Metrics that lie
A talk on how common SOC metrics can look accurate while misleading leadership, hiding operational reality, and driving the wrong business decisions.
Security leaders rely on metrics to understand risk, performance, and where to focus investment. But some of the most common SOC metrics can tell a technically accurate story while still leading executives to the wrong conclusion.
This talk explores how familiar reporting patterns — averages, aggregate trends, green SLAs, and performance targets — can hide operational reality. Using simple SOC examples, we will look at mean vs median, Simpson’s Paradox, and Goodhart’s Law, and show how good teams can accidentally create dashboards that mislead leadership.
The goal is not to argue against metrics. It is to make them more honest. Attendees will leave with a practical way to report SOC performance with better context, clearer narrative, and stronger decision-making.
UK-based cyber security leader and currently a Principal Cloud Security Operations Centre Manager at Microsoft. For more than a decade, I’ve built, led, and mentored SOC teams operating in high-pressure environments.