Agent Foskett Academy • Microsoft Security Copilot • Module 4 • Lesson 35

Lesson 35 — Measuring Analyst Efficiency

Security Copilot can make analysts faster, but speed alone does not tell us whether security operations have improved.

A mature SOC measures whether analysts reach accurate conclusions sooner, investigate more consistently, explore evidence more deeply and spend less time on repetitive work.

This lesson builds a practical model for measuring Security Copilot without confusing AI activity with genuine productivity.

The objective is not more AI activity. The objective is better security operations.
Agent Foskett Measuring Analyst Efficiency lesson
What you will learn

Measure the operational value of Security Copilot using meaningful SOC outcomes.

✓ Establish useful baselines
✓ Measure time and quality
✓ Evaluate consistency and depth
✓ Avoid misleading AI metrics

The measurement cycle

Establish baseline

Select repeatable SOC activities

Measure time, quality and effort

Introduce Security Copilot

Measure the same activities again

Compare speed AND quality

Review consistency, depth and workload

Check security outcomes

Refine workflows and measure again

What should a SOC measure?

AreaQuestionExample indicator
TimeIs repetitive work taking less time?Median triage or investigation time.
QualityAre conclusions accurate and evidence-based?Peer-review corrections.
ConsistencyAre required investigation steps followed?Evidence-check completion.
DepthAre analysts exploring relevant evidence?Validated pivots and data sources.
WorkloadHas repetitive effort reduced?Time spent summarising and documenting.
ResponseAre meaningful decisions happening sooner?Time to escalation or containment.
LearningAre analysts becoming more capable?Independent investigation performance.

Learning objectives

Establish useful baselines, measure time and quality, evaluate consistency and depth, assess workload, connect AI use to operational outcomes and avoid misleading vanity metrics.

Efficiency is not just speed

An analyst who closes an incident five minutes faster but misses a compromised account has not become more efficient. Useful efficiency combines time, quality and outcome.

Establish a baseline first

Record how selected SOC activities perform before a new Copilot workflow is introduced.

Choose comparable work

Compare similar incident types and complexity. A simple phishing alert should not be compared directly with a multi-stage identity compromise.

Measure median time

Median values can be more useful than averages when a few unusually long investigations would distort the result.

Measure triage time

Track how long analysts take to understand an alert, identify affected entities and decide whether deeper investigation is required.

Measure investigation time

Track time from investigation start to a defensible conclusion, escalation or response decision.

Measure reporting time

Copilot may reduce the time required to turn validated technical evidence into readable reports and handovers.

Measure repetitive effort

Look for reductions in manual summarisation, formatting, query explanation and evidence organisation.

Measure investigation quality

Review whether conclusions are supported by evidence, important telemetry was checked and uncertainty was documented.

Track corrections

Record how often peer review identifies inaccurate statements, missed evidence or unsupported conclusions.

Track missed evidence

A faster investigation is not an improvement if analysts overlook relevant identity, endpoint, email or cloud evidence.

Measure validation behaviour

Check whether analysts continue opening source telemetry rather than accepting generated summaries as evidence.

Measure false confidence

Review cases where generated language sounded more certain than the underlying evidence justified.

Measure escalation quality

Determine whether escalations contain enough validated evidence for responders to act without repeating basic investigation work.

Measure consistency

Verify whether required investigation steps are being followed across analysts and shifts.

Use investigation checklists

Measure completion of required evidence checks for repeatable scenarios such as phishing and compromised accounts.

Compare analyst variation

Look for excessive differences in investigation quality between analysts handling similar incidents.

Measure handover quality

Review whether handovers preserve status, evidence, uncertainty, owners and next actions.

Measure investigation depth

Efficiency should create more time for useful reasoning, not simply faster closure.

Count meaningful pivots

Review whether investigations explore relevant users, devices, IP addresses, applications and resources.

Measure telemetry coverage

Check whether analysts use appropriate identity, endpoint, email, cloud and SIEM evidence.

Measure hypothesis testing

Look for evidence that analysts tested alternative explanations rather than only confirming the first theory.

Do not reward unnecessary depth

More queries are not automatically better. Investigation depth must remain relevant to risk and evidence.

Measure analyst workload

Efficiency gains should reduce repetitive effort and create capacity for investigation, hunting, engineering and learning.

Measure queue pressure

Check whether priority incidents are processed more effectively without rushed closures or reduced quality.

Measure time recovered

Track where saved time goes. Ideally it becomes capacity for higher-value security work.

Measure analyst experience

Combine operational data with structured analyst feedback about usefulness, friction, trust and workflow fit.

Measure analyst development

Copilot should support capability growth rather than dependency on generated answers.

Test independent skills

Periodically assess whether analysts can interpret telemetry, construct queries and explain reasoning without Copilot.

Measure query improvement

Track whether analysts improve at understanding and refining KQL rather than merely copying generated queries.

