The metrics a SOC lives by

~25 min

(Quick review first: the job is a loop — detect, triage, investigate, respond, recover, learn — and triage is the high-volume decision that routes everything else.)

Why metrics matter to you

SOCs are measured, and those measurements shape your daily life — what you are pushed to optimise, what "good" looks like on your shift, and how the SOC is judged by the business that funds it. Understanding the metrics helps you understand the incentives acting on you, including the ones that quietly push you toward bad behaviour.

The core metrics

MTTD — Mean Time To Detect. Average time from an attack starting to the SOC noticing. The Beginners course called this dwell time, and it is the headline number. Lower is better; the whole point of detection is to shrink it. An attacker detected in an hour is an incident; the same attacker detected in six months is a catastrophe.

MTTR — Mean Time To Respond (or Resolve). Average time from detection to containment or resolution. Once you know, how fast do you act? Detecting fast and responding slowly still lets damage accumulate.

Alert volume and the true/false ratio. How many alerts, and how many are real. This ratio is the health of the SOC. Thousands of alerts that are 99% false is a SOC drowning — and a SOC drowning is a SOC that misses the real one in the flood.

Escalation rate. What fraction of alerts move up the tiers. Too high and Tier 1 is escalating things it should handle; too low and it may be closing things it should escalate.

Coverage. How much of your environment is actually monitored, and how much of the attack landscape — ATT&CK techniques — you can detect. The gaps in coverage are where attacks succeed unseen.

How metrics distort behaviour

Here is the part most courses skip, and the part that will actually affect your work: metrics change behaviour, and not always for the better. Knowing this makes you a more honest analyst and a harder one to mislead.

  • Optimising MTTR can push analysts to close alerts fast rather than correctly. If you are measured on speed, the temptation is to mark things resolved to keep the number down. A closed alert is not a solved problem — and a real attack closed quickly as "false positive" is the worst possible outcome, dressed up as good performance.
  • Chasing a low alert count can hide real problems. Tune too aggressively to reduce volume and you suppress real detections along with the noise. The metric improves while security gets worse.
  • Vanity metrics. "We processed 4 million events" sounds impressive and means nothing. Volume is not value; a number that only measures activity, not outcomes, is decoration.

The lesson: metrics are tools, not truth. They point roughly at things that matter, and they can be gamed, and optimising the number instead of the underlying reality is a classic and dangerous failure. A good analyst — and a good SOC manager — uses metrics to find problems, not to look good, and stays suspicious of any number that is improving for reasons nobody can quite explain.

The metric that should matter most

If forced to choose one honest measure: can the SOC reliably detect and respond to the attacks that actually matter, fast enough to limit the damage?

Everything else is a proxy for that, and every proxy can be gamed. Keep the real question in view — behind every dashboard number, "are we actually catching real attacks quickly?" — and you will not be fooled by a SOC that has excellent metrics and misses real intrusions, which is a genuine and embarrassing thing that happens.

Try it now

Reason about the incentives, because you will feel them:

  1. If you are measured mainly on closing alerts quickly, what bad habit does that encourage? What would you do to resist it?
  2. If your SOC is proud of a very low alert count, what should you check before being reassured?
  3. Which single metric would you most want to be judged on as an analyst, and which would you most distrust?

These are not abstract. You will work under metrics like these, and the pressure to make a number look good — at the cost of doing the job right — is one of the real hazards of the profession. Recognising it now is part of becoming trustworthy.

Sign in to track your progress.