Summary
Mistakes regarding implementation and detection are bound to happen; not only have they already occurred but they will continue. The key is to learn from those mistakes, and you can then use that to be more prepared for the next implementation or learn to be more efficient when creating detections. You also shouldn’t be ashamed to talk about failed projects because you can use that to get feedback and helpful suggestions from other industry professionals. Many times in my career, I’ll talk through a particularly tough task and use my network to help talk through ideas.
In the next chapter, we’ll discuss the alerts that, in my experience, have provided the most value. We’ll also talk through ways to measure the efficacy of alerts and set up feedback loops to identify what alerts need to be improved.