Ridgeline Grid's SOC mоnitоrs twо different things аbout а substаtion's SCADA gateway: how well it holds up if an actual intrusion attempt is under way right now, and how well it identifies known vulnerable configurations before anyone has attempted to exploit them. A junior analyst calls both of these "Threat Tolerance." A senior analyst says only one of them is. Which one, and why?