Supervisory Analytics Tool for SOC Assessment (SAT-SA)
National Technical Research Organisation (NTRO) · Miscellaneous · Software
A genuinely original framing that NTRO wants, but the whole demo rests on SOC data you synthesise — invest in making that data realistic and varied in ways you did not trivially hand-encode, or the tool just rediscovers your own assumptions.
What it actually is
The national infrastructure protection body assesses whether critical organisations' security operations centres are actually effective, by manually reviewing samples of their security alerts and case records — which does not scale. The ask is a tool that analyses SOC alert and case-management data to help supervisors spot which organisations need attention and which weaknesses to examine, without replacing human judgement.
What to build
A supervisory analytics tool that ingests SOC alert and case-management records and, rather than judging individual alerts, derives capability signals across the eight areas the description names — threat detection, investigation, escalation, incident response, security operations, governance, operational discipline and cyber resilience — computing indicators such as time-to-triage distributions, escalation completeness, case-closure discipline and unhandled-alert backlogs, then ranks entities needing supervisory attention, prioritises which alert samples a human examiner should review, and surfaces operational weaknesses, explicitly as decision support rather than automated judgement.
Smallest thing that wins the room
Load two organisations' SOC case datasets and show the tool ranking one as needing attention because its escalation-completion rate and case-closure discipline lag, then drilling into the specific sample of cases a human examiner should review to confirm the concern.
How crowded this one gets
A guess, projected from the 2025 statements — the last year where both the submission counts and the winners were published.
Quieter than 37% of the 226 · #142 of 226 by expected field
A normal-sized field. Your idea has to be good, not miraculous.
Why: defence, intelligence and space bodies drew small fields.
This is a guess, not a fact
Nobody has published 2026’s numbers yet. This is an analysed estimate from last year’s pattern, so please do not take it as the truth — check the live counter on the SIH portal before you decide anything. The range covers the middle half of likely outcomes, so one statement in two lands outside it. Entry closes at 500 ideas per statement, so no range goes past that — a statement that reaches the cap fills and shuts rather than drawing an unlimited crowd. The model reads only three things a team can see before choosing — software or hardware, the theme, and what kind of body posted it — and those explain about a quarter of the variation in last year’s field sizes (R² 0.25 on held-out statements). Trust the band more than the number, and the ordering more than either. It cannot see how good your idea is, which is the part that actually decides it.
The scores
The number is the shorthand. The line under it is the reason.
Acceptance potential
3/5The framing is genuinely original and NTRO clearly wants it, but the entire demonstration rests on synthetic SOC data you must construct convincingly, and if the synthetic organisations differ only in ways you deliberately encoded, the tool merely rediscovers your own assumptions.
Feasibility
3/5The analytics themselves are standard, but there is no public dataset of SOC alert and case-management records, so you must synthesise realistic SOC operational data across multiple organisations with plausible capability differences — and the quality of that synthetic data determines whether the tool demonstrates anything meaningful.
Innovation scope
4/5Deriving organisational capability signals from operational alert and case data — using the SOC's own workflow exhaust as evidence of its maturity — is a genuinely novel framing, and which indicators actually reveal capability weakness is entirely open.
Clarity
4/5The description is unusually precise about intent and boundaries — it names the eight capability areas to assess, states that individual alerts are evidence not the target, and explicitly lists what is out of scope — so you know exactly what to build and what not to.
Effort
HeavySynthesising realistic multi-organisation SOC data, deriving the capability indicators, and building the ranking and drill-down interface is focused work, with the data synthesis a substantial part.
Demo-ability
MediumThe rank-and-drill-down story is clear, but it runs on synthetic data you authored, so the demo shows the analytical approach rather than a finding from real SOC operations.
In its favour
- Green flag: The description is exceptionally precise about scope and boundaries, including an explicit out-of-scope list, so there is no ambiguity about what to build
- Green flag: Using a SOC's own workflow data as evidence of its capability is a genuinely novel and defensible framing
- Green flag: Positioning the tool as decision support rather than automated judgement matches the description exactly and avoids overreach
- Green flag: The niche supervisory-analytics nature guarantees an essentially empty field
Against it
- Red flag: No public SOC alert and case dataset exists, so you synthesise it, and the tool can only reveal the capability differences you built into that synthetic data
- Red flag: Deciding which indicators genuinely reflect capability weakness requires SOC operational expertise a student team likely lacks, so your indicators may not mean what you claim
- Red flag: The demo demonstrates the method on invented organisations rather than surfacing a real finding, which limits how convincing it can be
- Red flag: This is a specialist supervisory tool, so the value is legible mainly to an NCIIPC-type judge and lands flat with a general audience
What you will be writing
- SOC case/alert data modelling + synthesis
- Capability indicator engineering (MTTR, escalation rate, closure discipline)
- Anomaly / outlier ranking across entities
- Explainable scoring with drill-down
- React supervisory dashboard
- Sample prioritisation logic
- Security operations assessment
- Supervisory analytics
- Cyber resilience
Prior art to read before you start
SOC maturity assessment from operational data · capability indicator derivation · supervisory sample prioritisation
Analysed by Claude Opus. Every score above is a judgment call with its reasoning attached — kindly cross-check this against the official statement on the SIH portal before your team commits to it.