Policymakers are increasingly interested in measuring cybersecurity performance in critical infrastructure organizations and sectors. Measuring performance is critical for policymakers to understand current levels of risk and exposure and the effectiveness of existing policies and approaches. Armed with performance data, policymakers can answer key questions (“is our approach working?”) and make better decisions about engagement, risk reduction, and other potential solutions.
According to its new strategic plan, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) plans to use performance goals to set standards and recommendations to guide security decisions regarding critical infrastructure protection. During a recent meeting, CISA Director Jen Easterly stated that “We're really going to be working hard to align our goals and objectives with specific measurements that help us reduce risk.”
What performance areas should policymakers begin measuring? Why are these important? How should they collect the data?
Performance Measurements Tied to Ransomware
Bitsight recently studied how cybersecurity performance can impact the likelihood of an organization experiencing a ransomware incident. Bitsight non-intrusively collects unique telemetry into the cybersecurity performance of organizations around the globe, and uses it to create cybersecurity analytics that measure performance over time. The Bitsight Security Rating measures an organization’s overall cybersecurity performance. Bitsight risk vectors measure an organization’s performance in particular cybersecurity domains (e.g. patching cadence, software updating practices, etc.).