Design Your Progress Measurement System
Would you rather watch this on YouTube?
Most security teams can’t prove they’re improving. They track vulnerabilities, incidents, and compliance checkboxes, but none of that shows whether cyber risk is actually integrated into business decisions. This resource changes that. The Design Your Progress Measurement System exercise guides you through building a plan that tracks integration over time, not just security posture at a point in time. It’s from Chapter 10 of Cyber Risk is a Myth, and it’s designed for leaders who want security to stop living in a separate universe from the rest of the organization.
Looking for the exercise?
Download it here: Word | Markdown | Proton Docs
And if you like resources like this, consider subscribing to my newsletter where I release tools like this weekly.
When Should You Use This Resource?
This worksheet fits specific situations. You don’t need it if you’re still figuring out basic security controls or hiring your first security analyst. It’s for when you’ve got technical foundations in place but can’t prove they’re connected to business value.
Budget cuts keep happening
Use this resource when your security budget gets cut repeatedly despite solid work. Leadership doesn’t see the connection between security activities and business outcomes. A measurement system gives you data that speaks their language.
Business teams complain about slowdowns
Deploy it when business teams complain that security slows things down. They might be right, or security might be slow because of poor integration. The metrics will show you whether security reviews are streamlining decisions or creating friction.
Shifting from reactive to proactive
Apply this when you’re transitioning from reactive security to proactive risk management. Moving from fixing breaches after they happen to preventing them before they matter requires tracking different things. Process metrics tell you if new prevention activities are happening, and outcome metrics tell you if they’re working.
Leadership changes
Use this when you’ve had a leadership change. New executives come with new priorities. If you have a documented measurement system, you can show them how security supports their goals without starting from scratch.
Rapid growth
It works when you’re scaling up quickly. Imagine a company like Precision Components, LLC hitting eight million dollars in revenue. Growth creates new risks faster than your team can document them, so a measurement system scales with you because it’s built on processes, not personalities.
When NOT to use this
Don’t use this if you don’t have executive buy-in for the concept of integration. You’ll collect metrics that nobody reads. Get agreement on the premise first that security belongs in business planning, then build the measurement system around that premise.
Why Does This Matter?
Integration without proof is just hope. You can say security is embedded in your operations. You can claim it’s part of every project decision. But if you can’t show it with data, leadership treats it as noise. The measurement system turns assertions into evidence.
Connecting Security to Business Performance
Most organizations track security separately from business performance. They run a security report next to a financial report and pretend they’re related. This resource helps you connect them directly.
- Time-to-market becomes a security metric.
- Customer trust becomes a security metric.
- Operational efficiency becomes a security metric.
These aren’t just nice additions. They’re proof that security affects outcomes people care about.
The Alternative Is Guessing
- Guessing whether your investments are paying off.
- Guessing if integration is improving.
- Guessing if stakeholders trust you.
Guessing burns resources. A measurement system replaces guesses with trends.
What Happens Without Measurement
Consider what happens when you don’t have this. A project gets delayed because of a late security review. Nobody knows if that delay was necessary or if better planning would have avoided it. You repeat the mistake. Six months later, the same thing happens. A year later, business leaders stop involving security in early planning because they think it’s just bureaucratic overhead.
With a measurement system, you see the pattern. The quarterly analysis shows bottleneck trends. You identify the specific project stage where security checks fail. You adjust the process. The next quarter shows improvement. The data proves you moved in the right direction.
Sustaining Momentum Through Changes
New executives inherit reports. If those reports show consistent progress over time, they respect the work. If the reports disappear when a champion leaves, the program resets. Documentation keeps the program alive across personnel shifts.
Why Specificity Works
Generic dashboards collect data without purpose. This exercise ties every metric to a decision it informs. You know why you’re tracking each number. You know who needs to see it. You know when to act on it. That specificity makes it credible.
A Look at the Completed Example
It’d be so much easier if you’ve downloaded the exercise: Word | Markdown | Proton Docs
Here’s what the finished product looks like when you apply the framework to a real scenario.
The first section captures which metrics you’ll track. Process metrics show activity levels. Outcome metrics show business value. Perception metrics show how people feel about security’s role.

This metric tells you if security is getting involved early enough. If the number drops, you know integration broke down somewhere in the workflow.

This connects security work to business speed. A shorter approval window means security isn’t a bottleneck. It’s an enabler.

Feelings matter. If business leaders dislike how security operates, they’ll find ways around you. Positive perception predicts cooperation.
The reporting format section determines who sees what information.

Executives need trends. Managers need operational details. Workers need tasks. One size doesn’t fit all.
Timing drives consistency.

Monthly data collection prevents backlog. Quarterly workshops allow for corrective action. Board reviews maintain executive visibility.
Communication strategy handles difficult conversations.

Different leaders care about different things. Tailoring messages builds trust. Planning for bad news prevents panic when numbers dip.
Frequently Asked Questions
How Long Does It Take to Complete This Worksheet?
Most teams finish it in two to three weeks. You need input from multiple departments to define metrics and data sources accurately. Rushing it reduces credibility.
Do I Need Special Software to Run This Measurement System?
No. You can start with spreadsheets and existing ticketing systems. Automation helps but isn’t required initially. Focus on consistent collection before worrying about tooling.
What If My Organization Resists Sharing Data Across Departments?
Start with metrics that benefit the resisting department directly. If IT won’t share project timelines, show how faster security reviews reduce their rework burden. Win them with value before asking for data.
Can I Use This If I Work for a Small Company with Limited Staff?
Yes. Scale the frequency of reviews to match your capacity. A monthly collection might become quarterly. The framework adapts to resource levels.
How Often Should I Update the Metrics Themselves?
Review them annually. Major business changes justify mid-cycle updates. Changing metrics too frequently undermines trend data credibility.
What Happens When Metrics Show Failure Instead of Success?
Treat it as diagnostic data. Document why it happened. Adjust the process. Show the improvement curve in the next reporting period. Failure without correction hurts credibility. Failure with correction builds trust.
Does This Replace Other Security Metrics I’m Already Tracking?
No. It adds a layer that connects existing metrics to business outcomes. Keep tracking vulnerabilities and incidents. Add integration metrics alongside them.
Attribution
This resource and the accompanying training are derived from the work of Kayne McGladrey, author of “Cyber Risk is a Myth” (published 2026). You can find the book for sale online, wherever you buy books, and at your local library. The fictional company scenarios used in the examples are for illustrative purposes only and do not represent real organizations.