No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC
ID: 08e0ccf9-cb31-5921-970f-e9993bf6b0e4
STIX ID: report--08e0ccf9-cb31-5921-970f-e9993bf6b0e4
Feed Name: Infosecurity Magazine (News)
The NCSC warns that common SOC metrics (ticket counts, time-to-close, volume of rules/logs) can incentivize poor behaviour; instead the only meaningful outward metric is time-to-detect/time-to-respond (TTD/TTR). The guidance recommends red/purple teaming to assess TTD/TTR and suggests internal metrics such as hypothesis-led hunting, maximizing true positives, analyst training and job satisfaction, and log coverage to improve SOC performance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
