Understanding KPIs
While the KPIs highlighted are important, organizations should not become excessively fixated on the numbers. Simply knowing the problematic areas in an organization's cybersecurity defense will not solve the underlying issues. In many cases, these metrics identify inefficiencies in the IR team. However, they might not capture some contextual information about the numbers they present.
For instance, a sudden increase in open tickets might indicate that there are inefficiencies in the IR team but may not indicate why. It could be the effect of a sudden increase in customer numbers or the exit of some personnel required to solve the incidents. Consequently, organizations need to invest more in getting insights into the numbers that these metrics show. Without much information, companies could become frustrated with their IR teams if the metrics recorded are not desirable. However, when the measurements are coupled with important business or security...