Roll MTTD, MTTR, false-positive rate, ATT&CK coverage, staffing and automation into one weighted SOC health score.
Timing metrics are scored logarithmically because the improvement from 48 hours to 24 matters far more than from two hours to one, and a linear scale would make already-fast SOCs chase meaningless gains. Coverage carries the largest single weight, since speed on a technique you cannot see is worth nothing. SOC reporting tends to be a wall of unweighted metrics that hides the actual constraint; one weighted score with a named weakest area turns a monthly report into a decision about where the next pound goes.
SOC Health Score
Health = 0.24 × coverage + 0.22 × detection speed + 0.18 × response speed + 0.18 × alert quality + 0.18 × capacity, each normalised to 0–100.
Capacity component
Capacity = 0.5 × staffing% + 0.25 × scaled automation% + 0.25 × backlog score, where backlog score = 100 − 10 × median backlog days.
Health = 0.24 × coverage + 0.22 × detection speed + 0.18 × response speed + 0.18 × alert quality + 0.18 × capacity, each normalised to 0–100. Timing metrics are scored logarithmically because the improvement from 48 hours to 24 matters far more than from two hours to one, and a linear scale would make already-fast SOCs chase meaningless gains. Coverage carries the largest single weight, since speed on a technique you cannot see is worth nothing.
SOC reporting tends to be a wall of unweighted metrics that hides the actual constraint; one weighted score with a named weakest area turns a monthly report into a decision about where the next pound goes.
This calculator takes 8 inputs: Mean time to detect, Mean time to respond, False discovery rate of the alert queue, In-scope ATT&CK technique coverage, Staffed FTE against the required rota, Triage workflow automated, Case backlog age at the median, Critical assets sending required telemetry. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because undetected activity has no MTTD at all. A SOC that responds in twenty minutes to 40% of techniques is more exposed than one responding in two hours to 85%, and averaging unweighted metrics hides exactly that trade.
Use it as a diagnostic that points at the weakest component, not as a target in itself. Any single number becomes gameable once bonuses depend on it — usually by suppressing noisy detections, which improves the score and worsens the security.