Cybersecurity Benchmarking: Why, Why Not, When and How
Generaltl;dr Benchmarking is a waste of time when focused solely on inputs (e.g. budgets) rather than outcomes (e.g. effectiveness of controls). The budget comparisons are never “apples for apples” and may often end up setting risk tolerance only marginally ahead of others who may be in a bad state to begin with. Instead, we need to decouple this and compare leading not lagging indicators of performance to show (i) how those leading indicators drive the lagging indicators in the right direction and...
Read full story at Phil Venables - Risk and Cyber →