Winning the Cybersecurity Budget Battle: Metrics for Success
47mBeginner2021-06-30
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
In most areas of business, specifics matter. This is especially true in the area of cybersecurity. If you’re a cybersecurity professional, you’ll have a very short career if the best answer you can come up with to security questions is “I think everything is pretty secure.” You need metrics and hard data to effectively communicate the value of your security programs and activities. In this course, Caroline Wong gives you a tried-and-true approach for customizing metrics that you can use to communicate the objectives and progress of your team’s cybersecurity initiatives. Caroline starts with an overview of the value of metrics, then covers the different ways you communicate cybersecurity topics to different groups like executives, business leaders, and engineers. She also covers risk management objectives, and finishes the course by going over examples of a number of important cybersecurity metrics.
Skills covered
Governance, Risk, and ComplianceIncident ResponseCybersecurityLearning
Concepts
Introduction
- Why are security metrics important
Why Cybersecurity Practitioners Need Metrics
- Cybersecurity is hard to measure
- Cybersecurity investment
- Define success for a cybersecurity program
- Cybersecurity program maturity
Know Your Audience
- The executive mindset
- The business mindset
- The technical leadership mindset
Risk Management Objectives
- Defining a risk management objective
- How to use a risk management objective
- Examples of risk management objectives
Example Cybersecurity Metrics
- Incidents detected internally vs. externally
- Security NPS
- Fixes implemented within SLA
Conclusion
- Apply security metrics