What KPIs should I be measuring for cybersecurity?

The six most important Key Performance Indicators (KPIs) to measure for cybersecurity are:

  1.     MTTD: Mean Time to Detect – how fast do you identify an attack?
  2.     MTTA: Mean Time to Acknowledge – how quickly is the security team able to verify an attack?
  3.     MTTR: Mean Time to Respond – how much time does it take to start mitigation against the attack?
  4.     MTTC: Mean Time to Contain – how much time does it take to isolate the threat and prevent further impact?
  5.     MTTR(2): Mean Time to Recovery – how much time does it take for the company to recover from the threat, or any downtime/issues caused by the threat?
  6.     MTBF: Mean Time Between Failures – what is the average amount of time between system failures?


