
MSSP SOC reporting has a metrics problem #03
First part of my conversation with Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment. CHAPTERS (00:00) - In this episode & intro (01:20) - Dave’s introduction (04:34) - Dave jokes that he “tortures” vendors for a living (07:47) - The story behind his talk at Security BSides London, “You Scored 46” - and why SOC metrics matter (12:34) - For the purposes of his talk, he went to AI and asked for a monthly service delivery report + scope + inventory (15:57) - AI averages the internet, vendor claims & pure filler slides (17:00) - The industry doesn't know how to measure SOC performance: MSSP economics & honesty (24:30) - Those monthly service delivery meetings should be more about what is happening rather than the stats (30:29) - Goodhart’s Law: when metrics create the behaviour you want to avoid (33:28) - The MSSP value paradox: they want to bring value, but it's good to have “boring customers” too (38:59) - Why we need to keep clarifying the terminology: alerts, incidents & events (42:52) - What is even an incident? It depends who you ask: security vs data incidents GUEST Dave MCKENZIE, Cyber Risk Reducer, at Cyber Increment LinkedIn: https://www.linkedin.com/in/davewmckenzie/ HOST Michael VIRGONE LinkedIn: https://www.linkedin.com/in/michaelvirgone/ GET IN TOUCH If something in an episode made you think, or you have an idea for a conversation, feel free to reach out. I'd love to hear from you. LinkedIn is my preferred way to get in touch, but you can also reach me by email. LinkedIn: above Email: hello@cyberallday.io Website: https://cyberallday.io/ ENJOYING THE PODCAST? If you find Cyber All Day useful, a rating or review on your podcast app, my website or YouTube really helps people discover it 👌. And if you have a minute, I'd love to hear what you think.