skip to content

Reporting a Quiet Quarter

A quarter with no declared intrusion is either good defence or blind sensors, and the report has to say which. Interviewers probe how you argue for a function whose best output is an absence.

on this pageshow

explore

questions

4

What does 'zero security incidents this quarter' actually prove about your estate?

level: juniorimportance: must knowfreq 52%

answer

  1. a count of outputs, not of events
  2. four stages must all work
  3. silence has two competing readings
  4. no record of what was missed
  5. false-negative rate is not computable

basics

~20 s

It proves only that nothing was detected, worked and declared. Zero is consistent with a genuinely quiet estate and with an intrusion nobody saw. The number on its own cannot tell you which one you had.

solid answer

~50 s

An incident count is an output of your own pipeline, not a measurement of the estate. For a case to become a '1', telemetry has to arrive, a detection has to fire on it, someone has to work the alert, and someone has to declare an incident. A break at any of those four stages produces exactly the same zero as a quarter in which no adversary ever touched you. A non-event leaves no record, so a detection programme's false-negative rate cannot be computed from its own output. That is why I never report the zero alone: I report it beside the things that do discriminate between the two readings - which log sources were reporting all quarter, which adversary techniques were executed against production and detected, and the near-misses that were caught and contained early.

go deeper

for a junior

Be ready to say plainly that the count measures your own detection and declaration process, not the estate, and to name the two readings: genuinely quiet, or blind. Know the difference between an alert, a case and a declared incident.

for a middle

Explain the four stages behind a declaration - collection, detection, triage, declaration - and show why a break in any one of them produces the same zero. Be able to say why recall cannot be computed from a SIEM's own output while precision can.

for a senior

An interviewer expects you to turn the zero into a testable claim: name the coverage evidence, the executed-technique results and the contained cases you would put beside it, and state which reading each one rules out.

for a principal

Own the reporting standard. Decide what the organisation is allowed to claim from a quiet period, insist the competing reading appears in the same report, and make sure the evidence that would settle it is being collected before the quarter ends, not after someone challenges the number.

## What the number actually counts 'Zero security incidents' is a count of **declarations**, and a declaration sits at the end of a chain with four independent stages: 1. **Collection** - the relevant records reached the platform at all (endpoint process telemetry, identity sign-in logs, a cloud control-plane audit trail, mail, proxy, DNS). 2. **Detection** - a rule or an analytic actually matched the behaviour in those records. 3. **Triage** - a human (or an automation) worked the resulting alert rather than letting it age out of a queue. 4. **Declaration** - somebody judged the case serious enough to call it an incident. A failure at any single stage yields the same output as a genuinely uneventful quarter. That is the whole difficulty: **zero has two readings - 'nothing happened' and 'nothing was seen' - and the number itself does not distinguish them.** ## Why absence is not evidence here Every other number on a SOC dashboard is built from things that happened: alerts fired, cases opened, hosts isolated. A missed intrusion produces no record of its own missing-ness. There is no queue of 'attacks we failed to detect' to count, which means the **false-negative rate of a detection programme is not computable from the programme's own output.** An accuracy figure such as precision can be computed over alerts that did fire; recall cannot, because the denominator - everything that actually happened - is unobservable. Anyone who quotes you a false-negative rate straight off a SIEM dashboard has computed it against a set of known test cases, not against reality. The direction of the claim matters and is where candidates fail. A detection firing proves that **a rule matched records** - not that something malicious occurred. A detection not firing proves that **the rule did not match the records it received** - not that the estate is clean, and certainly not that the adversary was absent. ## Alerts, cases and incidents are different counts A quarter with zero incidents is almost never a quarter with zero alerts. Most alerts close as **false positives** (the rule was wrong about maliciousness) or as **benign true positives** (the rule correctly identified the behaviour, but the actor was authorised - an administrator running a credential tool during a sanctioned rebuild, a backup agent reading every file on a share). Those closures are real work and real evidence that the pipeline was live; they simply never became incidents. Reporting 'zero incidents' while never mentioning the several hundred alerts that were worked hides your strongest evidence. ## What makes a zero credible The zero becomes meaningful only when it is presented next to evidence about the pipeline itself: - **Coverage** - which sources were sending records for the whole period, and which parts of the estate had no source at all. A quarter is only as quiet as the places you were looking. - **Executed-technique results** - techniques deliberately run against production during an exercise, and whether telemetry, rule, analyst and response each did their part. Executing the behaviour is the only way to test a detection whose normal output is silence. - **Near-misses and contained cases** - cases detected and shut down before impact. They are the closest thing you have to positive evidence that the loop works end to end. - **How cases arrived** - internally detected versus reported to you by a third party. A quarter whose only findings came from outside is a quarter your own sensors did not contribute to. ## What to say in an interview Say what the zero is an output of, name the two competing readings, and name the discriminators you would bring to tell them apart. The weak answer treats the zero as a scoreboard - 'we had a good quarter' - and the strong answer treats it as a hypothesis that needs supporting evidence like any other.

  • Does a quarter with zero incidents mean no alerts fired?
    Almost never. Most alerts close as false positives, where the rule was wrong about maliciousness, or as benign true positives, where the behaviour was real but the actor was authorised. Those closures are worked cases and they are evidence the pipeline was live. Reporting only the incident count throws that evidence away.
  • Your CEO asks whether zero incidents means the company is secure. What do you say?
    That it means nothing was detected and declared, which is good news only if the sensors were working and looking in the right places. I would offer the two readings explicitly, then say which one the evidence supports: sources reporting throughout, techniques executed against production and caught, and cases contained early. Without that, the zero is unfalsifiable.
  • Which single piece of evidence most strengthens a zero-incident claim?
    A record of adversary behaviour deliberately executed against the production estate and detected end to end. It is the one test that produces an observable output from a system whose normal output is silence, and it directly attacks the 'we were blind' reading rather than merely asserting the opposite.

A year with no smoke-alarm activations tells you nothing until you know whether the battery was in. The alarm's silence is the same sound in a house with no fires and in a house with a dead sensor.

saying these in an interview costs you the question

  • Treats zero incidents as proof the controls worked
  • Says absence of alerts proves absence of an adversary
  • Confuses alert volume with declared-incident count
  • Quotes a false-negative rate read off a dashboard
  • Reports the zero without saying what was being watched
  • Calls every closed alert a false positive

context

open as a page

What does a purple-team test where your detection fired prove about a quiet quarter?

level: middleimportance: should knowfreq 42%

basics

~20 s

It proves the chain from telemetry to rule to analyst worked for the one technique executed, on the hosts in scope, at that hour. It is a positive control for the pipeline, not evidence no adversary was present.

open as a page

How do you present a quarter with no intrusion as evidence a detection programme worked?

level: seniorimportance: should knowfreq 38%

basics

~10 s

Report what the programme observably did: near-misses contained early, alerts correctly closed as benign, techniques executed and detected, and which sources were reporting. State the 'we were blind' reading in the same deck.

open as a page

The CFO reads two quiet years as over-investment and wants your second analyst cut - what do you argue?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Argue about capability, not fear. Say what the second person actually delivers in hours and cases, present the options with their honest costs, and let the budget holder choose knowingly. Never claim a number of breaches prevented you cannot evidence.

open as a page