September 02, 2026
4
50:41

Measuring what matters in a SOC #04

Second part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment.

CHAPTERS

(01:28) - Why Dave hates Mean Time to Detect (MTTD)

(07:00) - Why SOCs need to measure the quality of their data and signals

(13:01) - Confirmation rates + and why the math often doesn't add up

(18:00) - It’s very difficult to measure quality, but it’s very valuable + an example

(19:29) - Example: how to define the metrics that actually matter to your organisation

(23:41) - Mean Time to Respond (MTTR) - and why the number doesn't necessarily inspire confidence

(32:06) - Why SOC severity levels need business context

(35:28) - Making sure your SOC understands what is actually critical to the business

(39:09) - Example of business criticality

(41:09) - The importance of having a key operational contact inside the business

(43:34) - One of his big measures of quality: how many tickets had to be sent back for validation

(47:06) - Not many people understand what a SOC actually is

GUEST

Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment

LinkedIn: https://www.linkedin.com/in/davewmckenzie/

HOST

Michael VIRGONE

LinkedIn: https://www.linkedin.com/in/michaelvirgone/

GET IN TOUCH

If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you.

LinkedIn is my preferred way to get in touch, but you can also reach me by email.

LinkedIn: above

Email: hello@cyberallday.io

Website: https://cyberallday.io/

ENJOYING THE PODCAST?

If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.