SOC Analyst · Lesson 7 of 8
Escalating with a clear handoff
An escalation should let the next responder understand the concern and continue the work. Distinguish recommended actions from actions already taken.
A handoff the next analyst can use
Illustrative incident ticket, with observations separated from unknowns.
- Scopejlee · session S17
Record the relevant source and UTC time window.
- ObservedSuspicious sign-in; export attempt failed
Attach approved event references.
- UnknownLegitimacy and wider session activity
Do not claim confirmed data theft.
- Next ownerAuthorized responder
Request review and a containment decision under the playbook.
Read the visualWhy include unknowns instead of writing a confident conclusion?
They prevent unsupported claims and tell the next responder which questions still need evidence.
Lead with scope
State the affected entities, relevant time window, and potential business impact.
Summarize evidence
Include observations, source references, and checks already performed. Identify missing information explicitly.
Assign the next decision
Explain what you recommend, who should act, and the urgency. Follow the team process for acknowledgment and ownership.
Put it in context
Your ticket states: account jlee, session S17, suspicious sign-in followed by an attempted export. Available logs record an export failure; broader session activity remains under review. You request responder review and approved containment consideration.
A handoff needs evidence, uncertainty, ownership, and a next step.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.