- Lack of critical data sources
- No culture of learning
- Poor relationships with IT teams
- Misaligned manager/analyst priorities
- Too much managerial capitulation to strong personalities
2/
I spoke to an analyst in a class recently, and I asked them: "When do you feel comfortable walking away from an alert and calling it a false positive?" 8/
Me: "But what if you can't do that?" 9/
It was that simple to them. And ya know what? They pretty consistently executed.
10/10