Module 25 - Advanced - 50 min - +325 XP

Security Metrics, KPIs, KRIs & Dashboards

You cannot manage what you cannot measure. Security metrics translate complex technical realities into the language of business — enabling risk-based decisions, demonstrating security value, and holding the program accountable.

KPIsKRIsLeading IndicatorsBoard DashboardsSANS CISScorecards

Learning Objectives

  • Distinguish KPIs (Key Performance Indicators) from KRIs (Key Risk Indicators).
  • Explain the difference between leading and lagging indicators in security.
  • Design a three-tier security dashboard for operational, management, and board audiences.
  • Select the top security metrics for board reporting.
  • Apply the SANS 20 Critical Security Controls measurement approach.
  • Build a security scorecard using the Balanced Scorecard methodology.

Lecture

1 - KPIs vs KRIs

KPIs (Key Performance Indicators) measure how well security processes are executing: patch compliance rate, vulnerability remediation SLA adherence, phishing simulation click rates, training completion. They answer: "Is our security program performing as designed?" KRIs (Key Risk Indicators) measure changes in the risk environment that may indicate increasing risk exposure: number of critical open vulnerabilities, days since last pen test, vendor security score trends. They answer: "Is our risk level changing?"

2 - Leading vs Lagging Indicators

Lagging indicators measure what has already happened: breach count, mean time to detect, audit findings. They are accurate but backward-looking. Leading indicators predict future outcomes: phishing click rates predict credential compromise, unpatched vulnerability count predicts breach likelihood. Leading indicators enable proactive intervention — you can change the outcome before it materializes.

3 - Three-Tier Dashboard Design

Different audiences need different metrics at different levels of abstraction. Operational (SOC/IT): Technical metrics — open vulnerabilities, incident queue, failed logins, patch coverage. Management (CISO/Directors): Program performance — SLA adherence, risk register status, compliance posture. Board: Strategic metrics — top 3 risks with financial quantification, cyber insurance status, regulatory compliance score, incident trend.

Board metric principle: The board needs ONE risk metric that is meaningful — not 47. "Top 3 risks by ALE" and "Residual risk vs risk appetite" are the two most valuable board metrics.

Theory Deep Dive

📊 Security Metrics Framework

A comprehensive security metrics program covers four dimensions:

Coverage Metrics

What percentage of systems are protected? Examples: % endpoints with EDR deployed, % systems with MFA enabled, % critical systems with vulnerability scans within 30 days, % employees with completed annual training.

Effectiveness Metrics

How well are controls working? Examples: Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), phishing simulation click rate trend, patch SLA compliance rate, access review completion rate.

Efficiency Metrics

How efficiently is the security program operating? Examples: cost per incident, audit findings per system, false positive rate in SIEM alerts, remediation cost per vulnerability.

Risk Metrics

What is the current risk posture? Examples: open critical vulnerabilities by age, ALE of top 5 risks, vendor security rating trend, days since last tabletop exercise, regulatory compliance score by framework.

🎯 Leading Indicator Examples

Leading IndicatorWhat It PredictsTarget Trend
Phishing simulation click rateCredential compromise probabilityDecrease over time
Days to patch critical CVEsExploit likelihoodDecrease; target <7 days
Unreviewed access countInsider threat / privilege misuse probabilityDecrease; target 0
Vendor security score trendThird-party breach probabilityMaintain or improve
Open P1 IR findings from last exerciseIR effectiveness when real incident occursDecrease; target 0 open items
Security training completion rateHuman error incident probabilityIncrease; target 100%

📋 Balanced Scorecard for Security

The Balanced Scorecard (Kaplan & Norton) framework translates strategic security objectives into four balanced perspectives:

Financial Perspective

How does security create value? Metrics: ROSI, breach cost avoidance, insurance premium impact, revenue enabled by security certifications.

Customer Perspective

How do customers perceive our security? Metrics: SOC 2 findings count, customer security questionnaire completion time, security-related customer churn, NPS related to security incidents.

Internal Process Perspective

How effective are our security processes? Metrics: MTTD, MTTR, patch compliance rate, audit findings, vulnerability remediation SLA.

Learning & Growth Perspective

How is the team improving? Metrics: security training completion, certifications obtained, tabletop exercises conducted, tool adoption rate.

🧪 Lab — GRC Metrics Dashboard Design

You are designing a three-tier GRC metrics dashboard for a 1,000-person technology company. Complete each tier — operational (SOC), management (CISO weekly), and governance (board quarterly) — selecting the right metrics and KRIs for each audience and explaining why each metric belongs at that level.

Scenario

Quiz

Mission Complete

Back Next: Module 26