Cybersecurity KPIs: Making security measurable | SITS
Blog

Auditability as the Cybersecurity KPI: Making security measurable

Cybersecurity measures must do more today than simply exist on paper. Organizations need auditable KPIs that demonstrate whether security controls are effective, risks are covered, and regulatory requirements are being met. Learn how to develop robust cybersecurity KPIs for NIS2, ISO 27001 and an effective ISMS.
3 minutes

New cybersecurity regulations, particularly those introduced through the NIS2 Directive, require the effective implementation of risk management measures. The effectiveness of the cybersecurity practices achieved must be auditable and explicitly demonstrated throughout the supply chain.

In practice, this is best achieved through traceable Key Performance Indicators (KPIs), as an Information Security Management System (ISMS) must be managed using criteria that demonstrate whether defined objectives have been achieved. At the same time, a higher maturity level can only be reached if meaningful KPIs are identified, measured as automatically as possible, and monitored regularly. But where should organizations start to avoid getting hopelessly lost in a multitude of individual metrics?

The importance of these metrics is currently increasing. Regulatory requirements are having a greater impact on security processes, governance structures, and technology decisions. Organizations therefore face the challenge of implementing security measures while also being able to demonstrate their effectiveness to customers, regulators, and business partners. The question is therefore becoming less and less frequently, “Are measures in place?” and increasingly, “Can we prove their effectiveness?”.

Defining Cybersecurity KPIs correctly: What really matters

Experience shows that meaningful KPIs can only be developed if the following approach is taken into account:

  1. Only select something as a metric if it provides a clear indication of whether important objectives have been achieved and can be measured objectively, meaning with reproducible results.
  2. Only define a metric if measuring it actually provides feedback on required corrective actions.
  3. When selecting metrics, consider who the recipient of the metric will be and whether it will provide that recipient with a relevant gain in insight.
  4. A metric is only credible if the recipient has the impression that its collection could be reviewed, if necessary, potentially by an appointed third party, and that the reported value could therefore be verified.

A KPI is ultimately created by deliberately consolidating metrics, for example through the correlation or combination of different measured values.

In practice, however, organizations often collect too many metrics and lose sight of the bigger picture. What matters is not the number of metrics, but their relevance. A KPI should always be able to answer a specific question, such as whether critical systems are sufficiently protected, whether security measures remain effective over time, or whether existing risks have actually been reduced. Only then does it provide reliable value for management and operational teams.

ISO 27001: Requirements for Cybersecurity KPIs and measurability

According to Clause 6.1.1 of ISO/IEC 27001, organizations must ensure that their ISMS achieves its intended outcomes. These outcomes must be defined in measurable terms in accordance with Clause 6.2, and their achievement must be monitored. Organizations must determine how results will be evaluated at the planning stage. ISMS processes are managed based on defined criteria, making it possible to trust that the processes are being carried out as planned.

This is therefore about trust. More specifically, it is about confidence that the requirements and expectations of interested parties are being reliably fulfilled through the ISMS. This includes legal and regulatory requirements as well as contractual obligations. Or to put it another way: it is about confidence that relevant cybersecurity requirements are being fulfilled through the ISMS in a traceable and transparent manner.

Clause 9.1 of the standard also requires monitoring and measurement methods to produce valid, comparable, and reproducible results. This requires documented information, meaning documentation that is controlled and approved.

This aspect is becoming increasingly important as new regulatory requirements emerge. Documented evidence is no longer used exclusively for internal audits. It is increasingly becoming the basis for compliance assessments, supplier assessments, and regulatory evidence requirements. The ability to collect meaningful metrics in a transparent and traceable way is therefore becoming a central component of modern security governance.

NIS2 requirements: Which Cybersecurity KPIs do organizations need?

