← All Case Studies
Case study 02 · SOC workflow optimization

Reducing incident response time by 63%

A healthcare SOC was taking roughly 24 hours to respond to incidents. I helped close telemetry gaps, improve asset classification, and connect NDR data to the team’s investigation workflow.

ExtraHopNDRHealthcareSix months
The goal

Turn more security data into faster decisions

The platform was producing value, but missing telemetry and inconsistent asset classification slowed investigations.

The customer needed a tighter path from network evidence to analyst action. The goal was to reduce friction in the SOC workflow and create a stronger foundation for future AI-assisted detection.

01

Close telemetry gaps

Improve the evidence available to analysts during an investigation.

02

Fix asset context

Make classification more consistent so alerts could be interpreted faster.

03

Fit the workflow

Connect NDR data to the way the SOC actually investigated incidents.

The strategy

Improve the operating system around the platform

The response-time problem crossed product usage, data quality, and team workflow. I worked across those layers so analysts could move from signal to action with less friction.

Mapped the sources of delay

Focused on the points that slowed investigations: incomplete telemetry, inconsistent asset context, and a gap between NDR evidence and established SOC processes.

Improved data and classification

Worked to close telemetry gaps and correct asset classification so analysts had more reliable context when triaging and investigating alerts.

Connected data to the investigation path

Integrated NDR insights into the SOC’s working process, turning platform data into a more direct input for incident response.

Measured the operational outcome

Tracked the change in mean time to respond over six months, keeping the work tied to analyst performance rather than feature adoption alone.

My Personal Role & Authority

What I personally owned

I owned the customer-success workstream that connected product adoption, data quality, and the SOC’s operating process to a measurable response-time goal.

Diagnosed

Mapped the investigation delays to missing telemetry, inconsistent asset classification, and workflow friction.

Decided

Prioritized data quality and workflow integration, with MTTR as the operational measure of success.

Executed

Drove the remediation and adoption plan, connected NDR evidence to analyst workflows, and tracked the six-month outcome.

Cross-functional support: Customer SOC analysts and internal technical teams supported configuration, validation, and operational adoption.

The result

Fifteen hours removed from the response cycle

Mean time to respond fell from 24 hours to 9 hours in six months—a 63% improvement.

The improved telemetry, asset context, and workflow also prepared the SOC for AI-assisted detection by strengthening the underlying data and operating discipline.

63%

Faster mean time to respond

15h

Removed from the average response cycle

6 mo.

From baseline to measured result

What this case demonstrates

Customer success can change an operational metric when adoption work reaches beyond feature usage. The leverage came from connecting platform data, asset context, and the team’s real investigation process.

Customer name and sensitive implementation details are withheld. Results are drawn from my portfolio performance.

Ready to connect

Hiring an Enterprise CS Leader? Let’s talk.

I connect product adoption to the operating metrics that matter to customer leaders.