Skip to main content
Image coming soon

The AVP Threat Management Operating Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The AVP Threat Management Operating Playbook

How an AVP of Threat Management runs detect, hunt, respond, and report so the audit committee, the CISO, and the SOC see the same picture.

The audit committee opens the threat-management page first. It reads detections closed, mean time to contain, top unresolved exposure, and the trendline. Everything you do upstream has to roll into that one page, every quarter, without smoothing.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

An Associate Vice President of Threat Management sits between the SOC floor and the executive room. The SOC has alerts, hunts, tickets, and shift handovers. The executive room has a single page with four numbers and a trend arrow. Between those two layers sit detection coverage decisions, hunt programme priorities, IR runbook quality, threat-intel-to-control pipelines, vendor red-team scopes, and the headcount-versus-coverage tradeoffs you defend in budget season. Most operating models collapse one of those layers into the other. They either drown the executive in SOC noise, or they sanitise the SOC reality until the executive page no longer reflects what the analysts are actually seeing. The playbook keeps both layers honest. Detection engineering driven by adversary tradecraft your sector actually faces, mapped to ATT&CK, with the gap log that becomes next quarter's roadmap. Hunt programme with hypothesis-driven sprints, a findings register that names the threats, and a feedback loop into detection. IR runbooks that survive the worst-case call, including legal hold, regulator notification, customer comms, and post-incident learning. Threat intel ingestion with named owners and SLAs from indicator to control change. And one scorecard that compresses all of it into the page the audit committee reads first.

What you walk away with

  • Run detection engineering against ATT&CK with a published coverage map, a quarterly gap log, and an owned roadmap that survives a budget review.
  • Stand up a hunt programme with hypothesis-driven sprints, a findings register, and a closed feedback loop from hunt findings into detection content.
  • Maintain IR runbooks that hold up at 11pm on a Sunday, including legal, comms, regulator notification, and the post-incident learning loop.
  • Convert threat intel from PDFs into ticketed control changes with named owners and an indicator-to-action SLA you can defend.
  • Produce the one-page threat-management scorecard the audit committee opens first, with numbers that match what the analysts on the floor see.

The 12 modules

Module 1. The AVP operating model: SOC floor to audit committee
Map the layers you sit between. SOC analysts, shift leads, SOC manager, threat intel lead, IR commander, vendor MSSP, CISO, audit committee. Define what each layer needs from you and what you need from each, in plain language. Build the operating model diagram, the meeting cadence, and the escalation map. Run the diagnostic that finds where your current operating model leaks information up or sanitises information down.
Module 2. Adversary tradecraft for your sector, mapped to ATT&CK
Identify the threat actors who actually target your sector and your stack. Walk MITRE ATT&CK technique by technique against the tradecraft those actors use. Produce the prioritised technique list that drives detection engineering for the next two quarters. Includes the worked example of how to defend that prioritisation when finance asks why you are not buying the shiny vendor pitch instead.
Module 3. Detection engineering with a public coverage map
Build the detection coverage map the CISO actually reads. Detections per technique, alert volume per detection, false positive rate, time to triage, tuning backlog. Walk the engineering workflow from technique selection through detection authoring, testing in a purple team setup, deployment, and retirement. Output is the live coverage dashboard plus the quarterly gap log that drives roadmap.
Module 4. The hunt programme: hypothesis sprints and the findings register
Stand up the hunt programme as a real discipline rather than analysts with spare time. Hypothesis selection from threat intel and detection gaps, two-week hunt sprints with named hunters and named hypotheses, findings register that captures what was hunted, what was found, and what was promoted into detection content. Includes the metrics the CISO will ask for and the ones to refuse to commit to.
Module 5. Threat intel ingestion that ends in control changes
Build the intel-to-action pipeline. Sources, named owners, indicator-to-action SLAs, the ticket queue, the proof that an indicator made it into a detection or a control. Most threat intel programmes end at the PDF. This module ends at the change ticket with the closing date. Worked example covers commercial feeds, ISAC feeds, government advisories, and the in-house findings that feed back from hunt and IR.
Module 6. IR runbooks that hold up at 11pm on a Sunday
Write IR runbooks the on-call analyst can run without you on the bridge. Initial triage, containment decisions, evidence preservation, legal hold, regulator notification deadlines for your jurisdictions, customer comms templates, executive briefing cadence. Includes the post-incident review template that drives lessons into detection, hunt, and process change, not into a shelf-bound PDF.
Module 7. Tabletop exercises the board actually attends
Design tabletops that surface the executive-level decisions, not the SOC mechanics. Scenario selection driven by your top adversary techniques and your sector regulator's expectations, scripting the legal and comms branches, running the exercise so the CFO and the General Counsel say things on the record, and turning the after-action report into committed remediation owners. The output is a board-attended tabletop that converts into funded work.
Module 8. Vendor red team scopes that produce useful findings
Scope and run external red team engagements that produce findings your programme can actually action. Pick objectives over a generic scope, set the rules of engagement, define what counts as a finding worth a remediation ticket, and structure the debrief so it lands with the CISO and the audit committee rather than the engineer in the corner. Includes the debrief deck pattern and the remediation tracker template.
Module 9. Headcount, coverage, and the budget conversation
Defend headcount against the recurring CFO question of why the team cannot just buy a tool. Build the coverage-versus-cost picture that maps analyst hours to detection coverage, hunt cadence, and IR readiness. Walk the budget cycle from the August prep through the November defence to the January reset. Output is the budget pack the CFO and the CISO both sign off, with named tradeoffs.
Module 10. Working with the MSSP, the IR retainer, and the customer SOC
Most threat programmes run with at least one external partner. Define the boundary between your team and the MSSP, the IR retainer, and any customer or subsidiary SOC. Write the joint runbooks, the joint detection roadmap, and the joint metrics. Cover the contractual SLAs, the escalation paths, and the quarterly partner review that catches drift before the audit committee does.
Module 11. Regulator and audit conversations: walking them through the programme
Run the conversation with your sector regulator and your external auditor so they leave with confidence rather than questions. Pre-read pack, the live walk-through of the operating model, the evidence binder that maps to their framework, the answers to the standard probing questions, and the follow-up letter that closes out commitments. Includes worked examples for financial-services, healthcare, and critical-infrastructure regulators.
Module 12. The one-page audit-committee scorecard and the quarterly cycle
Compress the whole programme onto one page. Detections closed, mean time to detect and to contain, top unresolved exposure, headline hunt findings, IR readiness, programme trend. Walk the quarterly cycle from data pull to page sign-off to committee presentation to post-meeting commitments. The output is the page you present this quarter, plus the calendar that produces the next three.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Quarter close, audit committee in three weeks: modules 12 and 11 produce the scorecard and the regulator-ready evidence binder.
Detection coverage is a tooling list rather than a programme: modules 2 through 5 rebuild detection, hunt, and intel as one operating system.
Last incident exposed a runbook gap and a comms gap: modules 6 and 7 rebuild IR and tabletop with the board in the room.
Budget defence in two months and the CFO is pushing for tooling over headcount: modules 9 and 10 give you the coverage-versus-cost picture and the partner boundary that lets the headcount conversation land.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, sequenced from operating model through to the audit-committee scorecard.
  • Downloadable templates and worked examples for every module, including the detection coverage map, the hunt findings register, the IR runbook pack, the tabletop pre-read and after-action, the budget defence pack, and the audit-committee scorecard.
  • Hand-built implementation playbook tailored to your team's stack, reporting line, sector regulator, and committee cadence, delivered alongside course access.
  • Thirty-day refund window.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: learning-environment account provisioned, all twelve written modules available, downloadable templates and worked examples ready, hand-built implementation playbook delivered alongside course access.