To manage risks to the security of network and information systems:

  • The impact of security incidents must be kept as low as possible through prevention, a focus on realistic scenarios combined with the rehearsal of appropriate responses, and the effective early detection of events requiring action.
  • The continuation of adequate operations must be ensured, particularly under difficult conditions, thereby giving due consideration to Murphy’s Law.
  • Relevant input factors, such as the supply chain and vulnerabilities of the network and information systems used, must be controlled to prevent risks from being passed on “silently” to users and recipients as far as possible.
  • Common practices and principles relating to cyber hygiene must be followed. These include timely and targeted updates, appropriate protection of access points, reliable data backups, effective isolation through network segmentation, hardening and the Zero Trust principle, as well as the detection of unusual activity.

It is therefore advisable to derive KPIs for these four areas to obtain reliable feedback on the “health status” of the organization’s own network and information systems. The focus should be placed on systems that are critical to the organization’s value creation.

From metrics to reliable security decisions

A single measured value rarely provides a complete picture. Only when different metrics are considered together does it become clear whether security measures are actually effective and which risks still remain.

For example, the proportion of successfully remediated vulnerabilities can be combined with the number of critical attack paths. Similarly, the availability of emergency measures can be assessed together with the results of recovery tests. Combining several metrics in this way creates a KPI that enables a significantly more meaningful assessment than isolated individual values.

This transition from individual measured values to a holistic assessment will become increasingly important as organizations seek to demonstrate the maturity of their cybersecurity in a reliable manner.

Practical Example: Measuring Cyber Resilience with KPIs

An ISMS is resilient to security incidents if it is capable of withstanding relevant threats that are difficult to predict and may change rapidly, while achieving an adequate level of protection through reliable and stable network and information systems

The required resilience can be measured by determining whether every access point to network and information systems that are critical to the organization’s value creation is demonstrably subject to a control mechanism under which access is explicitly granted. This can be achieved, for example, through dedicated jump hosts or network zones combined with multi-factor authentication.

The former can, for example, be assessed technically by tracking potential attack paths using automated Attack Path Management, Continuous Threat Exposure Management, or External Attack Surface Management. Vendors regularly introduce new terms for these approaches, but ultimately, they all address the question of whether relevant attack paths have been sufficiently managed.

In this case, a meaningful metric could indicate the level of coverage currently achieved by the respective technical solution. Providers of these technical solutions also offer corresponding benchmark values, making it relatively easy to determine whether there is a greater need for action in order to achieve a better result. Since the result is usually presented as a percentage, the metric is sufficiently easy for recipients to interpret. Verification in this context primarily involves determining whether an important connection may have been unintentionally excluded and should therefore be included in the next evaluation cycle.

The required robustness, in turn, can be measured by determining whether a so-called Golden Image is available for the network or information system. Based on automated testing, this Golden Image should be demonstrably error-free and provide a sufficiently functional basis that can serve as a fail-safe mechanism for server systems. Source code analyzers that refer to established Secure Coding Guidelines and Hardening Guidelines provide a good basis for a meaningful metric. Here too, the ultimate result is effectively a documented level of implementation that highlights any existing need for action.

Together, the two metrics ultimately provide a meaningful KPI for the level of cyber resilience achieved. This is precisely where the real value of modern KPIs lies: They consolidate complex technical relationships into transparent and understandable foundations for decisions by management, auditors and regulators.

Making compliance and NIS2 maturity measurable

Naturally, compliance with cybersecurity requirements can also be demonstrated using KPIs. This is done, for example, as part of NIS2 Assessments. These assessments quickly provide a clear, targeted, and action-oriented overview of the areas that should be prioritized in order to achieve a higher level of trust. In line with the principle “Do good and talk about it,” the results can also be presented to relevant interested parties in a way that builds trust.

The Cyber Security Score determined for NIS2 compliance indicates how far an organization has already progressed in implementing the NIS2 regulation. In addition, the NIS2 Assessment indicates the level of implementation achieved with regard to governance, the state of the art, and an all-hazards approach. And that is precisely what is ultimately needed to establish a sufficient level of trust.

For sectors that are subject to NIS2 Implementing Regulation 2024/2690, we take our NIS2 Assessments one step further. In this case, the legislator has issued precise requirements for the measures that must be implemented. This allows us to provide relevant entities in these sectors with detailed feedback on the level of implementation achieved, building on the foundation of the general NIS2 Assessment. The European Commission has already announced comparable framework requirements for additional sectors. We are monitoring this development closely.

