Cybersecurity Podcasts
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityPodcastsEP264 Measuring Your (Agentic) SOC: Two Security Leaders Walk Into a Podcast
EP264  Measuring Your (Agentic) SOC: Two Security Leaders Walk Into a Podcast
CybersecurityAIEnterprise

Cloud Security Podcast

EP264 Measuring Your (Agentic) SOC: Two Security Leaders Walk Into a Podcast

Cloud Security Podcast
•February 23, 2026•29 min
0
Cloud Security Podcast•Feb 23, 2026

Why It Matters

Understanding how to measure SOC performance beyond simple speed metrics is critical as AI and automation become central to security operations, ensuring teams focus on effectiveness, not just efficiency. This episode offers practical guidance for security leaders to redesign metric programs that drive real security outcomes while adapting to rapid technological change.

Key Takeaways

  • •Traditional MTTD/MTTR metrics incentivize speed over quality.
  • •AI introduces quality and automation metrics alongside time measurements.
  • •SOC maturity measured via layered triangle of infrastructure, application, data.
  • •Regulators demand auditable AI decisions and human‑in‑the‑loop safeguards.

Pulse Analysis

In this episode the hosts and guests dissect why classic SOC metrics such as mean time to detect (MTTD) and mean time to respond (MTTR) are losing relevance. They argue that these time‑only indicators reward faster button clicks rather than effective incident resolution, and they highlight the need for quality‑focused measurements that capture automation success, false‑positive rates, and ticket accuracy. By reframing metrics around outcomes instead of raw speed, security teams can avoid the "teaching to the test" pitfall that many legacy programs fall into.

The conversation then shifts to the transformative role of AI and agentic automation in modern security operations. Guests describe a layered "triangle" or "pyramid" model that maps maturity across infrastructure, applications, and data, with each layer receiving its own detection and response metrics. As automation pushes response times from hours to seconds, the goalposts move: new metrics now blend time, quality, and AI‑driven confidence scores. Real‑world examples include automated ticket de‑duplication, AI‑evaluated ticket quality, and dynamic service‑level objectives that adapt as agents become more capable.

Finally, the panel tackles regulatory and audit challenges that accompany non‑deterministic AI decisions. Regulators expect auditable evidence of how alerts are handled, even when an AI model classifies an event as low‑risk. Organizations therefore maintain human‑in‑the‑loop safeguards, track the proportion of incidents resolved without human interaction, and measure the cost differential between human and machine effort. By publishing transparent metrics—such as automation accuracy, incident‑handling percentages, and compliance with standards like DORA—companies can demonstrate both operational efficiency and regulatory readiness while continuing to refine their SOC maturity roadmap.

Episode Description

Subscribe at YouTube

Subscribe at Spotify

Subscribe at Apple Podcasts

          Guest:

        

      

Alexander  Pabst, Global Deputy CISO, Allianz SE

Michael Sinno, Director of D&R, Google

Topics covered:

Resources:

Video version

EP252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success

EP238 Google Lessons for Using AI Agents for Securing Our Enterprise

EP91 “Hacking Google”, Op Aurora and Insider Threat at Google

EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI

EP189 How Google Does Security Programs at Scale: CISO Insights

EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil

The SOC Metrics that Matter…or Do They? blog

An Actual Complete List Of SOC Metrics (And Your Path To DIY) blog

Achieving Autonomic Security Operations: Why metrics matter (but not how you think) blog

Do you have something cool to share? Some questions? Let us know:

Web: 

            cloud.withgoogle.com/cloudsecurity/podcast

          

        

Mail: 

            cloudsecuritypodcast@google.com

          

        

Twitter: 

            @CloudSecPodcast

Show Notes

0

Comments

Want to join the conversation?

Loading comments...