Skip to main content
Image coming soon

The Security Engineering Manager's Detection Coverage Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Security Engineering Manager's Detection Coverage Playbook

Turn a sprawl of detections, alerts, and on-call pages into a measured coverage map your CISO and product engineering both trust.

Your detection coverage is real, and growing. Proving it to your CISO, to product engineering, and to your own on-call rotation in one consistent map is the part nobody has staffed.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Security engineering managers carry three audiences that ask the same question in incompatible shapes. The CISO wants coverage by threat category for the board. Product engineering wants coverage by service so they know where they still owe you instrumentation. The on-call rotation wants the alerts they actually triage to show up on a map, ranked by signal versus noise. Each audience gets its own slide, the slides disagree at the edges, and the next quarter starts with the same reconciliation work nobody has time for. The fix is one coverage artefact that answers all three views from the same underlying data, and a review cadence that updates it without rewriting it.

What you walk away with

  • A coverage map that names every product surface, every detection, and every gap, refreshed on a known cadence.
  • A detection-to-technique mapping that survives product renames and service splits.
  • A gap-ranking method weighted by on-call pager volume, not hypothetical risk.
  • A quarterly review format the CISO, product engineering, and on-call all read from the same artefact.
  • Runbook and detection updates closing the top-ranked gaps within one quarter.

The 12 modules

Module 1. The three audiences and the one coverage artefact
Why CISO, product engineering, and on-call read coverage differently, and why three slides drift apart by the next quarter. Frames the single map that answers all three views from the same data. Sets the design constraint that everything else in the course satisfies: one artefact, three readable cross-sections, refreshed on a cadence the team can actually sustain.
Module 2. Inventorying product surfaces a SecEng manager actually owns
How to enumerate the surfaces under detection responsibility without inheriting every service in the company. Covers the boundary call between SecEng coverage and AppSec coverage, the treatment of shared platform services, the handling of vendor-managed surfaces, and the labelling scheme that lets the inventory be queried by product, by team, and by data sensitivity from the same table.
Module 3. Detection-to-technique mapping that survives service renames
Mapping the detections you own against the technique catalogue you align to (MITRE ATT&CK in practice for most SecEng teams). The trick is decoupling the mapping from service names that change quarterly. Covers stable identifiers, mapping drift detection, and how to write the mapping so a service split next quarter doesn't invalidate six months of coverage history.
Module 4. Gap discovery from pager data, not threat models
Why the gap list ranked by hypothetical risk is the one nobody acts on. Walks through extracting the real on-call pager volume by surface, by technique, and by time-of-day, then using that as the primary input to gap ranking. Covers the secondary inputs (red team findings, incident retros, customer-reported events) and how to weight them without letting any one source dominate.
Module 5. Coverage scoring without a fake confidence number
The temptation is a single percentage. The trap is that the percentage is wrong and everyone knows it. Covers the multi-dimensional scoring approach that names what is covered, what is partially covered, what is uncovered, and what is uncoverable with current tooling. Includes the rubric for moving a detection between states and the audit trail for state changes.
Module 6. The CISO cross-section of the coverage map
How the same underlying data renders as a threat-category view for the quarterly CISO review. Covers the aggregation that holds up under board scrutiny, the trend lines that show the work the team has done this quarter, the gaps that are escalations rather than ranked-and-deferred, and the language that distinguishes a real coverage improvement from a tooling change.
Module 7. The product engineering cross-section
The same data rendered as a service-owner view for the engineering org. Covers the per-service coverage badge, the instrumentation requests that go on the product backlog, the SLA you offer product engineering in return for that instrumentation, and the escalation path when a product team has been carrying an uninstrumented surface for too long.
Module 8. The on-call cross-section and the noise budget
Coverage that the on-call rotation can read in their own terms: what alerts are real, what alerts are noise, what techniques the team should expect to see on a Tuesday afternoon. Covers the noise budget per surface, the tuning loop that draws from the on-call retro, and the rule that no new detection ships without an owner for its noise.
Module 9. Closing the top-ranked gaps without expanding the runbook past sustainability
A coverage gap closed by a detection that nobody can triage is not closed. Covers the sequencing of gap closures with runbook updates, the headcount math that decides whether a gap is closeable this quarter, and the cases where the right move is buying a managed detection instead of building one.
Module 10. The detection portfolio review cadence
The cadence that keeps the map current without devouring an engineer-week per cycle. Covers the weekly drift check, the monthly mapping refresh, the quarterly portfolio review, and the annual surface inventory. Includes the meeting format for each, the artefact each produces, and the rule for when a cadence escalates to an exception review.
Module 11. Communicating coverage upward and outward
How the coverage map renders for the board pack, for the customer trust page, for the SOC 2 auditor, and for the product engineering org-wide all-hands. Covers the four register-shifts the same data has to support, the framing that does not over-promise, and the failure modes of each audience (the board number that becomes a target, the auditor number that becomes a finding, the engineering number that becomes a competition).
Module 12. The 90-day rollout for a SecEng manager inheriting the role
A day-by-day plan for a SecEng manager either new to the role or new to running the coverage view. Covers the first-month conversations with the CISO and the on-call leads, the second-month inventory and mapping sprint, the third-month first published coverage map, and the artefacts to put on the shared drive so the next manager inherits the system rather than rebuilding it.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Quarterly CISO review where the coverage slide gets rebuilt from scratch every cycle.
Product engineering planning meeting where a service team asks what they owe security and nobody can answer cleanly.
On-call retro where the team realises the alerts that paged this quarter were not the ones the coverage map said were the priority.
Auditor walkthrough where the SOC 2 control about detection coverage needs an artefact that matches the operational reality.

