UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

27 April 2026
World Series winner and MLB great Garret Anderson was battling ‘serious medical conditions’ before his shock death at 53, autopsy reveals

World Series winner and MLB great Garret Anderson was battling ‘serious medical conditions’ before his shock death at 53, autopsy reveals

27 April 2026
Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

27 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Could your choice of metrics be harming your SOC?
News

Could your choice of metrics be harming your SOC?

By uk-times.com27 April 2026No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

A consideration when applying metrics is that if they’re used to quantify performance, then staff are incentivised to ‘optimise’ metrics, and this can lead to some perverse outcomes. Let’s consider some common SOC metrics, and how they can unintentionally degrade a SOC’s ability to detect threats.

Metric 1. Number of tickets processed

When a suspicious pattern in logs triggers an alert rule, it typically produces a ticket for analysts to triage. The analyst assigned to the ticket then has to assess the alert, and make a call whether it might be:

  • a real attack requiring escalation into an investigation/incident

or

  • a false positive due to a quirk of the alerting logic

In the vast majority of SOCs I’ve observed, alert logic leads to a lot of false positives. I’ve seen ticket-focussed SOCs where as many as 99% of tickets were being triaged as false positives. This means that an analyst being measured on ‘number of tickets processed’ is incentivised to quickly find a reason to close it as a false positive, rather than to escalate or investigate it.

Metric 2. Time taken to close a ticket

Similar to the above, but the analyst is now also incentivised to click ‘false positive’ as quickly as possible.

Metric 3. Number of detection rules

A subtly dangerous metric as the benefits seem self-evident. It seems logical to presume that the more rules there are to ‘detect bad things’ will result in more chances to ‘detect bad things’.

Unfortunately this is rarely the case.

Such a metric almost always leads to the perverse outcome of ‘alert inflation’; analysts are incentivised to write as many rules as possible, so the metric goes up. However, this leads to false positives as well as ineffective rules. At its worst, I’ve seen individual rules for individual Indicators of Compromise (IOCs) like an IP address.

Metric 4. Volume of logs collected vs value of logs collected

Effective detection needs good logs, and whilst logs are very useful for incident investigation, logs on their own won’t help with detection. I’ve seen too many SOCs that are ingesting ever-increasing volumes of logs, but those logs often either have limited detection value, or the SOC isn’t using the logs for detection (no relevant alerts, or threat hunts that require those logs).

I visited a SOC where one of their largest log feeds by volume had never been set up correctly, so they only had the first 30 characters of each entry. However, this had never been noticed, so they were not carrying out any meaningful alerting.

Worse still, collecting increasing volumes of logs with limited value generally means the existing logs can be retained for less time (as additional logs will incur additional cost, or take up disk space)

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

27 April 2026
Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

27 April 2026
Lorry carrying 20 tonnes of prosecco involved in motorway crash in Berkshire – UK Times

Lorry carrying 20 tonnes of prosecco involved in motorway crash in Berkshire – UK Times

27 April 2026
Man gets month in jail for Pennsylvania voter registration quotas in 2024 presidential race – UK Times

Man gets month in jail for Pennsylvania voter registration quotas in 2024 presidential race – UK Times

27 April 2026

Agenda for Overview and Scrutiny Board on Wednesday, 6 May 2026, 5.30 pm

27 April 2026
Why and how European airlines may cancel flights – and why passengers shouldn’t worry – UK Times

Why and how European airlines may cancel flights – and why passengers shouldn’t worry – UK Times

27 April 2026
Top News
Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times

27 April 2026
World Series winner and MLB great Garret Anderson was battling ‘serious medical conditions’ before his shock death at 53, autopsy reveals

World Series winner and MLB great Garret Anderson was battling ‘serious medical conditions’ before his shock death at 53, autopsy reveals

27 April 2026
Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times

27 April 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Starmer calls his wife Victoria his ‘rock’ before Commons vote – UK Times
  • World Series winner and MLB great Garret Anderson was battling ‘serious medical conditions’ before his shock death at 53, autopsy reveals
  • Ex-Secret Service agents see security gap after DC dinner attack: ‘A positive outcome, not a successful one’ – UK Times
  • What King Charles and Queen Camilla have planned for their US state visit
  • Lorry carrying 20 tonnes of prosecco involved in motorway crash in Berkshire – UK Times

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version