Unfortunately, many security professionals still consider noisy SOC metrics the best benchmarks for performance. I call this “activity theater”—a lot of show, but no real sustenance. High alert volumes consist mostly of noise that degrades true detection and camouflages exposure points.
This article presents a new way CISOs should evaluate metrics to accurately inform boards and CEOs about security status, and why risk reduction is the ultimate metric.
Drowning in Metrics
Security teams—in-house and at managed SOCs—are drowning in metrics. “Quantity” is not the issue. A busy SOC signals poor tuning and unattended protocols that distract defenders from stopping what matters most: actual attacks in motion.
Well-tuned SOCs should be quiet. When alerts are rare and precise, defenders recognize anomalies and respond decisively instead of sifting through noise. In our experience, true positives (outside of phishing) are highly unique and rarely repeat. When tuned correctly, 90% of true positives represent unique incidents requiring action.
Risk reduction metrics should lead any CISO’s board report. This requires a fresh mindset, but shifting toward “less is more” will result in stronger, more resilient security.
Noise Increases Security Risk
Simply put, overwhelming amounts of reactive “busy work” creates risk and leaves no time to properly manage transformation or enable and secure technology for critical business processes. The goal for in-house teams and MXDR providers is reducing business risk through focused metrics that allow SOCs to analyze critical alerts, work accurately, and refine detections.
Organizations with smaller teams often get bogged down by outdated systems that add noise without providing protection. When onboarding customers, we first clear legacy security to simplify the environment. This allows clear visibility across the entire estate and helps diagnose weak points.
For example, our experts have seen decades-old security misapplied to AWS and modern cloud environments. We have even taken over systems already compromised due to blind spots caused by alert abundance. Messy SOCs also make it easy to fall behind on patching; once alerts are out of control, implementing preventative measures becomes harder.
Beyond increasing risk, activity theaters have a human cost. These busy environments contribute to alert fatigue and burnout—real factors that affect not only work quality, but career longevity and mental health.
The Ideal State: What Does a Quiet SOC Look Like?
Our goal as defenders is to reduce alert volume while increasing detection. We’re constantly monitoring and adapting so that our response to suspicious activity is strategic, predictable, and fast. We consider every detection a security failure; this is why a quiet SOC is the ideal state.
To showcase success and identify weak spots, we focus on metrics for containment speed, risk reduction, detection quality, and automation effectiveness. Measuring these requires sustained tuning, correlation, and contextual analysis—work that often competes with daily incident response. This is why AI and automation are critical. These technologies can observe, orient, decide, and act (OODA) upon benign alerts at machine speed, freeing analysts and threat hunters to focus on urgent notifications.
As an example, experts in our Cyber Defense Center spent time on only about 3% of total customer incidents in 2024; our deterministic automation resolved the remaining 97%, as outlined in our whitepaper, “Cutting Through the Hype: What Agentic AI Really Means and the Future of Security Operations.” Metrics from this 3% – the “ideal quiet state” – are what CISOs should focus on when measuring and presenting their SOC’s value and status to stakeholders. As mentioned above, a key role for security experts is constantly calibrating controls and filters in the SOC. Think of it as a living, dynamic environment that changes daily – if not hourly – with employees coming and going (possibly leaving vulnerable ghost accounts and credentials), outdated local admin access, default or weak configurations exposed to the internet without proper patching or segmentation, human errors like plugging tainted personal USB drives into corporate workstations, and much more. Without a quiet SOC, it’s harder to detect, react to, and remediate this activity. With noisy metrics, CISOs might as well report what they’ve missed versus what they’ve caught and fixed.
Metrics Altitudes
Let’s take a step back and look at the 97% of alerts. At first glance, these may seem destined for the “cutting room floor,” but they do have a place in metrics reporting – they’re just not fit for page one of a board and CEO status summary.
We’ve categorized SOC metrics by audience and measurement level in what we call “Metrics Altitude.” Strategic metrics like root-cause recurrence rates belong in board reports, while operational metrics such as playbook success rates and automation utilization serve CISO and management needs. Tactical metrics like detection change failure rates focus on day-to-day management concerns. Every alert matters, even those in the 97%, but organizing metrics by audience creates more effective reporting and clearer action paths for each stakeholder group.
When CISOs inundate boards and CEOs with data that doesn’t make sense in five minutes or clearly answer “Are we protected?” no one wins. With a focus on high-fidelity alerts, managed security operations providers can quickly react with tangible security actions and remediations that stop and prevent cyberattacks. The result is not just better reporting, but a security team that spends less time proving its value and more time delivering it.
About the Author
My name is Craig Jones, Chief Security Officer at Ontinue. He oversees Ontinue’s global network of Security Operations Centers (SOCs) as Vice President of Security Operations. His role includes managing and optimizing the teams responsible for security monitoring, incident response, and threat detection across the company’s four SOCs. Before joining Ontinue, Craig spent eight years at Sophos, where he rose to Senior Director of Global Security Operations. At Sophos, Craig was responsible for the operational aspects of the company’s worldwide security program, ensuring that the organization’s global security infrastructure was robust and scalable.
Craig is a well-regarded expert in the field of cybersecurity, holding certifications such as GCIH and CISSP. He is actively involved in the cybersecurity community, volunteering as director of BSides Cymru/Wales since 2019 and frequently speaking at industry events. His thought leadership covers topics like incident response, SOC automation, threat intelligence, and SIEM. Craig earned a bachelor’s degree in Information Technology from the University of South Wales.
Craig can be reached on LinkedIn and at our company website https://www.ontinue.com/

