Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Operation Endgame Takes Down StealC and Amadey Infostealers

June 25, 2026

145 Mastra npm Packages Compromised via Hijacked Contributor Account

June 25, 2026

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC
News

No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC

Team-CWDBy Team-CWDApril 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Many of the most common metrics used to measure the effectiveness of the security operations center (SOC) are at best inaccurate and at worst actively harm SecOps teams, the National Cyber Security Centre (NCSC) has warned.

The NCSC’s CTO for architecture, Dave Chismon, wrote in a blog post that organizations often gravitate to measurements that can be easily expressed numerically to individuals who aren’t security specialists.

However, if “number of tickets processed” or “time taken to close a ticket” are used as metrics, staff may perversely be incentivized to rapidly triage and close them as false positives rather than investigate.

Similarly, “number of detection rules” may incentivize analysts to write as many rules as possible, driving up the number of false positives and ineffective rules.

In the same way, focusing on volume of logs collected over the value of those logs is self-defeating if they don’t improve detection, Chismon said.

Read more on SecOps: NCSC Shares Alternatives to Using a SOC

According to the NCSC, the only SOC metric that matters is: “does it detect (and respond to) attacks in a timely manner?” In other words, time to detect/time to respond (TTD/TTR).

Chismon recommended using red/purple teaming to allow assessment of a SOC’s TTD/TTR.

“Whilst TTD/TTR are the only reportable metrics that demonstrate a SOC is working, a SOC manager is likely to want to track a number of other metrics to help them monitor the week-by-week health of their service,” he continued.

“These metrics could include things like numbers of tickets, but crucially, those metrics should not be reported outwards (or arguably inwards, to the SOC analysts) lest they drive the wrong activities.”

How to Boost Threat Detection

To reduce TTD/TTR in the SOC, analysts must understand both the threat landscape and what they’re protecting, be experts in the tools they’re using, have the right data to spot unusual behavior and have time to hunt for threats.

Chismon recommended several approaches to build on:

  • Hypothesis-led hunting, where analysts hypothesize about likely attacks based on their understanding of threat actors and their techniques, and then search for evidence in logs
  • Maximal true positives/minimal false positives, where SOCs “maintain hard thresholds for false positive rates” when they’re evaluating whether a detection rule is suitable or not
  • Metrics based around analyst awareness of threats such as completeness of documentation about a threat actor, or training reports read and actioned
  • Tracking analyst expertise in tooling through training and certifications
  • Tracking SOC engagement with the wider organization to spot and flag suspicious activity
  • Analyst job satisfaction, which should be high if they are “learning about attackers, understanding techniques, applying it to data, and working with people across an organization”
  • Log coverage: tracking the percentage of relevant assets that are reporting the right logs can help to reduce blind spots

“With the wrong metrics, a SOC is ineffective and the job is miserable, with analysts describing themselves as ‘ticket monkeys’ measured on clicking ‘false positives’ as quickly as possible, whilst being shamed for missing real attacks,” Chismon concluded.

“If you’re worried your SOC might be falling into this trap, a red or purple team from a credible vendor will give you proof either way.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhy Most AI Deployments Stall After the Demo
Next Article ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Team-CWD
  • Website

Related Posts

News

Operation Endgame Takes Down StealC and Amadey Infostealers

June 25, 2026
News

145 Mastra npm Packages Compromised via Hijacked Contributor Account

June 25, 2026
News

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Watch out for SVG files booby-trapped with malware

September 22, 2025

Children and chatbots: What parents should know

January 23, 2026

What is it, and how do I get it off my device?

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.