While many IT, security, and risk professionals have developed good metrics and visuals for communicating internally about cyber risk, such as the safety cross and pareto charts, reporting on cybersecurity to non-technical individuals remains challenging.
Other departments have simple numbers that indicate their performance, like new leads, sales per month, ticket resolution time, or revenue. Cybersecurity, meanwhile, is much more difficult to quantify.
Choosing the right KPIs to represent your cybersecurity program can be a high-stakes exercise. In a report to the Board, for example, good KPIs can make the difference between an approved budget or slashed resources.
To help with your next report, we put together 6 cybersecurity KPI examples that can be used to communicate cyber risk and security performance to non-technical personnel.
In compiling this list, we tested potential KPIs against the following criteria:
-
Does it accurately communicate something important about cybersecurity performance? Metrics that rely too heavily on guesswork or have large margins of error do not make good KPIs. Accurate metrics that focus on insignificant areas of cybersecurity aren’t helpful either.
-
Is it easily understood, even by individuals with non-technical backgrounds? The individuals reading your report should be able to comprehend it without you being in the room to explain it to them.
-
Is it relatively simple to calculate? Good KPIs should be checked often in order to track progress over time. If you have to spend hours exporting/deriving/calculating a metric, those hours will add up over weeks and months.
Mean Time to Detect
In a security context, mean time to detect (MTTD) is a measurement of how long it takes the cybersecurity team or security operations center to become aware of a potential security incident (on average). This statistic should be relatively simple to find on your security incident and event management (SIEM) platform.
MTTD shows readers of your report how long security threats are going unnoticed within your organization’s systems. Long MTTD timeframes can indicate an increased risk of threat actors accessing sensitive data.
Mean Time to Resolve
Mean time to resolve (MTTR) is similar to MTTD, but accounts for how long it takes the cybersecurity team or security operations center to remediate a threat after it has been discovered. This can also be calculated using data from your SIEM.
If MTTR times are increasing, that indicates to the readers of your report that more resources are needed in order to mitigate cyber threats.
Bitsight Security Rating
A Bitsight Security Rating is a metric for describing overall cybersecurity performance based on externally observable indicators. The rating is informed by data from over 120 sources on compromised systems, security diligence, user behavior, and data breaches.