The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
Alerts Triaged per Shift
The number of security alerts you investigate and categorise during your shift. This includes closing false positives and escalating genuine threats.
Target · Typically >100 alerts per 8-hour shift, depending on alert volume and complexity.On a busy Monday, you might triage 120 alerts, closing 100 as false positives and escalating 20 for deeper investigation.
Ticket Escalation Accuracy
The percentage of incidents you escalate that turn out to be genuine threats, and the percentage of false positives you correctly close without escalation.
Target · >98% accuracy in correctly identifying and escalating real issues, and closing false positives.Out of 50 escalations, 49 were valid incidents. Out of 500 closed alerts, none were later found to be missed threats. That's good going.
Mean Time to Escalate (MTTE) for Critical Alerts
The average time it takes you to identify a critical security alert and escalate it to the appropriate team or lead for further action.
Target · <15 minutes for critical (P1) alerts; <30 minutes for high (P2) alerts.A P1 alert comes in at 10:05 AM, you confirm it's a genuine threat by 10:17 AM and escalate it. That's 12 minutes, well within target.
Incident Resolution Rate
The percentage of assigned Tier 2 incidents you successfully investigate, contain, and resolve without needing significant intervention from a senior analyst.
Target · >85% of assigned Tier 2 incidents resolved independently.You're assigned 20 Tier 2 incidents in a month and successfully close 18 of them, only needing help on two particularly tricky ones.
Investigation Quality & Documentation
How thoroughly you investigate incidents, the clarity and completeness of your findings, and how well you document your steps and conclusions in our ticketing system (Jira/Confluence).
- Your incident reports are clear, concise, and contain all necessary technical details. Other analysts can easily pick up your cases if needed. You include 'Lessons Learned' where appropriate, even if it's just for yourself. Your lead rarely has to ask for more detail or clarification on your cases.
Proactive Problem Solving
Your ability to not just react to alerts, but to identify underlying issues, suggest improvements to detection rules, or propose new ways to reduce 'Alert Fatigue'.
- You'll suggest tuning a noisy alert rule, or propose a new SIEM query that catches something we've missed. You might spot a recurring issue and suggest a permanent fix, rather than just patching it over each time. You're not afraid to say, 'This alert is rubbish, here's why, and here's how we fix it.'
Collaboration & Knowledge Sharing
How well you work with your team and other departments, and your willingness to share your knowledge, especially with newer analysts.
- You're helpful in team chat, offering advice or sharing useful queries. You might run through a complex case with a junior analyst, showing them the ropes. Other teams (like IT or DevOps) find you easy to work with and appreciate your clear communication during incidents. You contribute to our internal knowledge base (Confluence) with useful articles or playbooks.
Adaptability & Learning
Your openness to new tools, techniques, and threats, and your continuous effort to improve your skills.
- You're quick to pick up new EDR features or SIEM query languages. You actively seek out training or read up on new attack methods. When a new threat emerges, you're keen to understand it and how it might affect us, rather than just waiting to be told what to do. You don't shy away from complex or unfamiliar incidents
- you see them as a chance to learn.