SOCs generate a large amount of information about their activity. Number of alerts handled, average detection time, response time, false positives, and incidents resolved are some of the most common metrics on dashboards.

However, having many metrics does not necessarily mean having useful information for improvement.

A metric only provides value when it helps answer a specific question: Are we detecting threats earlier? Are we investigating more efficiently? Are our detections actually working?

The SOC Critical Path (SCP) model reminds us that all phases of the cycle (from data collection to continuous improvement) should be reviewed periodically to identify opportunities for evolution. And for this, it is essential to measure what truly reflects the SOC's operational performance.

When a Metric Stops Providing Value

Not all metrics offer the same capacity to improve a SOC. Some simply describe the activity performed, while others help identify where opportunities for improvement exist.

For example, knowing the number of alerts handled during the last month can be useful for understanding the team's workload, but it will hardly allow you to assess whether the SOC is detecting threats better or responding more effectively.

On the other hand, analyzing how indicators such as mean time to detection (MTTD), mean time to response (MTTR), detection coverage, or false positive rate evolve can provide information about the actual performance of the service and guide improvement decisions.

The key is not to measure more, but to select the indicators that allow you to understand what is working, what needs to be reviewed, and where action should be taken.

Which metrics should you monitor?

There is no universal set of indicators valid for all SOCs, but some metrics offer particularly useful insights into service effectiveness.

Mean Time To Detection (MTTD)

This shows how long it takes the SOC to identify a threat from the moment it occurs. A progressive reduction usually indicates an improvement in detection capabilities.

Mean Time To Response (MTTR)

This measures the time required to contain or resolve an incident. Analyzing its evolution helps identify potential bottlenecks during the investigation or response.

Detection Coverage

Beyond the number of existing rules, it is useful to review whether the main threats to the organization have adequate and up-to-date detection mechanisms.

False Positives

A high volume can significantly increase the workload of analysts and make it difficult to identify truly relevant incidents.

These metrics are especially valuable when analyzed together and over time. Viewed in isolation, they can offer an incomplete view of SOC performance.

The question isn't how much we measure, but what we do with those metrics.

Metrics should be the starting point for improvement, not the end goal.

For example:

  • If the MTTD increases, it may be necessary to review monitoring coverage or detection rules.
  • If the MTTR grows steadily, it may indicate that the context available during the investigation is insufficient or that there are repetitive tasks that could be automated.
  • If false positives increase, it's probably advisable to review the quality of detections before creating new rules.
  • If certain threats are not covered, it may be time to develop new use cases or incorporate new sources of information.

Each metric should lead to a question and, from there, to a concrete action.

An exercise to review the SOC dashboard

Before incorporating new indicators, it may be helpful to consider these questions:

  • Do the current metrics really help in decision-making?
  • Are there any metrics that are systematically collected but never used to improve the service?
  • Do the indicators allow you to identify trends or do they only describe the activity performed?
  • Do the periodic SOC reviews end up generating concrete improvement actions?
  • Are the metrics used to prioritize investments and evolve the SOC's capabilities?

Measurement is essential, but it only makes sense when the data serves to guide decisions and strengthen the SOC's operation.