August 24, 2026
3
49:25

MSSP SOC reporting has a metrics problem #03

First part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment.

CHAPTERS

(00:00) - In this episode & intro

(01:20) - Dave’s introduction

(04:34) - Dave jokes that he “tortures” vendors for a living

(07:47) - The story behind his talk at Security BSides London, “You Scored 46” - and why SOC metrics matter

(12:34) - For the purposes of his talk, he went to AI and asked for a monthly service delivery report + scope + inventory

(15:57) - AI averages the internet, vendor claims & pure filler slides

(17:00) - The industry doesn't know how to measure SOC performance: MSSP economics & honesty

(24:30) - Those monthly service delivery meetings should be more about what is happening rather than the stats

(30:29) - Goodhart’s Law: when metrics create the behaviour you want to avoid

(33:28) - The MSSP value paradox: they want to bring value, but it's good to have “boring customers” too

(38:59) - Why we need to keep clarifying the terminology: alerts, incidents & events

(42:52) - What is even an incident? It depends who you ask: security vs data incidents

GUEST

Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment

LinkedIn: https://www.linkedin.com/in/davewmckenzie/

HOST

Michael VIRGONE

LinkedIn: https://www.linkedin.com/in/michaelvirgone/

GET IN TOUCH

If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you.

LinkedIn is my preferred way to get in touch, but you can also reach me by email.

LinkedIn: above

Email: hello@cyberallday.io

Website: https://cyberallday.io/

ENJOYING THE PODCAST?

If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.