Security leaders are increasingly making their cases through metrics. Data-driven measurement of cybersecurity performance can be used to justify spending, quantify risk, and more.
But just how useful are the numbers that many security teams are gathering and presenting to leadership? Not very, reports Dark Reading. In a series of interviews, security experts weighed in on their least favorite metrics — and they had a lot to say. One expert claimed that metrics calculations are too complex and fail to provide context behind their conclusions. Another stated that most cybersecurity metrics are too focused on the use of a vague scale of low, medium, and high measurements for risk.
Let’s look at the metrics that are most useful and impactful to security leaders and the business at large.
Outcome-based metrics
Metrics should give leadership a quantifiable measurement of cyber risk in their organizations and the outcomes associated with taking certain actions to address that risk.
Bitsight Security Ratings, for example, use externally observable and verifiable data to provide an instantaneous, point-in-time snapshot of an organization’s overall cybersecurity posture. A security rating is built using an assessment of risk vectors such as software vulnerabilities, unpatched systems, and open ports — and a higher rating equates to a better overall security posture.
With a baseline understanding of an organization’s cyber risk, security teams can then leverage forecasting tools to model scenarios and identify opportunities to improve their overall security performance. By creating action plans and tracking progress over time, they can achieve a truly outcome-based approach to cyber risk reduction.
Context-based metrics
Traditional metrics can often be overwhelming. In the Dark Reading report, one security expert commented that some metrics are too focused on “shock and awe.” For example, a CISO may report that there are an eye-popping 12,000 unpatched vulnerabilities in an organization’s IT ecosystem. Yet that number lacks context or consideration for risk. Is the metric good or bad? Is it normal for an organization of that size or in that industry? Do those vulnerabilities congregate on one digital asset or are they scattered across multiple assets?
To help security teams prioritize their efforts, security leaders need to give context to the numbers they report on.
This starts with gaining visibility into digital assets so they can be secured. To do this, teams must be able to quickly discover, assess, and report on areas of disproportionate risk — both on-premise and in the cloud — bringing much-needed context to their security postures.
They also need to determine an acceptable standard of care pertaining to cybersecurity as it relates to key factors, such as company size, industry, geography, etc. Likewise, businesses with subsidiaries or operations in multiple geographies can conduct similar analysis across their enterprises to pinpoint where the greatest cyber risk exists. In this way, they can monitor, manage, and report on their security programs in the same way that's expected of other departments and business units.
Metrics alone offer value but being able to say how a company’s security program performs compared to others in the industry and across highly dispersed organizations can help drive informed decisions within the security practice.