Cybatar Security Hub
Security Metrics / Measure selection
Security-measurement guide

Selecting Cybersecurity Measures That Support Decisions

What makes a cybersecurity metric useful?

Direct answer

A cybersecurity measure is useful when it supports a defined decision, has an unambiguous calculation and scope, uses sufficiently trustworthy data, can be segmented to expose material differences, shows uncertainty or coverage limitations, and has an owner who knows what action should follow when it changes.

External reference

National Institute of Standards and Technology — NIST SP 800-55 Vol. 1 — Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures

Final, December 2024. NIST describes a flexible approach to developing, selecting, prioritising and evaluating information-security measures, including data quality, reporting and uncertainty considerations.

Primary source →

Measures to retain

Decision linkage

State which operational, risk or investment decision the measure is intended to improve. A number with no decision use is reporting overhead.

Definition and denominator

Document numerator, denominator, population, time window, inclusions, exclusions and units so the measure can be reproduced.

Data provenance and quality

Record the source systems, collection method, freshness, missing data and known integrity limitations.

Segmentation

Break results down by material dimensions such as business service, asset criticality, severity, source, team or exposure rather than rely only on enterprise averages.

Trend and context

Compare like with like and annotate major changes in scope, tooling, process or threat conditions that may explain movement.

Action and review trigger

Define who reviews the result, what threshold or pattern prompts investigation, and when the measure itself should be retired or redesigned.

Operating method

Step 1

Start with the decision

Write the management or operational question before choosing a metric.

Step 2

Define the evidence chain

Identify authoritative records, ownership, calculation rules and quality checks.

Step 3

Test the measure

Check whether it changes when the underlying condition changes and whether teams can interpret it consistently.

Step 4

Report with limitations

Show coverage, uncertainty, scope changes and exceptions beside the result.

Step 5

Use and improve it

Record decisions made from the measure and periodically remove metrics that no longer influence action.

Measurement anti-patterns

Unowned dashboardsCounts without denominatorsEnterprise averages that hide material segmentsTargets copied from another organisation without contextMeasures that improve when work is merely suppressed or reclassified

Relevant Cybatar sources

Claim boundary

No individual metric or dashboard proves that security controls are effective, that risk is acceptable or that Cybatar has improved security outcomes. Measurement quality depends on the deployment, source data, definitions and decisions made from the evidence.

Cybatar publishes measurement and reporting guidance as a first-party operating model. Examples are not universal benchmarks, regulatory thresholds, promises of security outcomes or evidence that a particular deployment is effective.

Related resources