Weeks one to two: work through modules one through five to rebuild the operating model and the detection-hunt-intel core.

Weeks three to four: work through modules six through ten to rebuild IR, tabletop, vendor scopes, budget defence, and partner boundaries.

Weeks five to six: work through modules eleven and twelve to land the regulator walk-through and the audit-committee scorecard, in time for the next committee cycle.

Before and after

Before

Threat management runs as a SOC plus a hunt cell plus an IR retainer plus a stack of PDFs from intel feeds. Quarterly reporting is rebuilt from scratch each cycle. The audit committee leaves with questions you answer by email later. The CFO keeps proposing tools instead of analysts. Coverage against the adversary techniques that actually hit your sector is unknown.

After

Threat management runs as a single operating system with detection coverage, hunt cadence, intel-to-action, and IR readiness all rolled into one scorecard. The audit committee opens the page first and leaves with confidence. The budget conversation runs off a coverage-versus-cost picture rather than vendor pitches. The MSSP and the IR retainer run inside named boundaries. Adversary tradecraft maps to live detections you can name.

What happens if you do not address this

Skip the operating model work and the next post-incident review surfaces a runbook gap in front of the General Counsel and the regulator. Skip the coverage map and the next budget cycle hands headcount to a tool the CFO chose without you. Skip the scorecard and the audit committee starts asking why the threat page is different every quarter. None of those are tail risks. They are the predictable consequence of running a threat programme without an operating model the AVP layer owns.

Who it is for

Associate Vice Presidents and senior directors who own threat management for a regulated enterprise. You report to the CISO or the CSO. You have a SOC manager and a threat intel lead beneath you. You sit on the IR bridge. You present quarterly to the audit committee, the risk committee, or both. Your headcount is somewhere between 15 and 80 analysts and engineers. You are the one who has to translate adversary reality into a board-readable number, and a board-readable number into where the next analyst goes.

Who this is NOT for. Not for SOC analysts looking for tooling tutorials, not for CISOs looking for a strategic posture document, not for sales engineers writing customer security narratives. The level is mid-management running a threat programme, not the SOC floor and not the C-suite.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly thirty to forty hours total over four to six weeks, split between the modules and the templates. Most takers work it as two evening sessions a week plus one weekend pass.

Why $199 is the right number

Open-source frameworks like ATT&CK, D3FEND, and NIST 800-61 give you the vocabulary but not the operating model. Vendor playbooks give you their product workflow, not your programme. SANS courses train the SOC analyst. Big consulting engagements rebuild the function from outside, slowly, at a price that competes with two analyst salaries. This playbook sits in the gap. It is the AVP-level operating model with the templates already drafted, priced so it does not need a budget approval cycle.

FAQ

I already use ATT&CK for coverage. What does this add?
ATT&CK gives you the techniques. The playbook gives you the operating model that turns a technique list into a detection roadmap, a hunt programme, an intel pipeline, an IR runbook set, and a scorecard. Most teams using ATT&CK are using it as a vocabulary, not as a programme spine.
Is this aligned to a specific sector regulator?
The implementation playbook is hand-built to your sector. Financial services, healthcare, critical infrastructure, energy, telco. Module eleven covers the regulator walk-through with worked examples across the major sector frameworks.
Will this work for a 15-analyst team and an 80-analyst team?
Yes. The operating model scales by named role rather than by headcount. The implementation playbook calibrates the cadence and the partner boundary to your size.
What if my SOC is run by an MSSP?
Module ten covers the MSSP boundary specifically. Joint runbooks, joint detection roadmap, joint metrics, and the quarterly partner review.
Refund?
Thirty-day window, no questions asked.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.