TL;DR: SOC metrics still centred on volume can cause teams to optimise activity rather than risk reduction, creating noise, mis-prioritisation, and inefficient remediation, according to Hadrian. The underlying governance issue is that operational reporting can reward throughput while obscuring whether detection and exposure management are actually improving.
NHIMG editorial — based on content published by Hadrian: If your SOC metrics still reward volume, you are redesigning the job incorrectly
Questions worth separating out
Q: How should security teams measure whether exposure management is actually reducing risk?
A: Measure whether validated attack paths, privileged access paths, and high-risk exposures are being removed, then confirm those fixes with retesting.
Q: Why do volume-based SOC metrics create security blind spots?
A: Because they reward outputs that are easy to count, not outcomes that reduce attack surface.
Q: What do security teams get wrong about offensive testing metrics?
A: They often treat the number of tests or findings as proof of maturity.
Practitioner guidance
- Redesign SOC scorecards around exposure reduction Track whether validated attack paths were removed, not how many alerts, scans, or tests were produced.
- Add identity-specific risk measures Include standing privilege counts, stale secrets, and time-to-revoke for privileged accounts, service accounts, API keys, and tokens.
- Close the loop between testing and remediation Require every high-risk finding from offensive validation to map to an owner, a fix date, and a retest result.
What's in the full article
Hadrian's full blog post covers the operational detail this post intentionally leaves for the source:
- How Hadrian frames the metrics problem in offensive security and why volume can distort priorities
- The practical implications of agentic-powered testing for teams comparing manual and automated approaches
- How the source article connects measurement quality to remediation outcomes and SOC effectiveness
👉 Read Hadrian's post on why SOC metrics should measure outcomes, not volume →
SOC metrics and volume-based scoring: are your controls aligned?
Explore further
Volume metrics create governance theatre when they are not tied to exposure reduction. Security teams can optimise for visible output while the real risk remains unchanged. That is particularly damaging in offensive security, where the point is to expose what matters, not to generate a higher count of activity. Practitioners should treat any metric that cannot be linked to a change in attack surface as incomplete.
A question worth separating out:
Q: How can organisations tell if their reporting model is driving the wrong behaviour?
A: Look for incentives that increase activity without decreasing exposure, such as more scans with the same unresolved findings or more detections with no faster remediation. When metrics reward visibility over risk reduction, the programme is optimising appearances instead of security.
👉 Read our full editorial: SOC metrics that reward volume can distort security work