Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Ally
Eric Lovell, Senior Director, It/Cyber Security Risk
Continual Improvement In The Key To Optimum Cyber Security


And from a risk perspective (with few exceptions), cyber security relevant information technology aligned metrics are at the top of the mind for boards, end users, and every stakeholder group.
I would hazard to guess that at any organization, cyber security “metrics” of some type are being collected, tracked, and communicated. Some organizations have robust, well managed programs; others may take a minimalist approach, only tracking a handful of items because leadership demands accountability for basic things with direct and obvious business impact.
In regulated industries, such as financial services, there is an expectation that their entire digital presence should be secure and well managed. For many firms, the identification, collection, tracking, and reporting of metrics, rather than an ancillary process, is a fundamental organizational capability with measurable value for all stakeholders.
In my experience, even a cursory review of industry specific regulatory, academic, and authoritative cyber security standards and/or research products produced by organizations such as the Center for Internet Security, and the National Institute of Standards and Technology, like a mature cyber risk management metrics program has the following characteristics:
1.Both retrospective and prospective/actionable
2.Comprehensive in scope but limited in number
3.Clear, concise, and of adequate frequency to provide expected benefits
4.Authoritative, both internally and externally
1.Both Retrospective and Prospective/ Actionable
Metrics should provide a view into both past and likely future outcomes. The retrospective lens should provide insight into what has occurred recently and what has occurred over time, i.e., trending of performance. Although not to the caliber of true predictive analytics, the forward-looking view should provide expected future outcomes based on past performance.
2.Comprehensive in Scope
Contain targeted audience specific/relevant information (operational, executive, regulatory, etc.). More than different presentation formats that resonate well with a differentiated audience, metrics should be nuanced and have specific meaning and value to various groups. Although there is a subset of metrics which may be ubiquitous across most/all recipients, each group has a unique set of questions they expect the metrics program to answer. In addition, the number of metrics should be as few as possible, identifying aggregate or composite metrics where feasible. Furthermore, in support of both 1 and 2, relevant threat landscape information should be added to allow insight into the probability of occurrence.
If you can’t measure it, you can’t manage it
To borrow from lean manufacturing, the concepts of "just-in-time" and "flow" are relevant to effective cyber metrics. If the purpose of the metrics program is to both inform and induce action, the progression (flow) from risk identification to remediation must be continuously displayed with drill down, easily accessible when needed (just-in-time). Metrics reporting can be a static product with limited value or a valuable, extensible tool that increases in value over time. Additionally, data visualizations should be of diversity and quality to both support the data and provide insight. To this end, upper and lower thresholds (specification limits) should be determined and applied where possible to allow a clear line of sight as to what is within an acceptable tolerance…as well as how close a metric is to breaching tolerance.
4.Authoritative, Both Internally and Externally
The intended outcome is a single source of objective truth based on data, seasoned with insightful and expert analysis. Although there may be various interpretations of the root cause of variances, and/or the effective weight of multiple ancillary causes, the data and resultant metrics must be considered authoritative across all audiences.
In conclusion, I suggest a quick assessment of your current metrics program. Is it redundant readouts that no one reads? Is it an exhaustive and exhausting list of everything under the sun? Making the shift from sad to glad is easier than you may think. Barring some external impetus (such as a regulatory finding) which requires wholesale changes, start with what you have, reframe if necessary, and incrementally enrich your program. Over time and with continual improvement, you will reach your destination.

