Those that work in the cybersecurity industry are accustomed to seeing many metrics, KPIs and statistics, such as mean-time, to detect and respond to a number of security incidents and known vulnerabilities.
They act as a barometer for security leaders to track how an organisation’s security programme is progressing.
Metrics are often showcased in internal business meetings that involve key personnel and operational stakeholders when discussing risk-based concerns.
By learning from the past, metrics can be used to plan for current and future security initiatives, which is pivotal when deciding where to allocate resources.
Furthermore, if visible positive steps have been made based on security outcomes, metrics can be presented to the rest of the organisation to make employees and key stakeholders aware of the progress made.
Security metrics are a critical element in bringing together business and security strategies, so they are more closely aligned. They can make the difference in winning and retaining customers who can visibly see that positive security actions are being made.
Despite the encouraging outcomes that can be achieved when showcasing security metrics, many organisations struggle to hone in on what is meaningful amongst all the noise.
It has become a challenging task for CISOs to decipher which metrics should be showcased as there is no go-to standard or template of what is regarded as acceptable or meaningful.
Of course, each organisation is unique and will have different security programmes in place that will provide different metrics.
Thankfully, there are principles that can be followed to enhance and better align security metrics that are already in place.
Expressing security metrics
It has become common for organisations to seek advice from cybersecurity consultants, particularly when implementing security programmes and meeting regulatory compliance requirements.
Their experiences can help pinpoint what is necessary when it comes to security metric reporting.
To do this effectively, the current principles should be considered:
Align with frameworks
It is beneficial for organisations to align security management with the security frameworks they are trying to comply with, whether this is to meet industry best practices or legislative standards like PCI, HIPAA or FRB.
From this, the security metrics can be categorised so that whatever is obtained will be relevant.
Evaluate individual metrics that highlight specific risk exposures
Metrics can be used to understand many aspects of the security programme including effectiveness, efficiency, compliance, cost, and overall security maturity.
These can be analysed using qualitative, quantitative, or binary measurements.
How often should security metrics be reviewed?
Security is continuous and so is reviewing security metrics. This needs to be conducted regularly to ensure the metrics are still considered relevant.
Furthermore, if the metrics have achieved the desired outcome, adjustments should be made to increase the relevant thresholds to extract more positive results and improve the security programme and overall security maturity.
Be clear, concise and support with evidence
As previously mentioned, security metrics are presented to provide context, reliability, and credibility but this needs to be conveyed in a way that can be understood by the audience.
To help articulate the relevancy of the metric, use industry reports and studies to help convey the desired message or when making recommendations regarding the security programme.
Presenting guidance
When presenting metrics, know the audience and ensure the presentation is appropriate and relevant for the audience, whether that is the Board of Directors, CEO or CISO.
Knowing the role or level of seniority will give you an indication of how much detail is needed for the presentation. When addressing key business stakeholders, it’s important that metrics are related to business outcomes.
A variety of presentation formats security professionals can use including scorecards, dashboards, and traffic lights but the bottom line is that the information needs to be communicated clearly and effectively.
Recommended
- DIGIT Movers and Shakers | July 2021
- Broadband on tap? New project to run internet cables in watermains
- Apprentice Employer of the Month | Sitekit
Moreover, do not present the metrics in isolation or rely on the audience to interpret the information without any additional context – this can cause unwanted confusion. There should be an added focus on consistency, simplicity, and clarity when presenting the metrics.
The way in which security metrics are displayed can put you and your security team in good stead to increase positive outcomes regarding the organisation’s security programme.
They can bridge the gap between credibility, context, understanding and motivation for a clear call to action to reduce risk and influence overall security strategy confidently.
Security metrics shouldn’t be underestimated and it’s time more businesses began optimising the information that’s readily available at their fingertips.





