Cybatar Security Hub
Resources / Security Metrics
Security measurement

Measure decisions and outcomes—not dashboard volume

Define measures that can be reproduced, interpreted and acted on. Keep denominators, data quality, scope changes and uncertainty visible so apparent improvement does not become false assurance.

Measurement library

Five operating measurement problems

Each guide starts from the decision the measure should improve, then connects calculation, evidence, limitations and action.

Metrics guide

Measure selection

A cybersecurity measure is useful when it supports a defined decision, has an unambiguous calculation and scope, uses sufficiently trustworthy data, can be segmented to expose material differences, shows uncertainty or coverage limitations, and has an owner who knows what action should follow when it changes.

Open guide →
Metrics guide

Alert triage metrics

Useful triage measures show whether material alerts receive timely, explainable decisions: backlog by age and severity, time-to-first-review distributions, missing-context rates, duplication, closure reasons, incident escalation, reopened work and source or parser failures. Alert volume by itself cannot distinguish better detection from noisier telemetry.

Open guide →
Metrics guide

Incident response metrics

No. A single mean-time-to-resolve figure compresses incidents with different severity, business impact and decision paths. Measure readiness, time to declaration, time to critical containment or recovery decisions, business-impact duration, evidence preservation, recovery validation and corrective-action closure, segmented by incident type and materiality.

Open guide →
Metrics guide

Detection quality metrics

Measure detection quality as an evidence chain: telemetry prerequisites and source health, validation results by detection version, known blind spots, alert context and duplication, investigation outcomes, tuning changes and retest age. A false-positive rate or ATT&CK mapping alone is not sufficient evidence of detection effectiveness.

Open guide →
Metrics guide

Exposure & remediation metrics

Measure the material unresolved exposure, not just tickets closed: affected critical services, known-exploited vulnerabilities in scope, age by priority, accountable ownership, approved exceptions, treatment progress, validation results and reopened conditions. Closure rate alone can improve while material residual exposure remains unchanged.

Open guide →
Executive reporting

Board & CISO reporting

Roll operational evidence into material risk, trend, confidence and decisions required without turning leadership packs into SOC dashboards.

Executive reporting
Methodology

Measurement methodology

Definitions, denominators, uncertainty, aggregation, causality and non-claims for Cybatar-authored security measurement.

Read methodology
Platform

Reporting & Governance

Review Cybatar's documented reporting and governance workflow surface.

Platform capability