Tips
- To be able to lead change in your organization, you should know how to use and address the cybersecurity metrics, as demonstrated in Figure 4.13:
Figure 4.13: Cybersecurity metrics
- Ensure that you understand the metrics very well, as your IR success heavily depends on them.
- As discussed earlier, communication with stakeholders is very important. The metrics can help you to formulate data and statistics that will allow the leadership team to make critical decisions.
- Your IR program should be built around metrics that will help you to showcase to senior management your leadership skills and demonstrate to partners the maturity of your organization and processes.
- Identify gaps in prevention, detection, and operational capabilities. Pinpoint areas of focus for process improvement, based on the standards set out in ISO 27001, an international IT security framework. This includes the PDCA (or Plan, Do, Check, Act) protocol relating...