- Many security leaders put off adding metrics to their program because they don't know where to start or how to assess what is worth measuring.
- Sometimes, this uncertainty causes the belief that their security programs are not mature enough for metrics to be worthwhile.
- Because metrics can become very technical and precise,it's easy to think that they're inherently complicated (not true).
Our Advice
Critical Insight
- The best metrics are tied to goals.
- Tying your metrics to goals ensures that you are collecting metrics for a specific purpose rather than just to watch the numbers change.
Impact and Result
- A metric, really, is just a measure of success against a given goal. Gradually, programs will achieve their goals and set new more specific goals, and with them come more-specific metrics.
- It is not necessary to jump into highly technical metrics right away. A lot can be gained from metrics that track behaviors.
- A metrics program can be very simple and still effectively demonstrate the value of security to the organization. The key is to link your metrics to the goals or objectives the security team is pursuing, even if they are simple implementation plans (e.g. percentage of departments that have received security training course).
Member Testimonials
After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve. See our top member experiences for this blueprint and what our clients have to say.
9.4/10
Overall Impact
$25,871
Average $ Saved
9
Average Days Saved
Client
Experience
Impact
$ Saved
Days Saved
Braun Intertec Corporation
Guided Implementation
9/10
N/A
N/A
Petar was an amazing resource and his guidance and input was instrumental in the success of this project.
Bath Iron Works Corporation
Guided Implementation
9/10
$12,999
5
Good exchange of ideas and overall communications. Representative was able to take customer's base idea and concepts and translate them into action... Read More
NIPPON GASES EURO-HOLDING, SLU
Guided Implementation
9/10
$10,000
20
Mutual Benefit Group
Guided Implementation
10/10
$129K
N/A
Shastri was extremely helpful as I navigated the problems of establishing a metrics set for our security operations program. I had no negative exp... Read More
Florida State Board of Administration
Guided Implementation
10/10
$6,299
5
Working with Cameron was, without question, the best part of experience. He was gracious and patient as I rambled through my thoughts and was adept... Read More
TransForm Shared Service Organization
Guided Implementation
10/10
$10,000
10
Kansas Public Employees Retirement System
Guided Implementation
9/10
N/A
2
We rec'd very helpful information from our analyst which will help guide us on our project!
Viridor Energy Limited
Guided Implementation
9/10
$1,800
2
Alberta Blue Cross
Guided Implementation
10/10
$10,000
20
Best was Ian's attitude and advice. He provided us with the tools we needed in order for us to start our metrics and reporting program - Thanks Ian.
New York University in Abu Dhabi Corporation – Abu Dhabi
Guided Implementation
10/10
N/A
10
Best part : Helped me in numerous presentations & make a huge impact in defining my role across the enterprise
Allegis
Guided Implementation
9/10
$2,479
2
Logan was extremely knowledgeable in the subject matter. Always had a response, suggestions or resources to any query.
Workshop: Build a Security Metrics Program to Drive Maturity
Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.
Module 1: Current State, Initiatives, and Goals
The Purpose
Create a prioritized list of goals to improve the security program’s current state.
Key Benefits Achieved
Insight into the current program and the direct it needs to head in.
Activities
Outputs
Discuss current state and existing approach to metrics.
Review contract metrics already in place (or available).
Determine security areas that should be measured.
Determine what stakeholders are involved.
Review current initiatives to address those risks (security strategy, if in place).
- Gap analysis results
Begin developing SMART goals for your initiative roadmap.
- SMART goals
Module 2: KPI Development
The Purpose
- Develop unique KPIs to measure progress against your security goals.
Key Benefits Achieved
- Learn how to develop KPIs
- Prioritized list of security goals
Activities
Outputs
Continue SMART goal development.
Sort goals into types.
Rephrase goals as KPIs and list associated metric(s).
- KPI Evolution Worksheet
Continue KPI development.
Module 3: Metrics Prioritization
The Purpose
Determine which metrics will be included in the initial program launch.
Key Benefits Achieved
A set of realistic and manageable goals-based metrics.
Activities
Outputs
Lay out prioritization criteria.
Determine priority metrics (implementation).
- Prioritized metrics
Determine priority metrics (improvement & organizational trend).
- Tool for tracking and presentation
Module 4: Metrics Reporting
The Purpose
Strategize presentation based around metric type to indicate organization’s risk posture.
Key Benefits Achieved
Develop versatile reporting techniques
Activities
Outputs
Review metric types and discuss reporting strategies for each.
Develop a story about risk.
Discuss the use of KPXs and how to scale for less mature programs.
- Key Performance Index Tool and presentation materials