Session

Measuring What Matters: How to "Quantify Cyber Security Effectiveness"!

After so many years working in cybersecurity, I realized many times in my career that “success” isn’t just about stopping attack, it’s about being able to measure how well we are doing it. That’s where information security metrics and key performance indicators (KPIs) come in. For me, these are not just numbers, they are the story of our organization’s security posture, a way to see, in real time, how effectively we are preventing, detecting, and responding to threats.
Security metrics are not limited to only incident response times. According to me, it must include all sub-team efforts of a CISO team. There are many types of cyber security metrics that can provide concrete data to justify security investments.
Examples of security metrics include but are not limited to coverage metrics, Threat and vulnerability metrics, Operational metrics, Compliance & Governance metrics, Risk based metrics, Board / Executive Leadership metrics etc.
I often being asked from leadership and stake holders, “Are we really covering everything that matters?” That’s when I learned the power of coverage metrics. Coverage metrics are like a security health map. They measure how complete our controls, monitoring, and testing are across the environment. These metrics help us to assess if all our important assets being watched, patched, and tested or are there hidden gaps waiting to be exploited?
Some of the key metrics quickly became part of our regular reporting. Asset coverage, for example, showed what percentage of servers, endpoints, code repositories, and applications were inventoried and under active security management. It was eye opening to realize that even a few unmonitored systems could represent a significant risk. Vulnerability scan coverage tracked whether those assets were regularly scanned, ensuring that we weren’t just aware of them, but actively looking for weaknesses. Patch coverage became another critical metric in our environment for measuring the percentage of critical vulnerabilities patched across all systems. By tracking the percentage of critical assets sending logs to our SIEM, we could see exactly where our visibility was strong and where it was weak. Similarly, identity and access coverage highlighted whether users and applications had multi-factor authentication enabled and if privileged accounts were being closely monitored. Finally, test coverage through penetration tests gave us confidence that our defenses would hold up under real-world attacks.

Anitha Dakamarri

DFIN-Lead Security Engineer

Dallas, Texas, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top