Measure reasoning quality

Review whether analysts can explain why evidence matters and what alternative interpretations remain possible.

Operational outcomes matter

Ultimately, Copilot should contribute to better security decisions and more effective SOC operations.

Time to escalation

Measure whether serious incidents reach the correct responder sooner with enough evidence to justify escalation.

Time to containment

Compare how quickly validated incidents move from detection to approved containment where appropriate.

Reopened incidents

An increase in reopened incidents can reveal that apparent efficiency is actually premature closure.

Repeat investigation work

Measure how often senior analysts must repeat basic evidence gathering because the original investigation was incomplete.

Detection improvement

Recovered capacity may enable better hunting, tuning and detection engineering.

Do not measure prompt volume

Ten prompts do not represent ten units of productivity. One precise prompt may be more useful than twenty vague ones.

Do not measure words generated

Longer summaries can increase review time and hide the evidence that actually matters.

Do not reward blind adoption

High Copilot usage is not automatically desirable if analysts use it where traditional tools are faster or more reliable.

Do not measure speed alone

Time savings must be reviewed alongside accuracy, evidence quality and security outcomes.

Beware selection bias

If Copilot is only used on easy incidents, measured improvements may not represent the broader SOC workload.

Beware novelty effects

Early changes may reflect enthusiasm, training effort or unfamiliarity. Measure over a meaningful period.

Create a balanced scorecard

Combine speed, quality, consistency, depth, workload and operational outcomes rather than relying on one KPI.

Use trends, not snapshots

Track measurements over time to distinguish sustainable improvement from temporary variation.

Segment the results

Review metrics by incident type, analyst experience and complexity where comparisons are meaningful.

Review unintended consequences

Look for over-trust, skill erosion, unnecessary prompting, sensitive-data issues and premature closure.

Turn measurement into improvement

Use findings to refine promptbooks, training, review gates, workflows and governance.

Final measurement principle

If Copilot saves time while maintaining or improving investigation quality and security outcomes, the efficiency gain is meaningful.

Example SOC efficiency scorecard

MetricBaselineWith CopilotInterpretation
Median initial triage time12 min7 minPotential efficiency gain.
Incident summary preparation18 min6 minStrong reduction in repetitive work.
Peer-review corrections8%7%Quality maintained or improved.
Evidence checks completed82%95%Improved consistency.
Incidents reopened3%3%No sign of premature closure.
Proactive hunting4 hrs/week7 hrs/weekRecovered capacity redirected.

Important: These figures are illustrative training examples, not Microsoft benchmarks. Each organisation should establish its own baseline.

Example measurement prompt

Review the supplied SOC performance data for the pre-Copilot and Copilot-assisted periods. Compare: 1. Median triage time 2. Median investigation time 3. Reporting and handover preparation time 4. Peer-review corrections 5. Required evidence checks completed 6. Incidents reopened 7. Time to escalation 8. Time to approved containment 9. Analyst time available for proactive hunting 10. Analyst feedback on workflow friction Identify improvements, regressions and inconclusive areas. Do not treat prompt count or generated word count as productivity. Separate measured facts from interpretation.

Agent Foskett investigation: “The analyst who won the prompt competition”

The monthly dashboard looked impressive

One analyst had used Security Copilot 684 times

Someone declared him the SOC's “AI productivity champion”

Agent Foskett checked the incident data

His median investigation time had barely changed

Several prompts repeatedly requested the same summaries

Peer review found unsupported conclusions

Another analyst had used Copilot far less

Her handover time had dropped by half

Her evidence-check completion had improved

She was spending more time threat hunting

The dashboard was redesigned

Prompt count disappeared

Time, quality, consistency and outcomes took its place
The analyst who talks to Copilot the most is not necessarily the analyst getting the most value from it.

Key takeaways

  • Efficiency combines speed, quality and security outcome.
  • Establish a baseline before claiming improvement.
  • Compare similar investigation types and complexity.
  • Track evidence quality and peer-review corrections.
  • Measure consistency and meaningful investigation depth.
  • Check whether recovered time moves to higher-value work.
  • Monitor analyst development and dependency.
  • Prompt count is a poor productivity measure.
  • Use a balanced scorecard and trends over time.
  • Measure whether Copilot helps the SOC make better decisions with less unnecessary effort.

Related Agent Foskett resources

Lesson 35 measures whether the daily Security Copilot operating model is delivering meaningful value.

Continue Module 4 — Operational Security Copilot

The next lesson turns to governance and access controls required to operate Security Copilot responsibly.
⬅ Previous lesson
Lesson 34 — Security Copilot in Daily OperationsIntegrate Copilot into daily SOC operations.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 4
Lesson 36 — Governance and Access ControlPlan roles, least privilege, plugin access, auditing, ownership and acceptable-use controls.

How do you measure Security Copilot analyst efficiency?

Measure Security Copilot with a balanced combination of time saved, investigation quality, consistency, depth, workload and operational security outcomes rather than prompt volume alone.