KPIs · Security

Security: KPIs

Detection, response and exposure measures, including dwell time, false-positive rate, and why counting blocked attacks is a vanity metric.

Markdown. No sign-up, no email.

Security metrics fail in a specific way: the comfortable ones are easy to grow and say nothing. Attacks blocked, alerts generated and tools deployed all rise without the company being safer.

These measure exposure, speed and whether the signal is trusted.

The six that matter#

MeasureDefinitionTargetHow it gets gamed
Dwell timeCompromise to detectionUnder 24 hoursOnly counting incidents that were detected, which excludes the worst ones by construction
Time to containDetection to containedUnder 4 hoursCalling partial containment done
False-positive rateAlerts that were nothingUnder 20%Tuning by suppression rather than by improving the signal
Critical vulnerability ageDays a critical stays open on an exposed systemUnder 7Reclassifying critical as high
CoverageShare of assets actually reporting telemetryAbove 98%Counting assets we know about. The unmonitored asset is the one that gets used
Approval latencyScore to human decision on a high-risk eventUnder 15 minAuto-approving to hit the number, which removes the gate entirely

Approval latency is the honest test of the human gate. A gate nobody can reach at 3am is a gate that will be removed within the quarter, and it will be removed for good practical reasons. The way to keep it is to make it fast, not optional.

Coverage is the number most likely to be quietly wrong. It is measured against the asset inventory, and the asset that hurts you is usually the one missing from it. Reconcile against billing and DNS, not against the inventory alone.

Two counter-metrics#

Counter-metricCatches
Alerts closed without investigationA team overwhelmed and triaging by clicking. The precursor to every missed intrusion
Exceptions granted and still openTemporary risk acceptances that became permanent. Every one has a date and most are past it

Exposure review, monthly#

QuestionBad answer
What is internet-facing that does not need to be?Anything discovered rather than known
Which credentials are older than 180 days?Any, on a production system
Which accounts have privileges they have not used in 90 days?Standing access nobody exercises is pure attack surface
Which cloud configurations drifted from baseline?Drift nobody noticed

What is deliberately not measured#

  • Attacks blocked. Grows with internet background noise and correlates with nothing.
  • Alert volume. More alerts is a cost, not a defence.
  • Tools deployed. Spend, not posture.
  • Training completion. Attendance, not behaviour. Measure phishing-report rate instead, which is behaviour.

Cadence#

ContinuousDetection and scoring
DailyHigh-risk events, approval latency, anything closed without investigation
WeeklyVulnerability ageing, false-positive rate
MonthlyExposure review, coverage reconciliation, open exceptions
QuarterlyResponse allowlist, access review with Data and Analytics, tabletop exercise

The quarterly tabletop is the only one that tests whether the plan works when people are tired and guessing. A plan that has never been rehearsed is a document, and during an incident it reads like one.

Back to Security

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.