Case Load Calculator
Compare incoming SOC case volume with investigative capacity, and see how fast the backlog grows or clears.
Inputs
Out of a 40-hour week; the rest goes to meetings, handover, training and documentation.
Capacity Utilisation
140.6%
Weekly Case Capacity
149.3cases/week
Cases per Analyst per Week
26.3cases
Weekly Surplus or Deficit
60.7cases/week
Negative means the backlog shrinks.
Weeks to Clear the Current Backlog
9,999.0weeks
Escalations per Week
25.2cases/week
Case Load Verdict
Over capacity — the backlog grows by 61 cases every week
Step by step
Values used
Cases opened per week = 210 cases/week; Investigating analysts = 8 analysts; Mean investigation hours per case = 1.50 hours/case; Investigative hours per analyst per week = 28 hours/week; Cases already open = 120 cases; Cases escalated to tier 2 or IR = 12 %
Case Load
Capacity (cases/week) = analysts × investigative hours per week ÷ hours per case. Utilisation = cases opened ÷ capacity.
Backlog burn-down
Weeks to clear backlog = open cases ÷ spare weekly capacity; when demand exceeds capacity the backlog never clears.
Capacity Utilisation
= 140.6
Weekly Case Capacity
= 149.3 cases/week
Cases per Analyst per Week
= 26.3 cases
Weekly Surplus or Deficit
= 60.7 cases/week
Weeks to Clear the Current Backlog
= 9,999.0 weeks
Escalations per Week
= 25.2 cases/week
How it works
The calculation is deliberately a queueing sanity check rather than a full model: if arrivals exceed service capacity, the backlog grows without limit, and no amount of process improvement changes that. Utilisation above roughly 90% also means normal variation alone will produce a permanent queue. A SOC running at 100% utilisation has no capacity for the one incident that matters, and the backlog figure is what turns 'we are busy' into a staffing decision a finance team can act on.
Formulas
Case Load
Capacity (cases/week) = analysts × investigative hours per week ÷ hours per case. Utilisation = cases opened ÷ capacity.
- investigative hours
- Hours per analyst genuinely available for casework, typically 26–30 of 40
- hours per case
- Mean end-to-end investigation effort
- utilisation
- Demand as a percentage of capacity
Backlog burn-down
Weeks to clear backlog = open cases ÷ spare weekly capacity; when demand exceeds capacity the backlog never clears.
- spare capacity
- Capacity remaining after the incoming queue is served
Frequently Asked Questions
How is Case Load calculated?
Capacity (cases/week) = analysts × investigative hours per week ÷ hours per case. Utilisation = cases opened ÷ capacity. The calculation is deliberately a queueing sanity check rather than a full model: if arrivals exceed service capacity, the backlog grows without limit, and no amount of process improvement changes that. Utilisation above roughly 90% also means normal variation alone will produce a permanent queue.
Why does Case Load matter?
A SOC running at 100% utilisation has no capacity for the one incident that matters, and the backlog figure is what turns 'we are busy' into a staffing decision a finance team can act on.
What values do I need to enter?
This calculator takes 6 inputs: Cases opened per week, Investigating analysts, Mean investigation hours per case, Investigative hours per analyst per week, Cases already open, Cases escalated to tier 2 or IR. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why not plan for 100% utilisation?
Because arrivals are bursty. Queueing behaviour means waiting time rises steeply as utilisation approaches capacity, so a team planned at 95% will have a persistent backlog even though the weekly averages balance. Target 70–85%.
What if the backlog never clears?
Then the fix is not process. Either reduce arrivals (tune detections, automate closure of benign categories) or add capacity. Deferring the decision converts the backlog into a permanent, silent detection gap.