Back to Blog
Managed Services
8 min read

SOC Metrics That Improve Outcomes, Not Just Dashboards

Most SOC reporting measures activity — tickets closed, alerts handled — which rewards volume rather than protection. The metrics that change behaviour, and the ones that mislead.

GuardsArm Team

Security Experts

January 7, 2026

SOC metrics

Most SOC dashboards measure how busy the team was. Alerts handled, tickets closed, events ingested. These are activity metrics, and they have a specific failure mode: they go up when things get worse. A SOC drowning in false positives posts excellent numbers.

Activity != outcome
Alert volume rises with noise, not with protection
Dwell time
The one number that most directly reflects attacker advantage
Board legibility
A metric leadership cannot act on will not survive budget season

The metrics that matter

Mean time to detect (MTTD). From the earliest attacker action you can evidence, to the moment someone knew. Measured honestly this is often uncomfortable, because the clock starts before the alert — at the initial access you reconstructed afterwards.

Mean time to respond (MTTR). From detection to containment. Split it: time-to-triage, time-to-investigate, time-to-contain. The aggregate hides which stage is actually slow, and they have different fixes — staffing, tooling and authority respectively.

Dwell time. How long an adversary was present before eviction. The purest measure of whether detection is working, and the hardest to game.

Detection coverage. Proportion of relevant ATT&CK techniques with a validated detection. "Validated" is doing real work in that sentence — see SIEM tuning.

Alerts closed without investigation. The honest fatigue measure. If it is rising, the queue is not being read.

MetricUseful becauseGamed by
MTTDReflects real detection capabilityStarting the clock at the alert, not the intrusion
Time to triageIsolates a staffing problemClosing tickets fast without reading them
Time to containIsolates an authority problemNarrow definition of "contained"
Dwell timeHardest to fakeOnly measurable for incidents you found
CoverageShows blind spotsCounting unvalidated rules
Closed-without-investigationExposes fatigueSimply not recording it

Metrics to stop reporting

  • Total alerts — rises with noise; says nothing about safety
  • Events ingested per second — a licensing figure, not a security one
  • Blocked attacks — counts the firewall doing its job, mostly internet background radiation
  • Tickets closed — rewards throughput over thoroughness
  • Uptime of the SIEM — necessary, not interesting
The metric that quietly causes harm
Ranking analysts on tickets closed per shift teaches the team to close quickly. It is the single most reliable way to manufacture the alert-fatigue problem you are trying to measure.

Healthcare-specific additions

Generic SOC metrics miss things that matter in a hospital:

  • Break-glass reviews completed within 24 hours — a control that only works if the review happens
  • Clinical system alert-to-notification time — how fast the clinical owner hears, not just the SOC
  • Medical device anomalies triaged — devices cannot self-report, so this measures a genuine blind spot
  • After-hours coverage gaps — attacks cluster where staffing does not, and hospitals run 24/7 while many SOCs do not

Reporting to a board

Executives do not need MTTD in minutes. They need to know whether the risk is moving, and what a decision would buy.

The four questions a board is actually askingThe four questions a board is actually asking1Are we getting better?TrendDwell time and MTTR over four quarters, not this month in isolation.2Where are we exposed?CoverageNamed gaps in plain language: "no detection for X on the imaging network".3What would money fix?OptionsThis gap closes with this investment, reducing this specific exposure.4How do we compare?ContextAgainst sector norms, with the caveat that benchmarks are rough.
Each answer should point at a decision. A number with no decision attached is a slide, not a metric.

Targets, and why to set them late

Setting a target before you have a baseline produces one of two bad outcomes: a target so soft it is met on day one, or one so aggressive that the team starts measuring differently to hit it. Both destroy the metric's usefulness.

Measure for a quarter first. Then set targets that are a stretch against your own baseline rather than against a vendor's marketing figure:

MetricReasonable first target
Time to triage80% of alerts within 30 minutes
Time to contain, criticalUnder 4 hours
Break-glass reviews completed100% within 24 hours
Alerts closed without investigationBelow 10%, trending down
Detection coverage, validatedGrowing quarter on quarter

Note that only one of those is an absolute. The rest are shaped as "better than last quarter", which is the honest framing for a programme still maturing.

Report the metric you are worst at
A dashboard showing only improving numbers is a marketing document. Leading with the measure that is going the wrong way is what earns the credibility to ask for budget against it.

Where to start

Pick three: dwell time, time-to-contain, and alerts closed without investigation. Measure them honestly for a quarter before setting targets — including the ones that look bad. A baseline you trust is worth more than a dashboard you do not.

GuardsArm builds SOC metrics programmes for healthcare, including the clinical measures generic frameworks omit. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “SOC Metrics That Improve Outcomes, Not Just Dashboards”

Talk to the GuardsArm team about how these services apply to your environment.