A focused course, tailored for you
The Merchant-Surface Security Analyst Playbook
For the senior analyst whose alerts fire on storefront traffic, checkout sessions, and the third-party scripts merchants paste into themes.
Your detections fire on traffic that touches a merchant's storefront, their installed apps, and their checkout, and the runbook treats it like a single-tenant corporate incident. It is not. It is a multi-tenant commerce security problem and the scoping decisions are different every time.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Senior analysts on a commerce platform security team work in a queue that does not look like any other SOC queue. The detections mix platform-managed surfaces, merchant-installed third-party apps, storefront themes a developer edited last night, and checkout sessions that carry tokenised payment data the platform never sees in cleartext. Half the alerts resolve to a merchant configuration choice rather than a platform compromise. The other half need a containment decision in the next hour because Black Friday traffic does not pause. The standard playbooks the CISSP curriculum trained you on assume one organisation, one network boundary, and a corporate breach-notification template. None of that fits the actual job. What is missing is a structured way to triage merchant-tenant detections, scope incidents that cross the platform/merchant boundary, and write the post-incident note in a way that protects both the merchant relationship and the platform's public position.
What you walk away with
- Triage a merchant-tenant alert in under fifteen minutes with a documented scoping decision.
- Distinguish merchant-configuration alerts from platform-compromise alerts on the first pass.
- Run a storefront-script abuse hunt across the merchant fleet without false-positive flooding.
- Write a post-incident note that closes the loop with the merchant without naming them publicly.
- Hand off a BFCM-window detection backlog with a documented containment posture for each open item.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules with downloadable worksheets, runbook templates, and worked examples.
- The hand-built implementation playbook tailored to a multi-tenant commerce security operation.
- Hunt-query templates for storefront-script abuse and checkout-session anomalies.
- Comms templates for merchant notification, customer-facing breach notes, and PCI scope letters.
- Thirty-day money-back if the modules do not match the merchant-surface scope described above.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours: learning-environment account provisioned and the tailored implementation playbook delivered alongside it.
Week 1: modules 1 to 4 cover the merchant-tenant triage decision tree and the highest-volume hunt patterns.
Weeks 2 to 4: modules 5 to 9 cover sales-event readiness, payment-tokenisation scope, and the forensics and comms patterns.
Week 5 onward: modules 10 to 12 close the loop on PCI scope letters, merchant escalation graphs, and the post-incident write-up template.
Before and after
Every merchant-surface alert resolves to a long scoping conversation, the runbook does not fit, and the post-incident note takes a week to write because the redaction questions are answered fresh each time.
The triage decision tree fits the alert in fifteen minutes. The runbook scopes platform-versus-merchant on the first pass. The post-incident template handles redaction and drives a detection-rule change rather than a finger-point.
What happens if you do not address this
The next sales-event window will reproduce the same scoping friction, the same merchant-comms delay, and the same redaction debate. Each repetition trains the queue to deprioritise merchant-surface alerts, and the one that matters arrives during a freeze.
Who it is for
Senior security analyst on a multi-tenant commerce platform security team. Two to six years in detection and response, comfortable in SIEM and EDR consoles, recently added storefront and checkout telemetry to the alert pipeline. Triages detections that span platform infrastructure, merchant-installed apps, and storefront customisations. Owns the on-call rotation for merchant-surface alerts and writes the post-incident notes that go to merchant security contacts.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. About 90 minutes per module if read end-to-end. Most senior analysts use it as reference: open the module that matches the current alert, run the worksheet, ship the response.
Why $199 is the right number
Generalist SOC training assumes a single-tenant network and does not address the platform/merchant boundary. PCI-focused training answers the assessor question but not the detection question. Vendor breach-comms templates are written for a corporate IT incident and do not handle the case where the platform is technical author of a merchant's customer-facing note. This playbook is written for the specific operation: detections that fire on merchant traffic on a multi-tenant platform.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.