Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Managed Security Provider Track Whether It Is Meeting Each Client's Contracted Response Targets?
Problems We Solve

How Does a Managed Security Provider Track Whether It Is Meeting Each Client's Contracted Response Targets?

MSSPs promise different response targets to each client but cannot see if they meet them. We build target tracking that times every alert against its contract.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Response targets are hard to track because each client's contract sets its own targets by severity and hours of cover, the clock starts in one tool and stops in another, and the PSA's own reporting does not know the contract. We build target tracking that reads each client's terms, times every alert and incident from detection to acknowledgement and response, warns the shift before a target is missed, and reports performance per client accurately.

A question you cannot answer quickly

A managed client's head of IT asks, a week before their renewal, whether you met your response targets last quarter. Their contract says critical alerts are acknowledged within a set time around the clock, high alerts within a longer time during business hours, and so on. Your answer should be a report. Instead it is a couple of days of an analyst exporting tickets from the PSA and alerts from the SIEM, matching them up, and working out which clock applied to which alert.

Along the way they find problems. Some alerts were acknowledged in the SIEM console but the ticket was opened later, so the PSA shows a slow response that did not really happen. Some high alerts arrived on a Sunday, when the contract only counts business hours. A few were genuinely slow, during a busy night shift.

The report goes out. It is probably right. Nobody would want to bet the renewal on it.

And the genuinely slow ones were found months after the fact, when nothing could be done about them except explain.

Why targets are hard to measure

  • Every client contract has its own targets, severities and hours of cover.
  • The clock starts at detection in one tool and stops at acknowledgement or response in another.
  • Severity sometimes changes during triage, which changes the target that applies.
  • Business hours, bank holidays and client-specific time zones affect when the clock runs.
  • PSA reporting measures ticket times, which may not be what the contract measures.

What not knowing costs

Blind spotConsequence
Near misses not visible liveTargets missed that could have been met
Wrong clock used in reportsPerformance overstated or understated
Manual quarterly reportsAnalyst days lost before each renewal
Pattern of slow nights not spottedStaffing problem continues
Service credits unclearDisputes with clients about what is owed

Targets are what a managed security client is paying for. If you cannot show them clearly, the client has to take your word for it, and at renewal that is not enough.

The target tracking we build

  1. Each client's contract terms are recorded as rules: severities, targets for acknowledgement and response, hours of cover, holidays and time zone.
  2. Alerts and incidents are read from your SIEM, EDR and PSA by API, and linked so that one timeline shows detection, acknowledgement, response and closure, whichever tool each step happened in.
  3. The right target is applied to each alert, including any severity change during triage, and the clock runs only when the contract says it should.
  4. A live view for the shift shows open alerts approaching their target, so the team can act before the target is missed rather than after.
  5. Monthly and quarterly reports per client show performance against each target, with every miss listed and a space for the reason.
  6. Where your contracts include service credits, the report shows which misses may be relevant, for your team to review under the contract terms.

We check with you how each step is recorded in your tools before building. Where a step is not recorded anywhere, we say so and suggest the smallest change that captures it.

What the SOC and account leads see

The shift lead sees targets approaching in real time. The SOC manager sees patterns, such as which shifts or alert types miss most often, which points to staffing or tuning. Account leads have a report per client, generated rather than built, that they can put in front of a client with confidence.

When a client asks at renewal whether you met your targets, the answer is a report you already have, with the misses explained. That is a much better conversation than a promise to look into it.

New contracts benefit as well. When sales propose tighter targets to win a deal, the history shows whether your team can meet them on the relevant shifts, before the promise is signed.

Signs you need this

  • Nobody can say, today, whether you met each client's targets last month.
  • Performance reports are built by hand before renewals.
  • PSA ticket times are used as a stand-in for contract response times.
  • Near misses are only noticed after the fact.
  • Different clients' targets are tracked the same way.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Which tools does this read from?

Your SIEM, EDR and PSA, where they offer APIs, which most do. We check each before scoping.

Can it handle clients with different hours of cover?

Yes. Each client's hours, holidays and time zone are part of their rules.

Does it calculate service credits?

It lists misses that may be relevant under each contract. Whether a credit is due is a decision for your team under the contract.

Can clients see their own figures?

If you want, a client view or a monthly report can be shared with them.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →