logo

No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC

ID: 08e0ccf9-cb31-5921-970f-e9993bf6b0e4

STIX ID: report--08e0ccf9-cb31-5921-970f-e9993bf6b0e4

Feed Name: Infosecurity Magazine (News)

Date Published: 2026-04-28

Date Updated: 2026-04-28

...
...

The NCSC warns that common SOC metrics (ticket counts, time-to-close, volume of rules/logs) can incentivize poor behaviour; instead the only meaningful outward metric is time-to-detect/time-to-respond (TTD/TTR). The guidance recommends red/purple teaming to assess TTD/TTR and suggests internal metrics such as hypothesis-led hunting, maximizing true positives, analyst training and job satisfaction, and log coverage to improve SOC performance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.