

Strategy 10: Measure Performance to Improve Performance
12 snips Jul 10, 2023
Kathryn Knerler and Ingrid Parker, co-authors of a pivotal book on world-class cybersecurity operations centers, dive into the complex world of performance metrics. They discuss the importance of aligning metrics with organizational goals and share insights on differentiating between measures, metrics, and KPIs. Challenges in communicating cybersecurity effectiveness to non-technical stakeholders are explored, along with the role of timely metrics in enhancing response strategies. The use of visual aids, whimsically called 'Pew Pew maps,' adds humor to serious topics, making complex data more digestible.
AI Snips
Chapters
Transcript
Episode notes
Metric vs KPI vs Assessment
- Metrics are numbers without meaning until interpreted.
- KPIs add context to metrics to show if goals are met or not.
Tailor Metrics to Your Audience
- Tailor metrics to different audiences: SOC team, leadership, and constituency.
- A metric meaningful for one audience may be irrelevant for another.
Show Value with Clear Metrics
- Use metrics to show the SOC's value and justify investments.
- Explain how tools and analysts prevent incidents in clear, non-technical terms.