Contents
Build the Baseline Before You Need It
None of these measurements mean anything without a reference point. A doubling of mentions on a Tuesday afternoon is alarming until you learn that this particular executive gets a doubling of mentions every Tuesday afternoon because that is when the company publishes its standard commentary.
Pull 60 to 90 days of historical data for every monitored entity and record four things:
Most teams have this data sitting in their platform already and have never looked at it as a baseline. Risk trends and analysis tooling exists for exactly this kind of retrospective pass.
Baselines need to be built per entity rather than per program. A consumer-facing retail CEO might average a couple hundred mentions a day, most of them complaints about delayed orders and billing. A regional distribution center can go a month without being named anywhere. One threshold applied across both will bury the analyst in noise on the first and catch nothing on the second until an incident is already underway.
Remember to rebaseline quarterly, and rebaseline immediately after any event that permanently changes an entity's profile. Events such as an acquisition, a public controversy, a layoff announcement, or a leadership change.
Four Signals Worth Instrumenting
Doubling Time
How many hours it takes for mentions of a monitored entity to double against its own baseline. This is the single most useful number a GSOC can produce, and it can be calculated from any threat monitoring export.
Platform Migration Count
The number of distinct platforms a narrative has appeared on within a rolling 24-hour window. Content that jumps from a fringe forum to a mainstream social platform has typically picked up an amplifier somewhere, and identifying that amplifier should be treated as a priority.
Unique Actor Growth Against Repost Ratio
Rising volume driven by new unique accounts indicates genuine spread. Rising volume driven by the same accounts reposting indicates a small group with a potential fixation, and it is worth looking at. Nonetheless, Identity resolution work separates these two cases quickly, and they warrant very different responses.
Specificity Drift
Track whether language is moving from general hostility toward references to times, locations, schedules, or methods. Keyword rules catch very little of this, because the shift usually happens in phrasing built from ordinary words. Put it on a scheduled review with a named analyst.
Map Velocity Readings to Response Tiers
Measurement without a pre-agreed response is just a nicer dashboard. Map velocity readings to specific tiers, and decide what each tier authorizes before anyone is under pressure.
A workable structure looks something like this:
The thresholds themselves matter less than the fact that they were agreed to in advance, in writing, with legal and communications in the room.
Where Velocity Readings Mislead
Coordinated inauthentic amplification produces beautiful velocity curves and often represents very little real-world capability. Verify actor authenticity before escalating on rate alone.
A single high-follower account can generate a spike that resembles organic mobilization and then evaporates within a day. Look at the second derivative, meaning whether the rate itself is still climbing after the initial burst.
News cycle contamination is the most common false reading in practice. When a company name appears in unrelated national coverage, entity mentions spike across every platform at once, and simple keyword monitoring cannot tell the difference between a trending business story and a targeting campaign.
Automated stance scoring also performs poorly on adversarial and politically charged content. Manual classification on a sample of the spike remains the reliable method for determining whether rising volume reflects hostility or ordinary attention.
Starting Small
None of this requires a program to be stood up first. Pick the principal with the highest risk profile, pull 60 days of history, and work out two numbers: the median daily mention count and how long a normal spike takes to double. Write them somewhere the on-shift analyst will actually see them, like the shift handover doc or the top of the monitoring runbook.
Once those two numbers exist for one principal, the same pass takes about an hour per additional entity, and the tiering and drift reviews have something to sit on top of.