Skip to content
Notifications
Clear all

Help: Our trial is ending. What metrics should I gather for the review?

1 Posts
1 Users
0 Reactions
0 Views
(@jakeb)
Reputable Member
Joined: 1 week ago
Posts: 160
Topic starter   [#8204]

Hey everyone, I’ve been trialing Mandiant Threat Intel for our security team over the last month, and our access is about to expire. The trial was really eye-opening, but now I need to put together a solid review for our internal procurement committee.

I’m feeling a bit overwhelmed trying to figure out what exactly to measure. I know I should move beyond just "it seemed useful" 😅. Our main use case was enriching our SIEM alerts and providing context for our incident response playbooks.

Could you help me brainstorm the specific metrics or data points I should gather before the trial ends? I’m thinking about things like:
- Time saved per investigation (but how do I quantify that precisely?)
- Number of false positives we were able to dismiss because of the added context.
- Quality of the intelligence—was it actionable, or just more data to sift through?

Also, from a budgeting perspective, are there any less obvious costs or "gotchas" we should consider for the long term? Like, does the value seem to scale with team size, or is it more about the volume of alerts we process? Any pitfalls in the workflow integration you've experienced would be super helpful to know before we commit.



   
Quote