Security 101

Which SOC Metrics Show Whether Risk Is Going Down?

Ticket counts and alert volumes show activity. Here are the SOC metrics that show whether risk is actually going down, and what to ask a provider to report.

The SOC metrics that show risk going down measure speed and signal quality over time: how fast threats are contained, how quickly someone owns the next step, whether false positives are falling, and how much routine work runs automatically. Ticket counts and alerts processed show how busy a SOC is, which is a different question.

That difference matters most when you buy security operations from a provider, because the metrics in the contract shape what the provider works toward.

What to track

  • Trends beat totals. A metric means something when it improves quarter over quarter.
  • Fewer alerts can be progress. As tuning improves, alert volume should fall.
  • Measure what happens after the alert. Time to own shows how long it takes someone to take the next step.
  • Check the incentives. A contract that pays for volume rewards activity over outcomes.

What is the difference between activity metrics and outcome metrics?

Activity metricOutcome metricWhat the outcome shows
Tickets closedMean time to resolve, trending downResponse is getting faster for real threats
Alerts processedFalse positives, trending downTuning is removing noise
Analyst hours loggedShare of routine triage automatedAnalysts have more time for investigation
Time to acknowledgeTime to ownSomeone takes the next step quickly
Based on our posts on SOC theater and escalation.

What do the key SOC metrics mean?

Time to own

How long it takes from an alert being seen to someone taking responsibility for the next step. Response often stalls here, after detection has already worked.

Mean time to contain

How quickly a threat is neutralized after it is discovered. Pre-approved response protocols shorten it by removing the wait for approval.

Dwell time

How long an attacker operates in the environment before detection. Faster detection and containment both bring it down.

Noise escalation rate

How much of what reaches your team turns out to need no action. Accelerynt publishes a rate under 1% for MDR Stage 1.

Time to own comes from our post The Alert Fired. The Team Froze., which looks at why escalation slows down even when the tools and the team performed as expected.

Why do activity metrics mislead?

When a contract pays for volume processed, more tickets look like more value. Our post When Outsourced SOC Activity Becomes Security Theater describes an engagement where a new provider changed alert settings and incident volume jumped by thousands, with no reduction in risk.

Headcount can mislead the same way. In our post The Headcount Trap, a SOC with more than 30 analysts was still missing basic incidents, because the system was designed for staffing instead of outcomes.

Which MDR providers have the fewest false positives?

A single false positive number is hard to compare across providers, because providers may count them differently. The trend over time, and how the provider gets there, tells you more. Ask every provider these questions.

  • Is mean time to resolve improving? Ask for the trend quarter over quarter.
  • Are false positives decreasing? Ask how tuning happens in your environment and who owns it.
  • Is automation tracked and rewarded? Check whether the contract encourages automation or penalizes it.
  • Where do analysts spend their time? Ask how much goes to investigation versus administrative work.

Accelerynt tunes detection rules directly in your Sentinel workspace and publishes its commitments: detection within 30 minutes and a noise escalation rate under 1% at Stage 1. For more on comparing providers, read how to choose an MDR provider for Microsoft Defender and Sentinel.

Which MDR providers give reports that executives can understand?

Executives need to see whether risk is going down, so useful reports show trends in containment time and the risks that were closed. Raw counts of alerts and tickets leave that question unanswered.

In Accelerynt’s MDR engagement model, monthly operational reports cover what was addressed, what changed and what comes next, and quarterly maturity briefings add trend analysis and recommendations. Every containment action is documented with its scope, entry point, actions taken and recommended next steps. See MDR stages for what each stage includes.

If you are still choosing between delivery models, read how to choose an outsourced SOC for a Microsoft environment, and for how MDR works with the SIEM you already run, see how managed detection and response improves SIEM.

Where to go next

For what Accelerynt’s MDR covers, start with managed detection and response. If an outsourced provider already runs your SOC, the IT Operations Security Audit tests whether it follows your security protocols.

For where response time goes after an alert, read why incident response stalls after the alert fires. To compare providers on what you can see of their work, read which MDR providers let you see what their SOC is doing.

Frequently asked questions

Which MDR providers have the fewest false positives?

Ask each provider for its false positive trend over time instead of a single number, and ask how tuning happens in your environment. Accelerynt tunes detection rules inside your own Sentinel workspace and publishes a noise escalation rate under 1% for MDR Stage 1.

Which MDR providers give reports that executives can understand?

Look for reports that show trends in containment time and risk reduced instead of ticket counts. In Accelerynt’s MDR engagement model, monthly operational reports cover what was addressed, what changed and what comes next, and quarterly maturity briefings add trend analysis and recommendations.

What is time to own?

Time to own is how long it takes from an alert being seen to someone taking responsibility for the next step. It exposes delays that time to detect and time to acknowledge do not show.

Should SOC alert volume go down over time?

In a well-tuned environment, yes. As detection rules are tuned and routine triage is automated, alert volume should fall while response to real threats gets faster.

Talk to a Microsoft security engineer

We work inside your Microsoft environment, with your team, and show you where to focus first.