The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
New Detection Rules Deployed & Efficacy
The number of high-fidelity detection rules you design, build, and get into production, along with how well they actually catch real threats without too many false positives.
Target · 2-3 new, high-impact detection rules per quarter, with >90% true positive rate.You design a new rule to detect specific lateral movement techniques. In Q2, you deploy three such rules. One catches a genuine phishing attempt that bypassed email filters, another identifies a suspicious admin login from an unusual country, and the third flags a legitimate but unusual activity. All three are true positives, showing high efficacy.
Reduction in Mean Time to Detect (MTTD)
How quickly we spot a genuine security incident from the moment it starts. Your detection engineering work should make us faster.
Target · Contribute to a 15% reduction in MTTD for critical incident types year-on-year.Last year, our average MTTD for ransomware was 4 hours. Through your new detection logic for suspicious file encryption and network beaconing, we now typically detect it within 3 hours and 20 minutes, a clear improvement.
Threat Hunting Success Rate
The percentage of proactive threat hunts that actually uncover previously undetected malicious activity or critical vulnerabilities.
Target · Minimum 2 successful threat hunts per quarter, leading to new detections or security control improvements.You run a hunt based on new intelligence about supply chain attacks. This leads to discovering a misconfigured cloud storage bucket that was publicly accessible, which wasn't flagged by automated scans. That's a win.
False Positive Reduction for Key Alerts
The extent to which your tuning and optimisation efforts reduce the amount of 'noise' (false alerts) that analysts have to sift through.
Target · Achieve a >20% reduction in false positives for at least two high-volume alert types per quarter.Analysts were drowning in alerts about 'suspicious PowerShell activity' from a specific development tool. You investigate, identify benign patterns, and tune the rule, reducing false positives by 30% without missing actual threats.
Technical Leadership & Mentorship
How effectively you guide and upskill the SOC analysts, helping them grow their technical capabilities and tackle more complex problems.
- Junior analysts consistently seek your advice before escalating. You're regularly running internal training sessions or 'lunch and learns'. Your mentees are visibly improving their investigation skills and taking on more challenging tasks. You're the one they turn to when they're stuck on a tricky incident.
Detection Engineering Maturity
The overall improvement in the sophistication and coverage of our detection capabilities, moving beyond simple IOCs to more behavioural detections.
- Our detection rules are increasingly focused on 'Indicators of Attack' (IOAs) rather than just 'Indicators of Compromise' (IOCs). We're mapping more of the MITRE ATT&CK framework with active detections. Post-incident reviews consistently highlight that your detections caught the attack early.
Incident Response Process Optimisation
Your ability to identify bottlenecks in our incident response (IR) processes and propose/implement improvements, often through SOAR playbooks.
- IR playbooks are updated and more comprehensive based on your input. Analysts are following more automated workflows. Post-incident reviews show smoother transitions between containment, eradication, and recovery phases, often directly attributable to a process change you championed.
Cross-Team Collaboration & Influence
How well you work with other technical teams (like Engineering, DevOps, Product Security) to implement security controls or get vulnerabilities remediated.
- You're regularly invited to planning meetings for new systems or features to advise on security. Other teams are proactively reaching out to you for guidance on secure configurations. You're able to persuade teams to prioritise security work based on clear risk explanations, even when it means delaying other projects.