Podcast
Root Causes 476: The Need for Security KPIs


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
March 10, 2025
Jason recounts a 2024 Black Hat talk about the need for objective measurements of our IT defenses and whether the good guys or bad guys are winning. Jason breaks down how to define and measure the impact of security measures.
Podcast Transcript
Lightly edited for flow and brevity.
The other one, though, is there's a secrecy problem. There's no reason to hide the fact that there was an earthquake. But when you get into breaches or vulnerabilities, you get into all kinds of tricky issues about, what do I want to reveal? When do I want to reveal it? How much do I want to reveal? What's the nature of what I want to reveal, and what's the nature of what I don’t. I can see where that would be a big impairment to building some kind of fact-based, comprehensive, consistent model around these factors.
Then lastly, sometimes you just don't know. Some attackers do things like go and erase their activities so you can't figure out what they did, and sometimes that's effective enough that it obscures things like timelines, and so there will be times when that isn't really measurable at all.

