Useful triage measures show whether material alerts receive timely, explainable decisions: backlog by age and severity, time-to-first-review distributions, missing-context rates, duplication, closure reasons, incident escalation, reopened work and source or parser failures. Alert volume by itself cannot distinguish better detection from noisier telemetry.
External reference
The external measurement principles come from NIST SP 800-55 Vol. 1. The specific alert-triage measure set is a Cybatar-authored application of those principles to security operations.
Primary source →Measures to retain
Material backlog and ageing
Track unresolved alerts by materiality and age bands so old high-impact work cannot disappear inside a total count.
Time to first meaningful review
Use distributions and percentiles rather than only an average; separate queue delay from analyst investigation time when possible.
Context completeness
Measure how often asset, identity, source, severity or correlation context needed for a decision is missing or stale.
Disposition quality
Retain closure reason, escalation, suppression rationale and reopen events so teams can test whether triage decisions remain defensible.
Incident conversion
Measure which alert classes become incidents, but interpret the ratio with severity, detection design and investigation policy rather than treating a low conversion rate as automatically bad.
Source and parser health
Report collection outages, parsing failures and field-quality gaps that make apparent alert improvement unreliable.
Operating method
Segment the queue
Separate by severity, source, business service and age before drawing conclusions.
Preserve disposition evidence
Require meaningful closure reasons and link escalated alerts to incidents.
Correlate with source health
A sudden drop in alerts can be a telemetry failure, not an improvement.
Review workload and outcomes together
Use backlog, time, context and escalation together rather than optimise one at the expense of another.
Measurement anti-patterns
Relevant Cybatar sources
Claim boundary
No single alert metric proves analyst quality, detection effectiveness or security posture. Changes may be caused by telemetry, policy, staffing, threat activity, classification or workflow changes.
Cybatar publishes measurement and reporting guidance as a first-party operating model. Examples are not universal benchmarks, regulatory thresholds, promises of security outcomes or evidence that a particular deployment is effective.