M ManySignal

Guide · ManySignal

The SOC Metrics Guide

Most SOC metrics measure activity, not effectiveness. Alert count, tickets opened, and analyst hours consumed tell you how busy the team is — not how safe the organisation is. This guide defines the metrics that actually matter, how to instrument them from the ManySignal case timeline, and how to present them to leadership.

HR Hannah Roth — VP Product, ManySignal
14 min read Published Jun 30, 2026 Download PDF
01

Why most SOC metrics are noise

Alerts processed per day is not a security metric — it is a workload metric. A SOC that processes 10,000 alerts per day and closes them all as false positives is not more secure than one that processes 100 high-fidelity alerts and reaches a verdict on every one. Volume metrics reward busyness; outcome metrics reward effectiveness.

The shift from activity metrics to outcome metrics is the same shift as the broader AI SOC model: the question is not 'how much did we do?' but 'how much risk did we reduce, how fast, and at what cost?'

02

The five metrics that matter

Mean Time to Verdict (MTTV): time from finding creation to documented verdict. Target: under 4 minutes for autonomous verdicts, under 30 minutes for human-escalated. This is the single most important operational metric — everything else is a component of it.

Autonomous verdict rate: percentage of findings that reach a verdict without human input. Target: 90%+ for a mature AI SOC. Below 70% indicates the question sets need tuning or the detection quality is low. TP:FP ratio by detection: for each detection, the ratio of true positives to false positives in the trailing 30 days. High-severity detections should target 20:1 or better.

Coverage delta: net new MITRE ATT&CK techniques covered per quarter. A programme that is not expanding coverage is maintaining a static risk posture against a dynamic threat landscape. Cost per verdict: total platform + analyst cost divided by verdicts rendered. This is the CFO metric — it translates security operations into business language.

03

Instrumenting metrics from the case timeline

Every metric in the five-metric framework is derivable from the ManySignal case timeline without any manual tracking. MTTV is the delta between case_created_at and verdict_timestamp. Autonomous rate is the percentage of cases where verdict_actor is 'agent' rather than a human identity. TP:FP comes from verdict values on closed cases.

The report agent generates a weekly metrics digest automatically. Configure the digest to send to a Slack channel and a PDF archive. The digest is the weekly ops review agenda — no additional reporting work required.

04

Executive and board reporting

Executives need three numbers: how many threats did we stop, how fast, and are we improving? Present MTTV trend, autonomous verdict rate trend, and coverage delta. Use 30-day rolling averages and show quarter-over-quarter direction. Do not present raw alert counts to executives — it creates perverse incentives.

For board-level risk reporting, map the coverage delta to the threat actors most relevant to your sector. 'We added coverage for three techniques used by APT29 this quarter' is more meaningful than 'we wrote twelve new detections'.

05

Metrics-driven tuning loops

Metrics are only useful if they trigger action. Build a weekly tuning loop: review the five metrics, identify any that regressed, trace the regression to its source (specific detection, question set, or connector), and create an engineering ticket to fix it.

MTTV regression almost always traces to either a new finding type without a question set (forcing human triage) or a resolver that is timing out. TP:FP regression traces to a detection that has drifted from its original context — tuning needed. Autonomous rate regression traces to threshold settings that were never calibrated.

Key takeaways

  • Activity metrics measure busyness; outcome metrics measure effectiveness. Use outcome metrics.
  • The five that matter: MTTV, autonomous verdict rate, TP:FP by detection, coverage delta, cost per verdict.
  • All five are derivable from the case timeline — no manual tracking required.
  • Executive reporting: MTTV trend + autonomous rate trend + coverage delta. Never raw alert counts.
  • Build a weekly metrics-to-tuning loop: regression → source identification → engineering ticket.
  • Cost per verdict is the CFO metric — it translates SOC operations into business language.

Further reading

Frequently asked questions

What is The SOC Metrics Guide in an agentic SOC?

The SOC Metrics Guide is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle the soc metrics guide?

ManySignal grounds the soc metrics guide in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for the soc metrics guide?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.