How does SITS support organizations in developing meaningful Cybersecurity KPIs?

Meaningful KPIs are not created by collecting as many metrics as possible. They result from the right selection, assessment, and continuous development of relevant measured values. This is precisely where SITS supports organizations in introducing, aligning, and optimizing KPIs for cybersecurity, compliance, and governance.

Drawing on our experience in Compliance Management, ISMS, NIS2 Assessments, and Security Assessments, we help organizations define measurable security objectives, derive suitable metrics, and develop reliable KPIs for management, auditors, and regulators. The focus is not on generating as many reports as possible, but on developing metrics that deliver insights that are genuinely relevant for governance and decision-making.

Our experts help organizations translate security requirements, regulatory obligations, and operational security measures into a transparent and traceable governance model. This creates an approach that combines compliance, risk management, and practical feasibility. Ultimately, it is not enough simply to implement cybersecurity. Organizations must also be able to provide reliable evidence that their measures are effective.

Would you like to learn which KPIs are genuinely meaningful for your organization and how the maturity of your cybersecurity can be measured?

Our experts will help you define the right KPIs, assess risks and develop a robust, sustainable security strategy.

How will Cybersecurity change by 2030?

Many organizations already collect cybersecurity metrics. The key question, however, is whether these metrics are sufficient to provide reliable evidence of compliance with future regulatory requirements, audits, and governance obligations.

Our CxO Security Agenda 2030 shows which topics European security leaders are currently prioritizing and which changes they expect by 2030. In addition to NIS2 and compliance, the study focuses particularly on auditability, digital sovereignty and AI governance.

Frequently Asked questions about Cybersecurity KPIs

A cybersecurity KPI is a consolidated metric that shows the extent to which a relevant security objective has been achieved. Several operational measured values can be combined for this purpose. A good KPI provides a clear indication, is based on objectively collected data, and highlights where action is required.

For NIS2, the most relevant KPIs relate to security incidents, cyber resilience, business continuity, vulnerability management, supply chain risks, and cyber hygiene. The metrics an organization needs depend on its risk profile, critical systems, and regulatory exposure.

There is no universally applicable number. It makes sense to use a limited selection that covers all essential security objectives and remains relevant to the respective recipients. Too many metrics make it more difficult to prioritize. Too few metrics can make critical risks or dependencies less visible.

The relevance of a KPI can be assessed by documenting its data source, measurement method, measurement interval, and ownership. The result should be reproducible and comparable across several evaluation periods. In addition, organizations should verify whether all relevant systems, processes and connections have been included in the measurement.

Assessment & Advisory
Grundschutz++ explained
Learn more
Assessment & Advisory
Auditability as the Cybersecurity KPI
Learn more
AI
SASE and AI Security: How organizations can use AI securely without losing control
Learn more
Assessment & Advisory
Check Point Security Hardening
Learn more
AI
Microsoft Copilot & Compliance
Learn more
AI
The AI Compass: How companies maintain course in times of Shadow AI
Learn more
RSA & ECC nearing the finish line: Become crypto‑agile now
Learn more
NIS2
NIS2aaS - Comprehensive support for NIS2 implementation
Learn more
AI
Ransomware 2.0: How AI is rewriting the rules of Cyber Defence
Learn more
Cloud Platform Security
Governance & Oversharing: How Copilot becomes a Productivity Booster
Learn more
NIS2
NIS2, DORA & Co: Aren’t we all part of someone’s relevant supply chain?
Learn more
Security & IT Solutions
Digital Resilience starts with Security by Design - That's why Managed Services are strategically unavoidable
Learn more
Cloud Platform Security
Copilot Usecases: Transforming Business Workflows from Personal to Organizational Impact
Learn more
Cloud Platform Security
If Copilot still doesn't ignite … yet
Learn more
Cyber Resilient Workplace
How Resilient Is Your Workplace IT Really?
Learn more
SITS
From 1 April 2025: mandatory reporting of cyberattacks on critical infrastructure in Switzerland
Learn more