UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot

M1 J5 southbound access | Southbound | Road Works

27 April 2026
Man United 2-1 Brentford: Bruno Fernandes masterclass proves tying the talisman down to a new deal this summer is THE most important piece of business on the agenda at Old Trafford, writes CHRIS WHEELER

Man United 2-1 Brentford: Bruno Fernandes masterclass proves tying the talisman down to a new deal this summer is THE most important piece of business on the agenda at Old Trafford, writes CHRIS WHEELER

27 April 2026
UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

27 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Could your choice of metrics be harming your SOC?
News

Could your choice of metrics be harming your SOC?

By uk-times.com27 April 2026No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

A consideration when applying metrics is that if they’re used to quantify performance, then staff are incentivised to ‘optimise’ metrics, and this can lead to some perverse outcomes. Let’s consider some common SOC metrics, and how they can unintentionally degrade a SOC’s ability to detect threats.

Metric 1. Number of tickets processed

When a suspicious pattern in logs triggers an alert rule, it typically produces a ticket for analysts to triage. The analyst assigned to the ticket then has to assess the alert, and make a call whether it might be:

  • a real attack requiring escalation into an investigation/incident

or

  • a false positive due to a quirk of the alerting logic

In the vast majority of SOCs I’ve observed, alert logic leads to a lot of false positives. I’ve seen ticket-focussed SOCs where as many as 99% of tickets were being triaged as false positives. This means that an analyst being measured on ‘number of tickets processed’ is incentivised to quickly find a reason to close it as a false positive, rather than to escalate or investigate it.

Metric 2. Time taken to close a ticket

Similar to the above, but the analyst is now also incentivised to click ‘false positive’ as quickly as possible.

Metric 3. Number of detection rules

A subtly dangerous metric as the benefits seem self-evident. It seems logical to presume that the more rules there are to ‘detect bad things’ will result in more chances to ‘detect bad things’.

Unfortunately this is rarely the case.

Such a metric almost always leads to the perverse outcome of ‘alert inflation’; analysts are incentivised to write as many rules as possible, so the metric goes up. However, this leads to false positives as well as ineffective rules. At its worst, I’ve seen individual rules for individual Indicators of Compromise (IOCs) like an IP address.

Metric 4. Volume of logs collected vs value of logs collected

Effective detection needs good logs, and whilst logs are very useful for incident investigation, logs on their own won’t help with detection. I’ve seen too many SOCs that are ingesting ever-increasing volumes of logs, but those logs often either have limited detection value, or the SOC isn’t using the logs for detection (no relevant alerts, or threat hunts that require those logs).

I visited a SOC where one of their largest log feeds by volume had never been set up correctly, so they only had the first 30 characters of each entry. However, this had never been noticed, so they were not carrying out any meaningful alerting.

Worse still, collecting increasing volumes of logs with limited value generally means the existing logs can be retained for less time (as additional logs will incur additional cost, or take up disk space)

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

M1 J5 southbound access | Southbound | Road Works

27 April 2026
UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

27 April 2026

A1(M) J3 southbound exit | Southbound | Road Works

27 April 2026

M5 southbound between J6 and J7 | Southbound | Road Works

27 April 2026
LAPD bomb squad that miscalculated explosion and damaged dozens of homes received light punishments, report says – UK Times

LAPD bomb squad that miscalculated explosion and damaged dozens of homes received light punishments, report says – UK Times

27 April 2026

M5 northbound between J8 and J7 | Northbound | Road Works

27 April 2026
Top News

M1 J5 southbound access | Southbound | Road Works

27 April 2026
Man United 2-1 Brentford: Bruno Fernandes masterclass proves tying the talisman down to a new deal this summer is THE most important piece of business on the agenda at Old Trafford, writes CHRIS WHEELER

Man United 2-1 Brentford: Bruno Fernandes masterclass proves tying the talisman down to a new deal this summer is THE most important piece of business on the agenda at Old Trafford, writes CHRIS WHEELER

27 April 2026
UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times

27 April 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • M1 J5 southbound access | Southbound | Road Works
  • Man United 2-1 Brentford: Bruno Fernandes masterclass proves tying the talisman down to a new deal this summer is THE most important piece of business on the agenda at Old Trafford, writes CHRIS WHEELER
  • UK scientists to fire salt water into the sky in bid to tackle climate crisis – UK Times
  • A1(M) J3 southbound exit | Southbound | Road Works
  • M5 southbound between J6 and J7 | Southbound | Road Works

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version