# Business-Aligned Security Metrics Selection Framework - **PURPOSE:** Helps security leaders identify and develop metrics that directly connect security activities to business outcomes and executive priorities. - **WHEN TO USE:**During annual security planning, when preparing board presentations, or when revising security reporting approaches that aren't resonating with business leaders. ## Step 1: Map Business Objectives | Key Business Objective | Owner | Success Measures | Timeline | | --- | --- | --- | --- | | [Example: Increase digital banking customers by 20%] | [Business unit owner] | [Key business metrics] | [Target date] | | | | | | Table 1: Map Business Objectives ## Step 2: Identify Security Dependencies | Business Objective | Security Dependencies | Risk if Not Addressed | | --- | --- | --- | | [Business objective from Step 1] | [Security capabilities required] | [Business impact of security failure] | | | | | Table 2: Identify Security Dependencies ## Step 3: Define Business-Relevant Security Metrics | Security Dependency | Traditional Technical Metric | Business-Aligned Metric | Business Impact | | --- | --- | --- | --- | | Customer authentication | MFA implementation percentage | Reduction in unauthorized access risk to revenue-generating systems | Protects $X in digital revenue | | Data protection | Encryption coverage | Customer data protection confidence score | Preserves trust of X million customers | | Availability | System uptime | Critical service uptime affecting revenue streams | Prevents $X/hour in lost business | | Threat detection | MTTD for critical systems | Speed of threat containment for business-critical assets | Limits financial exposure to $X per incident | Table 3: Define Business-Relevant Security Metrics ## Step 4: Establish Measurement Methodology | Business-Aligned Metric | Data Sources | Collection Frequency | Calculation Method | Target/Threshold | | --- | --- | --- | --- | --- | | [Metric from Step 3] | [Where data comes from] | [How often collected] | [Formula] | [Desired performance] | | | | | | | Table 4: Establish Measurement Methodology ## Step 5: Create Stakeholder-Specific Views | Stakeholder | Primary Concerns | Key Metrics to Present | Preferred Format | | --- | --- | --- | --- | | Board | Governance, risk oversight | Overall risk posture, compliance status | High-level dashboard | | CEO | Strategic alignment, reputation | Security's support of strategic initiatives | Executive summary | | CFO | Investment justification, cost management | Security ROI, cost avoidance | Financial analysis | | Business Unit Leaders | Operational impact, enablement | Security's impact on specific business functions | Function-specific metrics | Table 5: Create Stakeholder-Specific Views ## IMPLEMENTATION TIPS: - Begin with no more than 3-5 metrics for each stakeholder group to avoid information overload - Review regularly with business stakeholders to ensure metrics remain relevant as business priorities shift - Use a pilot approach with one business unit before expanding to the entire organization *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)