Defining metrics and KPIs
Measuring the effectiveness of an offensive security program and how it helps the organization remove uncertainty around its actual security posture and risks is one of the more difficult questions to explore and answer. When it comes to metrics, we need to distinguish between what I refer to as internal versus external adversarial metrics.
Tracking the basic internal team commitments
Internal metrics are those that the pen test team use to measure and hold themselves accountable. Some organizations call these commitments or objectives and key results (OKRs). Initially, the metrics might be quite basic, and comparable to project management KPIs:
- Performing x number of penetration tests over a planning cycle and delivering them on time
- Committing to performing a series of training sessions in H2
- Delivering a new Command and Control toolset in Q4
- Delivering a custom C2 communication channel by Q1
- Growing the team by two more pen...