It’s Tuesday morning, and you’re scrambling to get your weekly business review slides updated before the meeting. Manually updating metrics, tweaking graphs, and making sure your wins get noticed—it’s a last-minute dash that feels all too familiar.
Metrics are incredibly important. They help measure your organization’s current security posture and highlight whether you’re getting better or worse. Unfortunately, most security metrics are an afterthought, and it shows.
Security teams are constantly asked to do more with less. In that environment, non-critical tasks—like developing meaningful metrics—often fall by the wayside. Here are three other reasons metrics tend to get neglected:
Now the good news. There are simple tweaks you can make to develop valuable metrics that will help improve your security posture and make a real difference in your organization.
Here’s how, step by step:
Metrics should never be an afterthought. Often, people build their security program first and then scramble to find metrics that show off how great the program is. This results in vanity metrics—numbers that look good in business review decks but don’t drive real change. If you aren’t using your metrics to run your business or program, they’re just for show.
We can learn from a development concept called Test-Driven Development (TDD). In TDD, you write a test case for a requirement before you even start coding. The test fails at first, but then you write just enough code to make it pass. Once it does, you move on to the next requirement. What would this look like for security metrics?
Before you build a program or start a project, define the outcomes you expect. What are the requirements, and how will you know when you’ve met them? Develop metrics that measure those outcomes. They might look terrible when you first start measuring, but that’s okay. Then, build your program to improve those metrics and make them “pass.”
Not only does this ensure you’re building something that genuinely contributes to your goals, but it also shows your progress as you go.
So, what should you measure? True success as a security engineer is measured by how well you support your organization’s goals. Most organizations aren’t in the business of being secure—they’re in the business of selling products, providing services, or delivering value to customers.
Start by talking to your stakeholders to find out what’s important to the business you’re protecting.
Once you understand where the business is headed, determine how your program will support those goals. Ask yourself how your security efforts will help the business:
With this information, you can align your metrics with what matters most to the business. You’ll never struggle to demonstrate your contributions, and you’ll ensure your program continues to support the health of the organization you serve.
At Disney, I learned the art of storytelling. At first, I resisted the idea that storytelling had a place in business metrics. But telling a compelling story with data doesn’t mean starting with “Once upon a time.” It means being deeply familiar with your data and understanding your audience. You need to find the stories hidden in the data and bring them to light. Here’s how to do it:
Once you’ve got a handle on your data, share these insights in meetings and one-on-one conversations with stakeholders. The ability to unlock insights from data is a valuable skill, and sharing those insights helps your leadership understand where the business is going.
Metrics aren’t just numbers—they’re a tool to drive your business forward. By defining clear outcomes, aligning with business goals, and telling compelling stories with your data, you can make your security program a critical part of your organization’s success.