What you get with this course

  • Twelve written modules with worked examples drawn from a SecEng manager's portfolio.
  • Downloadable surface-inventory template with the labelling scheme pre-populated.
  • Detection-to-technique mapping template with drift-detection columns.
  • Gap-ranking spreadsheet driven by on-call pager volume inputs.
  • Quarterly portfolio review meeting format and slide skeleton.
  • 90-day rollout plan for a new or newly-accountable SecEng manager.
  • The hand-built implementation playbook tuned to the buyer's specific product surfaces and detection stack.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Modules 1 through 4 are designed for the first week, framing the artefact and inventorying surfaces.

Modules 5 through 8 are designed for weeks two and three, building the scoring, the cross-sections, and the on-call view.

Modules 9 through 12 are designed for the final week, covering gap closure, review cadence, communication, and the 90-day rollout.

Before and after

Before

Three slides that disagree at the edges, a coverage percentage nobody trusts, a gap list ranked by threat-model risk that the on-call team has never seen page, and a quarterly review that starts with two days of reconciliation work.

After

One coverage artefact that renders cleanly for the CISO, for product engineering, and for the on-call rotation. Gaps ranked by what actually pages. A quarterly review that updates the map rather than rebuilding it. A rollout plan a successor can pick up.

What happens if you do not address this

The reconciliation tax compounds. Each quarter, the three coverage views drift further apart, the CISO loses confidence in the number, product engineering treats the SecEng asks as unprioritised, and the on-call team carries the noise that nobody has time to tune. The seat the SecEng manager occupies becomes the seat that owns the slide nobody believes.

Who it is for

A Security Engineering Manager running a detection-and-response or platform-security team, responsible for the detection portfolio across multiple product surfaces, owning the on-call rotation and the quarterly review with the CISO, and accountable for the coverage story product engineering uses to plan their own security work.

Who this is NOT for. Individual contributor detection engineers who write rules but do not own the portfolio view. Application security managers whose primary surface is code review and SDLC rather than runtime detection. CISOs and Heads of Security looking for a board-level narrative without operational depth.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly four to six hours of reading across the twelve modules, plus three to five hours applying the templates to your own surfaces. Most managers complete a first-pass coverage map within two weeks.

Why $199 is the right number

Open-source ATT&CK navigator gives you the technique catalogue but no portfolio view, no audience cross-sections, and no review cadence. Vendor coverage dashboards give you a number per their product but stop at their product boundary. Internal wikis go stale within a quarter. This course is the operating system around any of those tools: it tells the SecEng manager how to make a coverage artefact that survives audiences, time, and team handover.

FAQ

We are mostly cloud-native and run our own detection-as-code repo. Does this still apply?
Yes. The course is tool-agnostic. The detection-as-code repo is one of the inputs to the mapping; the course handles the layer above it (the portfolio view, the audience cross-sections, the review cadence) that the repo does not.
Our SOC is partly outsourced to an MDR. Does the coverage artefact still work?
Yes, and the course covers the MDR boundary explicitly. The surface inventory marks MDR-managed surfaces, the gap-ranking weights them against the MDR's reported coverage, and the quarterly review includes the MDR's report as one of the inputs.
How does the implementation playbook get tailored to our stack?
After purchase you share your product surface list and detection tooling at a high level. The playbook is hand-built against that context within roughly 48 hours and delivered alongside course access. No code or detection content is requested; surface descriptors and tool categories are sufficient.
We already use MITRE ATT&CK heavily. Does this overlap?
It builds on it. ATT&CK is the technique catalogue the mapping aligns to. The course is about the layer above: keeping the mapping current, ranking gaps by pager reality not technique prevalence, and rendering the result for three different audiences from one artefact.
Refunds?
Thirty days, no questions, full refund.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.