they have shadowed triage across the main alert types, worked through the runbooks and handled a set of alerts with a senior analyst reviewing each decision. For many teams that is somewhere in the second month; it depends on the quality of the runbooks and how much context the alerts carry. Escalation rules should be clear before they work any shift alone.
What should a new cybersecurity analyst learn first?
What the organization has and where it is: the main systems, where sensitive data lives, which logs reach the security tools and which do not. Alerts only make sense against that map. The escalation and incident response procedure comes next, because it decides what the analyst does when something is real.
Do public companies have deadlines for reporting cyber incidents?
Yes. Under the SEC's 2023 rules, a public company generally must file a Form 8-K under Item 1.05 within four business days after it determines that a cybersecurity incident is material, and the materiality determination must be made without unreasonable delay. Analysts do not make that call, but their escalation speed and notes feed it. Other rules, such as state breach notification laws, may apply. This is not legal advice.
What metrics fit a security analyst's first 90 days?
Time to acknowledge and triage alerts, the share of escalations confirmed as real, documentation quality on closed alerts, and false positive rates on the detections they tune. Use them to coach in the first two months; avoid targets that reward closing alerts quickly over investigating them properly.