You cannot manage what you cannot measure. Security metrics translate complex technical realities into the language of business — enabling risk-based decisions, demonstrating security value, and holding the program accountable.
KPIs (Key Performance Indicators) measure how well security processes are executing: patch compliance rate, vulnerability remediation SLA adherence, phishing simulation click rates, training completion. They answer: "Is our security program performing as designed?" KRIs (Key Risk Indicators) measure changes in the risk environment that may indicate increasing risk exposure: number of critical open vulnerabilities, days since last pen test, vendor security score trends. They answer: "Is our risk level changing?"
Lagging indicators measure what has already happened: breach count, mean time to detect, audit findings. They are accurate but backward-looking. Leading indicators predict future outcomes: phishing click rates predict credential compromise, unpatched vulnerability count predicts breach likelihood. Leading indicators enable proactive intervention — you can change the outcome before it materializes.
Different audiences need different metrics at different levels of abstraction. Operational (SOC/IT): Technical metrics — open vulnerabilities, incident queue, failed logins, patch coverage. Management (CISO/Directors): Program performance — SLA adherence, risk register status, compliance posture. Board: Strategic metrics — top 3 risks with financial quantification, cyber insurance status, regulatory compliance score, incident trend.
A comprehensive security metrics program covers four dimensions:
What percentage of systems are protected? Examples: % endpoints with EDR deployed, % systems with MFA enabled, % critical systems with vulnerability scans within 30 days, % employees with completed annual training.
How well are controls working? Examples: Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), phishing simulation click rate trend, patch SLA compliance rate, access review completion rate.
How efficiently is the security program operating? Examples: cost per incident, audit findings per system, false positive rate in SIEM alerts, remediation cost per vulnerability.
What is the current risk posture? Examples: open critical vulnerabilities by age, ALE of top 5 risks, vendor security rating trend, days since last tabletop exercise, regulatory compliance score by framework.
| Leading Indicator | What It Predicts | Target Trend |
|---|---|---|
| Phishing simulation click rate | Credential compromise probability | Decrease over time |
| Days to patch critical CVEs | Exploit likelihood | Decrease; target <7 days |
| Unreviewed access count | Insider threat / privilege misuse probability | Decrease; target 0 |
| Vendor security score trend | Third-party breach probability | Maintain or improve |
| Open P1 IR findings from last exercise | IR effectiveness when real incident occurs | Decrease; target 0 open items |
| Security training completion rate | Human error incident probability | Increase; target 100% |
The Balanced Scorecard (Kaplan & Norton) framework translates strategic security objectives into four balanced perspectives:
How does security create value? Metrics: ROSI, breach cost avoidance, insurance premium impact, revenue enabled by security certifications.
How do customers perceive our security? Metrics: SOC 2 findings count, customer security questionnaire completion time, security-related customer churn, NPS related to security incidents.
How effective are our security processes? Metrics: MTTD, MTTR, patch compliance rate, audit findings, vulnerability remediation SLA.
How is the team improving? Metrics: security training completion, certifications obtained, tabletop exercises conducted, tool adoption rate.
You are designing a three-tier GRC metrics dashboard for a 1,000-person technology company. Complete each tier — operational (SOC), management (CISO weekly), and governance (board quarterly) — selecting the right metrics and KRIs for each audience and explaining why each metric belongs at that level.