Back to Field Notes
Security Operations/Field Note

SOC Metrics That Mean Something — A Short List

Number of alerts is not a metric. Number of investigations per analyst per shift is closer. The honest list is shorter than expected.

Author

Aisha Khan

Director, Threat Intelligence

Published

April 5, 2026

Read

8 min

Share
AI-generated illustration of a power grid substation
AI-generated illustration of a power grid substation
Key Takeaways
  • 01Most SOC dashboards report activity. Activity is easy to game. The metrics that actually correlate with security outcomes are smaller in number and harder to manipulate.
  • 02Honest short list: MTTD (for tested attack scenarios with current detection content), MTTR (detection to confirmed containment), coverage (% of relevant ATT&CK techniques with confirmed detection), false-positive rate by detection with trend, analyst case load (open cases per analyst per day with quality flag), detection content age (last-modified distribution).
  • 03What to avoid reporting: total alerts (incentivizes noise), total cases closed (incentivizes superficial closure), total rules (incentivizes proliferation). Each is an activity count that, in isolation, encourages the wrong behavior.
  • 04Cadence and audience: operational metrics weekly to the SOC manager, outcome metrics monthly to the CISO, strategic metrics quarterly to the board. Different audiences, different abstraction, same underlying data — that is the discipline.

Most SOC dashboards report activity. Activity is easy to game. The metrics that actually correlate with security outcomes are smaller in number and harder to manipulate.

The honest short list

  • 01Mean Time to Detect — for tested attack scenarios, with current detection content
  • 02Mean Time to Respond — from detection to confirmed containment
  • 03Coverage — percentage of relevant ATT&CK techniques with confirmed detection
  • 04False positive rate — by detection, with trend
  • 05Analyst case load — open cases per analyst per day, with quality flag
  • 06Detection content age — distribution of last-modified dates across active rules

What to avoid reporting

Total alerts (incentivizes noise). Total cases closed (incentivizes superficial closure). Total rules (incentivizes proliferation). Each of these is an activity count that, in isolation, encourages the wrong behavior.

Cadence and audience

Operational metrics weekly, to the SOC manager. Outcome metrics monthly, to the CISO. Strategic metrics quarterly, to the board. Different audiences, different levels of abstraction, same underlying data — that is the discipline.

#Metrics#SOC#Reporting

/WRITTEN_BY

Aisha Khan

Director, Threat Intelligence · Alexa Cybersecurity