- Percentage of priority assets covered
- Percentage of unmanaged assets discovered
- Network segments monitored
- Endpoint agent health
- Cloud accounts and subscriptions monitored
- Identity systems integrated
- Telemetry ingestion latency
- Data-source availability
- Event parsing and normalization failures
- Retention achieved by data class
- Mean time to detect
- Detection rate for tested attack scenarios
- ATT&CK coverage for prioritized techniques
- Percentage of detections using multiple telemetry sources
- High-confidence detection rate
- False-positive and non-actionable alert rates
- Percentage of incidents detected before material impact
- Detection rule precision after tuning
- Material coverage gaps identified and closed
- Mean time to acknowledge
- Mean time to determine scope
- Mean time to reach an analyst decision
- Number of tools used per investigation
- Number of manual enrichment steps
- Percentage of cases with complete evidence
- Time spent reconstructing attack timelines
- Analyst hours per incident
- Percentage of investigations completed within SLA
- Mean time to contain
- Percentage of incidents contained within target time
- Number of automated actions per incident
- Playboo execution success rate
- Response approval delay
- Rollback frequency
- Failed integration actions
- Percentage of containment actions completed through the XDR workflow
- Reduction in duplicated tools or capabilities
- Cost avoided through consolidation
- SOC capacity recovered
- Improvement in incident response readiness
- Audit evidence completeness
- Reduction in material security incidents
- Percentage of high-risk assets with validated detection coverage
- Improvement in service restoration time
- Security control gaps identified before an incident
- Executive confidence in reported security outcomes