In today’s landscape, managing your internal security processes as well as creating a third-party vendor risk management program should be top of mind, but prioritizing a solid understanding of the metrics surrounding your cybersecurity programs almost just as important. These metrics should dive deeper than “yes” or “no” questionnaire answers, but should help you gain a more comprehensive understanding of where you and your third parties fall when it comes to proactively mitigating cyber risk.
Where To Start When Tracking Cybersecurity Metrics
1. Number of botnet infections and detection deficit.
This is the top cybersecurity metric that every organization must monitor. By examining how many botnet infections have taken place on your network over a given period of time—and what types of botnets you’ve dealt with—you can better prepare for, and protect against, these types of attacks as well as learn from previous examples.
If your organization successfully tracks botnet infections, you may be able to shorten the detection deficit, or the time between the point of discovery and the point of compromise. In other words, the greater the speed at which you can identify that something is happening on your network and appropriately respond to it, the greater the likelihood of preventing the hacker from getting a foothold in your organization. If you’re able to keep the detection deficit as close to zero as possible, you’ll be in far greater shape.
The problem is for many organizations, fixing a gap between the intrusion and the solution can take hours, days, weeks, or even months to identify and remediate a security breach. By closely monitoring the number of botnet infections that take place on your organization’s network, as well as the time it takes you to remediate those infections, security leaders can take important steps towards managing their security.
2. Percentage of employees with privileged access to corporate information.
Gaining control of an employee’s login information or account access gives a hacker everything they need to take control of a corporate infrastructure and cause significant damage. Knowing who has super-user access and monitoring those individuals closely for internal or external issues is a very important metric for the board to be on top of. This information also will provide you with valuable insight to determine whether you’re providing too many individuals with unlimited network access, so you can reduce privileges to those individuals who actually need it.
3. Percentage of critical third parties whose cybersecurity health is continuously monitored.
Traditional vendor risk management practices only offer you a snapshot view of a vendor’s security posture at a single point in time. Even if you perform audits, penetration tests, and vulnerability scans, you still won’t know what’s going on with your vendors’ security on a day-to-day basis. But continuously monitoring the cybersecurity of your third-parties allows you to look at those you’ve deemed as critical — usually vendors who have access to sensitive data or direct corporate network connections — and determine in real-time how they’re performing. This will allow you to make data-driven decisions about your top-priority vendors.
What Metrics You Should Bring To Your CIO
There are many different metrics that the security team collects to measure the performance and effectiveness of its security program, but only a select number of these metrics hold enough weight to be reported to the C-suite. The cybersecurity metrics for the board should be presented in a language the board understands, and should speak directly to whether your company is taking the right steps toward managing cybersecurity. It may also be helpful put these metrics together into a cybersecurity dashboard that the C-suite can reference on their own.
Below are four key cybersecurity metrics for reporting cyber security to the board:
1. Company performance against your peers.
The top cybersecurity metric for board-level reporting today is how your organization’s cybersecurity performance compares to the peers in your industry. This information is usually easily digestible, visually appealing, and highly compelling, which makes it a top choice for reporting cyber security to executives.
You can gather this metric most easily through a security rating. The example below is a screenshot from the Bitsight Security Ratings platform, which allows you to easily benchmark your security performance against a number of your industry peers and competitors over a period of time.
2. Incident identification and response times.
It is important to differentiate between a vulnerability and an incident. A vulnerability is a flaw that could potentially be exploited, where an incident is an actual exploitation or compromise of a system. Identification and response times are important cybersecurity metrics for the board to understand because it demonstrates the effectiveness of the programs and processes they are budgeting for to protect their cyber footprint.
Cybersecurity programs are measured by how quickly the organization can measure and respond to incidents, because the quicker the programs can eliminate the malware the less damage is likely to be done. Unfortunately, many companies let malware dwell on their network for far too long, which gives hackers a longer opportunity to compromise their systems. This is often because the organization isn’t aware of the intrusion in the first place.
There are a number of different ways to measure incident response rates. You can: