From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively
Anatoly Antipov, who leads the L1 analyst group in a small in-house SOC of up to eight people, describes how classic time-based metrics often produce the opposite of their intended effect. Many leaders start the day reviewing dashboards built around MTTD, MTTR, and similar indicators recommended by NIST SP 800-61. These numbers look clean in quarterly reports, yet they frequently hide shallow investigations and growing technical debt.
The SANS SOC Survey highlights the same pattern: when speed and volume become the only targets, analysts begin optimizing for the metric instead of security outcomes. One documented case showed a simple script automatically moving new alerts into the “in progress” state to keep MTTA numbers green while real cases sat untouched for hours.
To address this, the team introduced a strict five-level verdict matrix. The categories are TP.Ext for confirmed external attacks, TP.Int for internal policy violations, BP for authorized testing activity, FP for legitimate business or IT actions, and FP.SOC for problems inside detection content, parsing, or filtering logic. This classification makes it immediately visible where the SOC is generating value and where it is accumulating its own technical debt.
The weekly report was rebuilt around three focused blocks. The first shows overall alert volume, closure rates, backlog, and shift workload distribution. The second breaks alerts down by the new verdict matrix so managers can see whether rising false positives stem from business changes or from SIEM and SOAR content issues. The third block lists real confirmed incidents together with concrete effort indicators such as emails sent, EDR scans launched, and indicators blocked.
Every week a sample of closed alerts from each analyst undergoes quality review. Reviewers check whether the verdict is correct, whether actions are fully documented, whether sufficient artifacts are attached, and whether FP.SOC items include clear recommendations for rule improvement. The process prevents analysts from being rated solely on speed.
The changes demonstrate that Mean Time metrics remain useful when paired with quality controls, transparent verdicts, and regular audits. Without these additions, small SOC teams risk turning into expensive click farms that look efficient on dashboards while actual risk reduction quietly declines.
Related articles
VK Files Lawsuit in EU Court Seeking to Overturn Sanctions Imposed in July
Russian internet company VK has submitted a formal challenge to the European Union's sanctions regime by filing a case with the Court of Justice of the European Union. The company argues that the restrictions placed on VK and its subsidiary Communication Platform LLC are both unjustified and unlawful. The lawsuit, registered under case number T-664/26 on 7 October, directly contests the July sanctions that targeted the developer of the MAX messenger. Earlier restrictions had already led to the removal of multiple VK ecosystem applications from Apple App Store and Google Play, forcing users toward alternative distribution channels such as RuStore, Huawei AppGallery, Samsung Galaxy Store and Xiaomi GetApps. While installed Android applications continue to function and receive updates, iOS users face disrupted push notifications after the apps were delisted. The legal action itself does not automatically restore app availability in the affected stores.
VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access
As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.
Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators
A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.
Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings
Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.