How do you present a quarter with no intrusion as evidence a detection programme worked?
answer
- what was done, not what did not happen
- grade each item by what it proves
- benign true positives are evidence, not noise
- internally found versus told to you
- write the blind reading into your own deck
basics
~10 sReport what the programme observably did: near-misses contained early, alerts correctly closed as benign, techniques executed and detected, and which sources were reporting. State the 'we were blind' reading in the same deck.
solid answer
~50 sI stop reporting the incident count as the headline, because zero is unfalsifiable on its own. Instead I inventory what the programme produced: cases detected and contained before impact, with the time from first record to containment; alerts correctly closed as benign true positives, which prove rules were live and analysts were right; techniques executed against the estate and the stage each reached; and coverage of the sources those findings depended on. Then I grade each item by what it proves rather than letting the reader generalise. The part people skip is the second half: I write the competing reading - 'we may simply not have seen it' - into the same deck, list what would discriminate between the two, and say honestly which parts I could not test. If the audience discovers that alternative themselves after I have claimed a good quarter, every number I presented loses its credibility at once.
code
json · 15 lines[
{ "case": "IR-2026-014", "source": "identity provider audit log",
"opened": "2026-04-11T09:22Z", "contained": "2026-04-11T10:05Z",
"verdict": "true positive",
"action": "consent for third-party OAuth app revoked; refresh tokens revoked",
"impact": "no mailbox access observed" },
{ "case": "IR-2026-021", "source": "endpoint process telemetry",
"verdict": "benign true positive",
"action": "authorised build account; rule scoped to exclude it",
"impact": "none" },
{ "case": "PT-2026-03", "source": "purple-team exercise",
"technique": "T1053.005", "stage_reached": "analyst verdict, 12 min",
"impact": "n/a - exercise" }
...
]go deeper
Know that a report about a quiet period should describe what the team observed and did - alerts worked, cases contained, tests run - rather than resting on the absence of incidents.
Be able to say what each kind of evidence proves and what it does not: a contained case, a correctly closed benign alert, an executed technique, and the list of sources that were reporting.
An interviewer wants the second half: that you state the competing 'we were blind' reading yourself, name the discriminators you used, and refuse to quote figures - prevented breaches, matrix coverage, a mean over two cases - that you cannot defend under challenge.
Own what the organisation is permitted to claim from a quiet period, and make sure the evidence that would settle the question is being collected during the quarter rather than assembled defensively after someone challenges the report.
## The problem with the headline number A report whose top line is 'zero incidents' asks the reader to accept an unfalsifiable claim. Worse, it is read two ways by two audiences in the same room: the security team hears 'the programme held', the budget holder hears 'nothing was going to happen anyway'. The fix is to change what the report is about - from **what did not happen** to **what the programme observably did**. ## The evidence inventory, graded by what each item proves **Near-misses and early-contained cases.** A case detected and shut down before impact is the closest thing to positive proof that the loop worked end to end. Report each with the record that started it, the source it came from, the time from first observable to containment, and the impact you could and could not rule out. Example shape: a third-party application consent granted in the identity provider by an employee, spotted in the SaaS audit trail, consent and refresh tokens revoked inside an hour, no mailbox access observed. **Proves:** the source was collecting, the detection fired, a human reached the right verdict, and the response executed. **Does not prove:** anything about behaviours in parts of the estate with no equivalent source. **Benign true positives.** Alerts where the rule correctly identified the behaviour but the actor was authorised. These are often dismissed as noise, and in a quiet quarter they are among your best evidence: they show the sensor was live and the analyst judgment was sound. **Proves:** rules were firing on real behaviour and were being adjudicated correctly. **Does not prove:** that the same rules would catch an unauthorised actor performing the behaviour deliberately quietly. **Executed-technique results.** Adversary behaviours deliberately run against production, recorded by the stage they reached - telemetry present, detection fired, analyst acted, response landed. **Proves:** the pipeline works for those techniques, on those hosts, at that hour. **Does not prove:** anything about untested techniques, which must appear in the same table. **Source coverage.** Which parts of the estate were feeding the platform for the whole period and which had no source at all. A quarter is only as quiet as the places you were looking, and stating the unlit areas yourself is far stronger than having them found. **How cases arrived.** The split between findings your own detections raised and findings someone else told you about - a supplier's breach notification naming your tenant, a report from an employee, an external notification. A quarter whose only findings arrived from outside is a quarter your sensors did not contribute to, and that ratio is one of the few honest programme metrics available when nothing was declared. ## Write the competing reading yourself The reading you are most exposed to is: *we saw nothing because our sensors were blind.* Put it in the report in your own words, then show what you did to test it. The discriminators are the ones above - sources demonstrably reporting throughout the period, techniques executed and caught, cases detected internally rather than reported to you. Where you cannot discriminate, say so and name the gap. This is not humility for its own sake. A report that only advances one reading of the evidence is an advocacy document, and the moment a sharp reader constructs the alternative on their own, the whole set of numbers is retrospectively suspect. Stating it first makes you the person who tested it rather than the person who omitted it. ## What not to claim - Do not claim breaches prevented. You cannot count events that did not occur, and the moment you assert a number you cannot defend, the rest of the report inherits the doubt. - Do not present a coverage percentage over a framework's full technique matrix as though it were a measured figure. - Do not quote a mean time to detect over a quarter with two cases in it. A mean of two is an anecdote wearing a statistic's clothes; report the cases individually. - Do not report the alert-closure ratio as an accuracy score without saying it is computed only over alerts that fired. ## The shape that lands One page: what we observed and shut down, with times; what we deliberately tested and what happened; where we were and were not looking; the alternative explanation and how we tested it; and the two or three decisions we want from this audience. Everything else is an appendix.
- Should you really put 'we may simply not have seen it' into your own report?Yes. It is the first alternative any sharp reader constructs, and if they construct it after you have claimed a good quarter, every figure you presented becomes suspect at once. Stating it and showing how you tested it - sources reporting throughout, techniques executed and detected, findings raised internally rather than by outsiders - makes you the person who checked rather than the person who omitted.
- You had two contained cases all quarter. Can you report a mean time to detect?Not usefully. A mean over two cases is an anecdote in statistical clothing, and it will be compared against a benchmark it cannot support. I report the two cases individually with their timelines and the source that started each one, which is both more honest and more persuasive than a number with an invisible sample size of two.
- How do you handle a finding that a supplier reported to you rather than one you detected?I report it prominently, because the internally-detected versus externally-reported split is one of the few honest programme metrics available when nothing was declared. It is a genuine gap, and naming it myself buys the credibility that carries the rest of the report. It also converts neatly into a concrete ask: the source or detection that would have caught it first.
saying these in an interview costs you the question
- Leads with the zero and calls the quarter a success
- Claims a number of breaches prevented
- Leaves the blind-sensors reading for the audience to find
- Quotes a mean time to detect over two cases
- Presents a technique-matrix coverage percentage as measured
- Discards benign true positives as noise rather than evidence