ADVERTISEMENT
This article is sponsored and contains advertising.

Measuring Cyber Risk Isn't Optional — It's National Security

measuring cyber risk featured image

Wang's Original Metrics Framework

  • Breadth measures the extent of protection — the percentage of assets, systems, users, or processes actually under a given control. It answers the fundamental question: how much of the environment is under control?
  • Performance evaluates whether controls operate with the speed, accuracy, and consistency real-world threats demand — detection accuracy, response speed, patch timelines, recovery success rates, and SLA adherence.
  • Friction quantifies the operational burden security imposes on the organization: engineering hours lost to authentication workflows, deployment delays from patch cycles, analyst time consumed by false-positive alerts. This dimension is Wang's sharpest departure from conventional cost analysis, which counts license fees and headcount but misses what security actually costs the rest of the organization.
ADVERTISEMENT

Applying the Dimensions Across NIST CSF 2.0

FunctionCategorySubcategory (example)BreadthPerformanceFriction
GovernRoles, Responsibilities & Authorities (GV.RR)GV.RR-02: Roles for cybersecurity are established% of business units with assigned risk ownersTime taken to approve or review risk exceptions; SLA adherence for policy updatesHours leadership spends per review cycle; project delays waiting on risk-ownership decisions
IdentifyAsset Management (ID.AM)ID.AM-01: Hardware inventories are maintained% of hardware and software assets inventoriedTime required to update inventory when new assets appear; accuracy of asset classificationEngineering hours per asset to maintain accurate inventory; cross-team coordination overhead when asset records are stale
ProtectIdentity Mgmt, Auth & Access Control (PR.AA)PR.AA-03: Users, services, and hardware are authenticated% of users with MFA activatedAccess request approval time for privileged accountsEngineering hours lost to authentication workflows; support ticket volume for access issues; deployment delays from access-control gates
DetectContinuous Monitoring (DE.CM)DE.CM-01: Networks and network services are monitored% of critical systems sending logs to SIEM; % of monitored assets covered by behavior-based analyticsMean time to detect (MTTD) suspicious activity; true-positive rate for alert detectionAnalyst hours per alert investigated; false-positive triage burden as % of SOC capacity
RespondIncident Management (RS.MA)RS.MA-02: Incident reports are triaged and validated% of incident response workflows documented; % of staff included in incident notification proceduresMean time to respond (MTTR) to high-severity incidents; % of incidents handled within SLAEngineering hours diverted from product work during incident surges; cross-team coordination overhead per incident
RecoverRecovery Plan Execution (RC.RP)RC.RP-03: Backup integrity is verified before restoration% of systems with validated backups; % of business processes with tested recovery plansTime required to restore systems from backup; % of recovery tests completed without errorsEngineering hours per recovery drill; system downtime during backup verification; team disruption from unscheduled recovery exercises

From Measurement to Investment Strategy

Adopted and Generalizable

Disclaimer
ADVERTISEMENT