News.Risky.Biz NCSC Warns Against Ineffective SOC Metrics
Article Content
- •NCSC advises against using ineffective metrics for SOC evaluation.
- •Common metrics can lead to careless behavior and false positives.
- •Time-to-detect and time-to-respond are recommended as better metrics.
The UK's National Cyber Security Centre (NCSC) has issued a warning regarding the reliance on ineffective metrics to evaluate Security Operations Centers (SOCs). NCSC's CTO, Dave Chismon, stated that common metrics such as 'number of tickets processed' and 'time taken to close a ticket' can lead to careless behavior among SOC teams, incentivizing them to prioritize speed over thorough investigations. This can result in a high volume of false positives and ineffective security measures. Instead, the NCSC recommends focusing on metrics like time-to-detect (TTD) and time-to-respond (TTR) to better assess SOC effectiveness. Chismon emphasized that using no metrics is preferable to using bad ones, as the latter can demoralize staff and lead to a culture of rushing through alerts. The NCSC also advocates for allowing SOC teams to engage in hypothesis-led threat hunting and to study threat actors to enhance their defensive capabilities. The guidance aims to improve the overall effectiveness and morale of SOC teams.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Kyber Ransomware, Anodot and CVE-2026-3965 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…