CORRELATING SOC MATURITY LEVELS WITH INCIDENT RESPONSE OUTCOMES: AN EMPIRICAL STUDY

Main Article Content

Sumanshu Sohal

Abstract

The growing complexity and frequency of cyber attacks require organizations to reassess how they evaluate their defensive effectiveness. This paper empirically examines the relationship between Security Operations Center (SOC) maturity and incident response performance through a threat-informed lens. We introduce and apply a five-level quantitative maturity model based on organizational implementation of the MITRE ATT&CK framework, evaluating four key areas: Cyber Threat Intelligence Integration, Detection Engineering, Adversary Emulation, and Incident Response Automation. Using a synthesized multi-organization dataset, we conducted correlation and regression analyses to assess how maturity influences Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Results demonstrate a strong negative correlation between higher ATT&CK-driven maturity and response times, indicating that organizations with more advanced threat-informed practices detect and remediate incidents significantly faster. These findings provide quantitative, practice-oriented justification for investing in the ATT&CK framework, offering a clear guide for optimizing real-world SOC operations and allocating resources to enhance cyber resilience.

Article Details

Section
Articles