{"id":5235,"date":"2026-04-29T06:36:53","date_gmt":"2026-04-29T06:36:53","guid":{"rendered":"http:\/\/ft365.org\/index.php\/2026\/04\/29\/no-metrics-are-better-than-bad-metrics-in-the-soc-says-ncsc\/"},"modified":"2026-04-29T06:36:53","modified_gmt":"2026-04-29T06:36:53","slug":"no-metrics-are-better-than-bad-metrics-in-the-soc-says-ncsc","status":"publish","type":"post","link":"https:\/\/ft365.org\/index.php\/2026\/04\/29\/no-metrics-are-better-than-bad-metrics-in-the-soc-says-ncsc\/","title":{"rendered":"No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"http:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Many of the most common metrics used to measure the effectiveness of the security operations center (SOC) are at best inaccurate and at worst actively harm SecOps teams, the National Cyber Security Centre (NCSC) has warned.<\/p>\n<p>The NCSC\u2019s CTO for architecture, Dave Chismon, wrote in a blog post that organizations often gravitate to measurements that can be easily expressed numerically to individuals who aren\u2019t security specialists.<\/p>\n<p>However, if \u201cnumber of tickets processed\u201d or \u201ctime taken to close a ticket\u201d are used as metrics, staff may perversely be incentivized to rapidly triage and close them as false positives rather than investigate.<\/p>\n<p>Similarly, \u201cnumber of detection rules\u201d may incentivize analysts to write as many rules as possible, driving up the number of false positives and ineffective rules.<\/p>\n<p>In the same way, focusing on volume of logs collected over the value of those logs is self-defeating if they don\u2019t improve detection, Chismon said.<\/p>\n<p><em>Read more on SecOps: NCSC Shares Alternatives to Using a SOC<\/em><\/p>\n<p>According to the NCSC, the only SOC metric that matters is: \u201cdoes it detect (and respond to) attacks in a timely manner?\u201d In other words, time to detect\/time to respond (TTD\/TTR).<\/p>\n<p>Chismon recommended using red\/purple teaming to allow assessment of a SOC\u2019s TTD\/TTR.<\/p>\n<p>\u201cWhilst TTD\/TTR are the only reportable metrics that demonstrate a SOC is working, a SOC manager is likely to want to track a number of other metrics to help them monitor the week-by-week health of their service,\u201d he continued.<\/p>\n<p>\u201cThese metrics could include things like numbers of tickets, but crucially, those metrics should not be reported outwards (or arguably inwards, to the SOC analysts) lest they drive the wrong activities.\u201d<\/p>\n<h2><strong>How to Boost Threat Detection<\/strong><\/h2>\n<p>To reduce TTD\/TTR in the SOC, analysts must understand both the threat landscape and what they\u2019re protecting, be experts in the tools they\u2019re using, have the right data to spot unusual behavior\u00a0and have time to hunt for threats.<\/p>\n<p>Chismon recommended several approaches to build on:<\/p>\n<ul>\n<li>Hypothesis-led hunting, where analysts hypothesize about likely attacks based on their understanding of threat actors and their techniques, and then search for evidence in logs<\/li>\n<li>Maximal true positives\/minimal false positives, where SOCs \u201cmaintain hard thresholds for false positive rates\u201d when they\u2019re evaluating whether a detection rule is suitable or not<\/li>\n<li>Metrics based around analyst awareness of threats such as completeness of documentation about a threat actor, or training reports read and actioned<\/li>\n<li>Tracking analyst expertise in tooling through training and certifications<\/li>\n<li>Tracking SOC engagement with the wider organization to spot and flag suspicious activity<\/li>\n<li>Analyst job satisfaction, which should be high if they are \u201clearning about attackers, understanding techniques, applying it to data, and working with people across an organization\u201d<\/li>\n<li>Log coverage: tracking the percentage of relevant assets that are reporting the right logs can help to reduce blind spots<\/li>\n<\/ul>\n<p>\u201cWith the wrong metrics, a SOC is ineffective and the job is miserable, with analysts describing themselves as \u2018ticket monkeys\u2019 measured on clicking &#8216;false positives&#8217; as quickly as possible, whilst being shamed for missing real attacks,\u201d Chismon concluded.<\/p>\n<p>\u201cIf you\u2019re worried your SOC might be falling into this trap, a red or purple team from a credible vendor will give you proof either way.\u201d<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Many of the most common metrics used to measure the effectiveness of the security operations center (SOC) are at best inaccurate and at worst actively harm SecOps teams, the National Cyber Security Centre (NCSC) has warned. The NCSC\u2019s CTO for architecture, Dave Chismon, wrote in a blog post that organizations often gravitate to measurements that<\/p>\n","protected":false},"author":2,"featured_media":5236,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5235","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"thumbnail":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad-150x150.jpg",150,150,true],"medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"medium_large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"1536x1536":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"2048x2048":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"morenews-featured":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"morenews-large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"morenews-medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad.jpg",300,300,false],"crawlomatic_preview_image":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/04\/5235-8def00d6-b98a-4220-a00d-b478e768b9ad-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"https:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"https:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/5235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=5235"}],"version-history":[{"count":0,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/5235\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/5236"}],"wp:attachment":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=5235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=5235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=5235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}