.

Continual Improvement IN the Key to Optimum Cybersecurity

Peter Drucker is oft quoted for a true pearl of wisdom; “If you can’t measure it, you can’t manage it”. And although many question its attribution and/or universal applicability, little did he know that someday an opportunistic fellow would borrow the phrase, and with a little formatting, allow the statement to really resonate with those interested in communicating and managing business in the digital age. 

And from a risk perspective (with few exceptions) cybersecurity relevant information technology aligned metrics are top of mind for boards, end users, and every stakeholder group in between.

I would hazard to guess that at any organization of any size, cybersecurity “metrics” of some type are being collected, tracked and communicated.  Some organizations have robust, well managed programs, others may be taking a minimalist approach, only be tracking a handful of items because leadership demands accountability for basic things with direct and obvious business impact.

“If you can’t measure IT, you can’t manage IT.”

In regulated industries, such as financial services, there is an expectation that their entire digital presence will be secure and well managed. For many firms, the identification, collection, tracking, and reporting of metrics, rather than an ancillary process, is and should be a fundamental organizational capability, with measurable value for all stakeholders. 

In my experience, even a cursory review of industry specific regulatory, academic, and authoritative cybersecurity standards and/or research products produced by organizations such as The Center for Internet Security, and the National Institute of Standards and Technology, a mature cyber risk management metrics program has the following characteristics:

1. Both retrospective and prospective/actionable

2. Comprehensive in scope, but limited in number

3. Clear, concise, and of adequate frequency to provide expected benefits

4. Authoritative, both internally and externally

Characteristics in Detail:

1. Both retrospective and prospective/actionable
Metrics should provide a view into both past and likely future outcomes.  The retrospective lens should provide insight into both what has occurred recently, as well as what has occurred over time, i.e., trending of performance. The forward-looking view, although not to the caliber of true predictive analytics, should provide expected (likely) future outcomes based on past performance. 

2. Comprehensive in scope

Contain targeted, audience specific/relevant information (operational, executive, regulatory, etc.). More than different presentation formats which resonate well with a differentiated audience, metrics should be nuanced and have specific meaning and value to a variety of groups.  Although there is a subset of metrics which may be ubiquitous across most/all recipients, each group has a unique set of questions they expect the metrics program to answer.  In addition, the number of metrics should be as few as possible, identifying aggregate or “composite” metrics where feasible.  Furthermore, in support of both 1 and 2, relevant threat landscape information should be added to allow insight into probability of occurrence.

3. Clear, concise and of adequate frequency to provide expected benefits

To borrow from lean manufacturing, the concepts of “just-in-time”, and “flow” are relevant to effective cyber metrics.  If the purpose of the metrics program is to both inform and induce action, the progression (flow) from risk identification to remediation must be continuously displayed with drill down, easily accessible when needed (just-in-time).  Metrics reporting can be a static product with limited value, or a valuable, extensible tool which increases in value over time. Additionally, data visualizations should be of a diversity and quality to both support the data and provide insight.  To this end, upper and lower thresholds (specification limits) should be determined and applied where possible, to allow a clear line of sight as to what is within an acceptable tolerance…as well as how close a metric is to breaching tolerance.

4. Authoritative, both internally and externally

The intended outcome is a single source of objective truth based on data, seasoned with insightful and expert analysis.  Although there may be various interpretations of the root cause of variances, and/or the effective weight of multiple ancillary causes; the data and resultant metrics must be considered authoritative across all audiences.

In conclusion, I suggest a quick assessment of your current metrics program.  Is it redundant readouts that no one reads?  Is it an exhaustive and exhausting list of everything under the sun?  Making the shift from sad to glad is not as difficult as you may think.  Barring some external impetus (such as a regulatory finding) which requires wholesale changes, start with what you have, reframe if necessary, and incrementally enrich your program.  Over time and with continual improvement, you will reach your destination.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.