An increasing number of security and risk teams are using security ratings to effectively assess the impact of their security programs as well as communicate changes to key decision makers — like the Board of Directors. These teams know that their company needs tools that provide an objective and quantitative view of their cybersecurity performance over time.
As a CEO, I have learned the importance of establishing goals and benchmarks and the need to be able to measure performance against them over time. This is an important demand that the people I report to (my Board of Directors) have of me; in turn, it is a critical demand I have of people who report to me.
As adoption of Security Rating Services has rapidly increased, many customers have tied their Bitsight Security Rating to broader business goals and initiatives. With senior leadership more involved in security and risk programs than ever before, companies are beginning to set intervals of rating improvement as the benchmark for performance-based raises and compensation. But should they be?
Progress in a fast changing environment like cybersecurity isn't absolute; rather, it's relative based a) on a goal determined by your specific organization and its leadership and b) on the prevailing conditions that confront your market and your peer group. Performance should be based on progress towards that goal as well as performance relative to others you measure yourself against in other business dimensions. So how do you know what a realistic goal is for cybersecurity performance? Setting that goal is the first step, and the next is tracking that progress over time as well as understanding the context for your performance.