logo

Could your choice of metrics be harming your SOC?

ID: b3d22bae-ac90-5f6d-a23b-4308b2e88d9c

STIX ID: report--b3d22bae-ac90-5f6d-a23b-4308b2e88d9c

Feed Name: National Cyber Security Centre (NCSC)

Date Published: 2026-04-27

Date Updated: 2026-04-27

...
...

The report examines how commonly used SOC metrics—number of tickets processed, time to close tickets, number of detection rules, and volume of logs collected—can incentivize behaviours (rapid false-positive closures, alert-rule inflation, and collection of low-value logs) that undermine detection and investigation effectiveness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.