惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Y
Y Combinator Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
L
LangChain Blog
美团技术团队
N
Netflix TechBlog - Medium
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
博客园 - 司徒正美
爱范儿
爱范儿
D
DataBreaches.Net
月光博客
月光博客
U
Unit 42
B
Blog RSS Feed
Engineering at Meta
Engineering at Meta
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
MongoDB | Blog
MongoDB | Blog
腾讯CDC

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization
Meaningful metrics demonstrate the value of cyber-resiliency
2026-04-06 · via Search Security Resources and Information from TechTarget

Paul Kirvan

By

Published: 06 Apr 2026

Business leaders face daily threats to the security of their information systems -- phishing attacks, DDoS attacks, viruses, ransomware and more. Many organizations have IT departments to address cybersecurity and manage threats to information systems, applications, websites networks and data. Larger enterprises likely have a security team or security operations center dedicated to preparing for, preventing and responding to cybersecurity incidents. 

But what happens in the aftermath of a cyberattack? How does the organization weather the intrusion? How well does it respond to the incident and then adapt and modify operations to better recover from future attacks? 

Cyber-resilience is the ability to manage the outcomes of a cybersecurity incident and, more importantly, make changes to business and technology. Mature security operations have the data and insights to establish effective cyber-resilience programs that provide measurable value to the business. 

Why CISOs need cyber-resilience metrics

As with many aspects of cybersecurity management, metrics help CISOs measure the effectiveness of their cybersecurity initiatives, particularly from a business perspective. CISOs need to understand and employ these metrics to demonstrate that cybersecurity investments not only protect the organization, but also align with business strategies and leadership priorities. 

A chart demonstrating the efforts a security team must undertake to achieve cyber-resilience.
A cybersecurity incident often prompts security teams to define a new normal to prevent similar occurrences in the future.
  • They are measurable, especially in the aftermath of a cyberattack, mapping the company's performance against acceptable performance metrics. 

  • They are business-focused and examine which business processes were affected, how well they recovered and the impact of the disruption to the firm. 

  • They help identify needed improvements in cybersecurity and decision-making. 

  • They examine all aspects of a cyberattack for insights into where the firm needs to adapt or change how it responds and recovers from an attack. 

Business, financial and operational considerations all factor into cyber-resilience analyses. Ideally, the outcomes improve cyber-resilience and result in a "new normal" that enhances cybersecurity efforts. 

Core cyber-resilience metrics

An array of metrics is available to help senior management understand cyber-resilience. The key is to select the relevant metrics for the situation. 

  • Mean time to detect measures the average time it takes for an organization to identify a security threat or incident after it occurs. Rapid MTTD and analysis reduce the likelihood that a cyberattack will disrupt business operations. 

  • Mean time to respond measures the average time it takes to contain and neutralize a cyberthreat. Rapid MTTR is essential for minimizing the severity of a cyberattack. 

  • Time needed for system recovery determines how quickly the organization can recover IT operations and return to normal business activities. 

  • Patch management metrics measure the frequency of patching and number of systems patched. Effective patching ensures cybersecurity resources are optimized for keeping the business operating smoothly. 

  • Third-party risk metrics monitor the performance of supply chains and key vendor ecosystems. 

  • Business impact metrics measure losses avoided due to resilience initiatives. 

  • Recovery time objectives versus actual recovery times metrics illustrate how quickly mission-critical assets are recovered against target recovery times. 

  • Recovery point objective metrics assess how long data can be unused before it no longer has value to the enterprise. A short-duration RPO means the risk of lost business or customer data was reduced. 

  • Percentage of backed up assets measures how many mission-critical systems, networks and applications are backed up to a secure location and have sufficient availability to minimize the likelihood of a system failure. 

  • Compliance metrics measure the level of compliance with security standards, such as ISO 27001 or NIST Special Publication 800-53. 

Best practices for implementing cyber-resilience metrics

The process for building a cyber-resilient technology infrastructure includes the following activities. 

Identify relevant business performance targets and align metrics 

Cybersecurity teams charged with addressing cyber-resilience should understand business mandates, such as uninterrupted availability, compliance and customer trust. 

Build resilience using established frameworks 

Examine cybersecurity events 

Use all relevant metrics related to cyberattack prevention, detection, response and recovery. 

Ensure metrics drive positive actions 

Use analytics to identify where investments are needed or procedures need to be changed. 

Validate metrics 

Run simulations or other tests to ensure the metrics are providing useful data. 

Balance metrics 

Balance technology metrics -- e.g., MTTD and MTTR and business metrics -- e.g., cost of downtime -- to deliver a more inclusive situation analysis. 

Discuss third-party and supply chain issues

Address external relationships and supply chains when discussing resilience, as those dependencies can pose risks. 

Keep an eye on industry trends 

Examine how other enterprises use cyber-resilience metrics to validate compliance and identify improvements. 

Establish a process for continuous improvement 

Keep metrics current and in sync with business strategies and the risk landscape to address the frequency and severity of cyberattacks. 

Ensuring useful metrics

The right metrics translate abstract values into specific data used for decision-making. Conduct these activities to ensure that cyber-resilience metrics deliver actionable results: 

  • Identify use. Define how metrics will map to business imperatives such as uptime and compliance. 

  • Address the incident lifecycle. Include metrics that address prevention, detection, response, recovery and post-event outcomes. 

  • Gather data using relevant methods. Many data sources are available, such as incident logs and risk assessments. Automate data gathering when possible. 

Reporting cyber-resilience metrics

The data metrics create is of little value unless CISOs can clearly communicate it to the board, CEO or other stakeholders or committees. CISOs must know their audience when presenting to senior management. Use business terms rather than technical jargon, discussing only the most relevant metrics linked to desired outcomes. Report on straightforward outcomes, such as "resolving a cyberattack and recovering business operations in less than one hour." When possible, use visual aids such as dashboards and charts. 

The audience will need context, so present trending data that shows how cybersecurity improvements have enhanced business risk management and justified cyber-resilience investments. People respond to stories, so consider presenting a narrative that illustrates how cyber-resilience initiatives have helped the company, such as mitigating a recent cyberattack or saving the company money. 

Paul Kirvan, FBCI, CISA, is an independent consultant and technical writer with more than 35 years of experience in business continuity, disaster recovery, resilience, cybersecurity, GRC, telecom and technical writing.   

Next Steps

Dig Deeper on Security analytics and automation