The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
Mean Time to Contain (MTTC) for Incidents Led
The average time it takes from when you take ownership of a high-severity incident to when the threat is fully contained and no longer spreading.
Target · < 60 minutes for critical incidents (P1/P2)You take over a ransomware incident at 10:00 AM, and by 10:45 AM, all affected systems are isolated and the spread is stopped. That's a 45-minute MTTC – excellent work.
New High-Fidelity Detection Rules Deployed
The number of new, effective detection rules you've designed, tested, and pushed into our SIEM or EDR that consistently catch real threats without generating too many false positives.
Target · 2-3 per quarter (must be high-fidelity)You spot a new phishing technique, design a custom SIEM rule to catch it, test it thoroughly, and deploy it. Over the next month, it correctly flags 5 real phishing attempts and zero false positives. That counts.
Threat Hunt Success Rate
The percentage of proactive threat hunts you lead that actually uncover previously undetected malicious activity or significant security gaps.
Target · > 25% of hunts leading to actionable findingsYou lead a hunt for 'living off the land' binaries, and it uncovers a persistent backdoor on a development server that no one knew about. That's a successful hunt.
Junior Analyst Mentorship & Development
The measurable progress and increased capability of the junior analysts you're mentoring, evidenced by their ability to handle more complex tasks independently.
Target · At least 1 mentee promoted to L2 within 18 months, or demonstrably improved performance.Your mentee, who used to struggle with complex Splunk queries, can now independently investigate multi-stage attacks and draft initial incident reports, showing clear growth under your guidance.
Incident Report Quality & Clarity
How well your post-incident reports articulate what happened, why it happened, the impact, and clear, actionable recommendations for preventing recurrence. These reports need to be understood by both technical teams and senior leadership.
- Reports are consistently concise, accurate, and provide a clear narrative. Leadership (including the SOC Manager) rarely asks for clarification, and recommendations are genuinely useful and implemented by other teams.
Post-Incident Review Effectiveness
Your ability to lead blameless post-incident reviews, extracting genuine lessons learned and driving concrete improvements in our processes and tools, rather than just pointing fingers.
- You run these meetings effectively, ensuring everyone contributes constructively. The team comes out with clear action items, and those actions actually get prioritised and completed, leading to measurable improvements in our security posture.
Technical Leadership & Guidance
How effectively you guide junior analysts through complex investigations, share your knowledge, and help them develop their own skills and judgment.
- Junior analysts regularly seek your advice. You're seen as a trusted technical expert. Your code reviews and feedback are constructive and help others improve. You're often asked to lead training sessions or present on new techniques.
Proactive Threat Identification
Your knack for spotting emerging threats or subtle anomalies before they become full-blown incidents, often through proactive threat hunting or deep dives into data.
- You regularly bring up potential risks or vulnerabilities that haven't been formally reported yet. Your threat hunts consistently uncover suspicious activity that requires further investigation, even if it's not a full breach.