SOC Metrics That Improve Outcomes, Not Just Dashboards
Most SOC reporting measures activity — tickets closed, alerts handled — which rewards volume rather than protection. The metrics that change behaviour, and the ones that mislead.
GuardsArm Team
Security Experts
Most SOC dashboards measure how busy the team was. Alerts handled, tickets closed, events ingested. These are activity metrics, and they have a specific failure mode: they go up when things get worse. A SOC drowning in false positives posts excellent numbers.
The metrics that matter
Mean time to detect (MTTD). From the earliest attacker action you can evidence, to the moment someone knew. Measured honestly this is often uncomfortable, because the clock starts before the alert — at the initial access you reconstructed afterwards.
Mean time to respond (MTTR). From detection to containment. Split it: time-to-triage, time-to-investigate, time-to-contain. The aggregate hides which stage is actually slow, and they have different fixes — staffing, tooling and authority respectively.
Dwell time. How long an adversary was present before eviction. The purest measure of whether detection is working, and the hardest to game.
Detection coverage. Proportion of relevant ATT&CK techniques with a validated detection. "Validated" is doing real work in that sentence — see SIEM tuning.
Alerts closed without investigation. The honest fatigue measure. If it is rising, the queue is not being read.
| Metric | Useful because | Gamed by |
|---|---|---|
| MTTD | Reflects real detection capability | Starting the clock at the alert, not the intrusion |
| Time to triage | Isolates a staffing problem | Closing tickets fast without reading them |
| Time to contain | Isolates an authority problem | Narrow definition of "contained" |
| Dwell time | Hardest to fake | Only measurable for incidents you found |
| Coverage | Shows blind spots | Counting unvalidated rules |
| Closed-without-investigation | Exposes fatigue | Simply not recording it |
Metrics to stop reporting
- Total alerts — rises with noise; says nothing about safety
- Events ingested per second — a licensing figure, not a security one
- Blocked attacks — counts the firewall doing its job, mostly internet background radiation
- Tickets closed — rewards throughput over thoroughness
- Uptime of the SIEM — necessary, not interesting
Healthcare-specific additions
Generic SOC metrics miss things that matter in a hospital:
- Break-glass reviews completed within 24 hours — a control that only works if the review happens
- Clinical system alert-to-notification time — how fast the clinical owner hears, not just the SOC
- Medical device anomalies triaged — devices cannot self-report, so this measures a genuine blind spot
- After-hours coverage gaps — attacks cluster where staffing does not, and hospitals run 24/7 while many SOCs do not
Reporting to a board
Executives do not need MTTD in minutes. They need to know whether the risk is moving, and what a decision would buy.
Targets, and why to set them late
Setting a target before you have a baseline produces one of two bad outcomes: a target so soft it is met on day one, or one so aggressive that the team starts measuring differently to hit it. Both destroy the metric's usefulness.
Measure for a quarter first. Then set targets that are a stretch against your own baseline rather than against a vendor's marketing figure:
| Metric | Reasonable first target |
|---|---|
| Time to triage | 80% of alerts within 30 minutes |
| Time to contain, critical | Under 4 hours |
| Break-glass reviews completed | 100% within 24 hours |
| Alerts closed without investigation | Below 10%, trending down |
| Detection coverage, validated | Growing quarter on quarter |
Note that only one of those is an absolute. The rest are shaped as "better than last quarter", which is the honest framing for a programme still maturing.
Where to start
Pick three: dwell time, time-to-contain, and alerts closed without investigation. Measure them honestly for a quarter before setting targets — including the ones that look bad. A baseline you trust is worth more than a dashboard you do not.
GuardsArm builds SOC metrics programmes for healthcare, including the clinical measures generic frameworks omit. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “SOC Metrics That Improve Outcomes, Not Just Dashboards”
Talk to the GuardsArm team about how these services apply to your environment.


