Measure decisions and outcomes—not dashboard volume
Define measures that can be reproduced, interpreted and acted on. Keep denominators, data quality, scope changes and uncertainty visible so apparent improvement does not become false assurance.
Five operating measurement problems
Each guide starts from the decision the measure should improve, then connects calculation, evidence, limitations and action.
Measure selection
A cybersecurity measure is useful when it supports a defined decision, has an unambiguous calculation and scope, uses sufficiently trustworthy data, can be segmented to expose material differences, shows uncertainty or coverage limitations, and has an owner who knows what action should follow when it changes.
Open guide →Metrics guideAlert triage metrics
Useful triage measures show whether material alerts receive timely, explainable decisions: backlog by age and severity, time-to-first-review distributions, missing-context rates, duplication, closure reasons, incident escalation, reopened work and source or parser failures. Alert volume by itself cannot distinguish better detection from noisier telemetry.
Open guide →Metrics guideIncident response metrics
No. A single mean-time-to-resolve figure compresses incidents with different severity, business impact and decision paths. Measure readiness, time to declaration, time to critical containment or recovery decisions, business-impact duration, evidence preservation, recovery validation and corrective-action closure, segmented by incident type and materiality.
Open guide →Metrics guideDetection quality metrics
Measure detection quality as an evidence chain: telemetry prerequisites and source health, validation results by detection version, known blind spots, alert context and duplication, investigation outcomes, tuning changes and retest age. A false-positive rate or ATT&CK mapping alone is not sufficient evidence of detection effectiveness.
Open guide →Metrics guideExposure & remediation metrics
Measure the material unresolved exposure, not just tickets closed: affected critical services, known-exploited vulnerabilities in scope, age by priority, accountable ownership, approved exceptions, treatment progress, validation results and reopened conditions. Closure rate alone can improve while material residual exposure remains unchanged.
Open guide →Board & CISO reporting
Roll operational evidence into material risk, trend, confidence and decisions required without turning leadership packs into SOC dashboards.
Executive reportingMeasurement methodology
Definitions, denominators, uncertainty, aggregation, causality and non-claims for Cybatar-authored security measurement.
Read methodologyReporting & Governance
Review Cybatar's documented reporting and governance workflow surface.
Platform capability