Are there any specific KPIs or metrics that you use to measure the effectiveness of your security programs?

14k viewscircle icon3 Upvotescircle icon7 Comments
Sort by:
CASH Europe IT Director in Transportation6 years ago

KPI of security depends on the business line. In my eyes I would look at : 
Compliance results ( mainly certificate audits)
Penetration results
Use of security tools to make users "life" easier
Employee education program

Lightbulb on1
Associate Director in Software6 years ago

The training scores of security engineers, vulnerability assessment scores, Audit report analysis and quality assurance, Assessment time and response time.

Lightbulb on1
CIO in Finance (non-banking)6 years ago

Vulnerabilities per line of code written. In the development team

Lightbulb on1
CIO in Finance (non-banking)6 years ago

Also trend lines on vulnerabilities, incidents, suspicious activities

Lightbulb on2
CIO in Finance (non-banking)6 years ago

Nist tier rank (capability)
Training scores (people)
Simulated Phishing scores (people)
External risk assessment and penetration testing results tied to NIST (snapshots)
Incident response readiness (more qualitative)
Recovery time objectives and recovery point objective (measured in hours and minutes)
Third party risk scores (nist based)

Lightbulb on1

Content you might like

Slow recovery response times35%

Data availability is limited52%

Too expensive to scale effectively51%

Difficult to manage for widespread use34%

Prone to misconfiguration14%

No - There are no drawbacks6%

View Results

Disruption via ransomware45%

Exploitation via phishing62%

Exfiltration of PII (Personally identifiable information)42%

Disruption via DDoS attacks29%

Disruption of a business-critical application25%

Other (comment below)

View Results