Second part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment.
CHAPTERS
(01:28) - Why Dave hates Mean Time to Detect (MTTD)
(07:00) - Why SOCs need to measure the quality of their data and signals
(13:01) - Confirmation rates + and why the math often doesn't add up
(18:00) - It’s very difficult to measure quality, but it’s very valuable + an example
(19:29) - Example: how to define the metrics that actually matter to your organisation
(23:41) - Mean Time to Respond (MTTR) - and why the number doesn't necessarily inspire confidence
(32:06) - Why SOC severity levels need business context
(35:28) - Making sure your SOC understands what is actually critical to the business
(39:09) - Example of business criticality
(41:09) - The importance of having a key operational contact inside the business
(43:34) - One of his big measures of quality: how many tickets had to be sent back for validation
(47:06) - Not many people understand what a SOC actually is
GUEST
Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment
LinkedIn: https://www.linkedin.com/in/davewmckenzie/
HOST
Michael VIRGONE
LinkedIn: https://www.linkedin.com/in/michaelvirgone/
GET IN TOUCH
If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you.
LinkedIn is my preferred way to get in touch, but you can also reach me by email.
LinkedIn: above
Email: hello@cyberallday.io
Website: https://cyberallday.io/
ENJOYING THE PODCAST?
If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.
