Two alerts land in the queue on the same morning. Both show forty mentions of the same executive over the past week. One of them reached forty in six hours and was still climbing when the analyst opened it. The other accumulated slowly on a single forum across five weeks. A volume report renders both as the number forty, and a threshold rule ranks them the same way.
Now, counting is the default because it is easy to configure and easy to explain to a stakeholder, but the problem is that a conversation going from three posts to forty in six hours and a conversation going from three posts to forty over five weeks produce the same number in a volume report. The first one is mobilizing, while the second is background noise, but a threshold alert measure treats them as the same event.
Our CEO Jonathan Graff wrote about this compression recently in Security Executive, describing the pipeline from online commentary to coordinated real-world activity as dangerously short and arguing that velocity has replaced volume as the defining measurement. That framing is right at the program level. What follows is the operational version: what to instrument, what to baseline, and where the readings go wrong.
Velocity is a rate of change, which requires at least two observations and a clock. This then leads to four dimensions, which are all worth tracking separately, because they move independently and each one tells you something different about what is happening.
Amplification rate covers how fast a piece of content is spreading. Platform migration covers how many distinct environments it has reached. Actor growth covers whether new people are joining the conversation or the same small group is repeating itself. Specificity drift covers whether the language is moving toward operational detail.
The useful cases are the ones where these four readings disagree with each other. Amplification can sit flat while platform migration climbs, which usually means someone is deliberately seeding the content in new places rather than a crowd finding it on its own.
None of these measurements mean anything without a reference point. A doubling of mentions on a Tuesday afternoon is alarming until you learn that this particular executive gets a doubling of mentions every Tuesday afternoon because that is when the company publishes its standard commentary.
Pull 60 to 90 days of historical data for every monitored entity and record four things:
Most teams have this data sitting in their platform already and have never looked at it as a baseline. Risk trends and analysis tooling exists for exactly this kind of retrospective pass.
Baselines need to be built per entity rather than per program. A consumer-facing retail CEO might average a couple hundred mentions a day, most of them complaints about delayed orders and billing. A regional distribution center can go a month without being named anywhere. One threshold applied across both will bury the analyst in noise on the first and catch nothing on the second until an incident is already underway.
Remember to rebaseline quarterly, and rebaseline immediately after any event that permanently changes an entity's profile. Events such as an acquisition, a public controversy, a layoff announcement, or a leadership change.
How many hours it takes for mentions of a monitored entity to double against its own baseline. This is the single most useful number a GSOC can produce, and it can be calculated from any threat monitoring export.
The number of distinct platforms a narrative has appeared on within a rolling 24-hour window. Content that jumps from a fringe forum to a mainstream social platform has typically picked up an amplifier somewhere, and identifying that amplifier should be treated as a priority.
Rising volume driven by new unique accounts indicates genuine spread. Rising volume driven by the same accounts reposting indicates a small group with a potential fixation, and it is worth looking at. Nonetheless, Identity resolution work separates these two cases quickly, and they warrant very different responses.
Track whether language is moving from general hostility toward references to times, locations, schedules, or methods. Keyword rules catch very little of this, because the shift usually happens in phrasing built from ordinary words. Put it on a scheduled review with a named analyst.
Measurement without a pre-agreed response is just a nicer dashboard. Map velocity readings to specific tiers, and decide what each tier authorizes before anyone is under pressure.
A workable structure looks something like this:
The thresholds themselves matter less than the fact that they were agreed to in advance, in writing, with legal and communications in the room.
Coordinated inauthentic amplification produces beautiful velocity curves and often represents very little real-world capability. Verify actor authenticity before escalating on rate alone.
A single high-follower account can generate a spike that resembles organic mobilization and then evaporates within a day. Look at the second derivative, meaning whether the rate itself is still climbing after the initial burst.
News cycle contamination is the most common false reading in practice. When a company name appears in unrelated national coverage, entity mentions spike across every platform at once, and simple keyword monitoring cannot tell the difference between a trending business story and a targeting campaign.
Automated stance scoring also performs poorly on adversarial and politically charged content. Manual classification on a sample of the spike remains the reliable method for determining whether rising volume reflects hostility or ordinary attention.
None of this requires a program to be stood up first. Pick the principal with the highest risk profile, pull 60 days of history, and work out two numbers: the median daily mention count and how long a normal spike takes to double. Write them somewhere the on-shift analyst will actually see them, like the shift handover doc or the top of the monitoring runbook.
Once those two numbers exist for one principal, the same pass takes about an hour per additional entity, and the tiering and drift reviews have something to sit on top of.