This document is under active development and has not been finalized.
Skip to content

KPIs & Metrics

Security KPIs

Vulnerability Management

KPIDefinitionTargetMeasurement
Patch compliance% of vulnerabilities patched within defined deadlines≥ 95%Monthly
Open critical vulnerabilitiesCount of unpatched CVSS ≥ 9.0 vulnerabilities0Weekly
Mean Time to Patch (MTTP)Average days until patch deploymentCritical: < 2d, High: < 7dMonthly

Incident Management

KPIDefinitionTargetMeasurement
Mean Time to Detect (MTTD)Time from attack onset to detection< 24 hoursPer incident
Mean Time to Respond (MTTR)Time from detection to containmentCritical: < 4h, High: < 24hPer incident
Reporting compliance% of incidents reported to BSI within required deadlines100%Per incident

Access Control

KPIDefinitionTargetMeasurement
MFA coverage% of accounts with active MFA100% (external access)Monthly
Orphaned accountsCount of active accounts without a corresponding employee0Monthly
Offboarding compliance% of accounts deactivated within 24h of departure100%Per event

Business Continuity

KPIDefinitionTargetMeasurement
Backup success rate% of successful backup jobs≥ 99%Daily
Restore success rate% of successful restore tests100%Quarterly
RTO complianceRecovery time within defined target100%Per test / incident

Training

KPIDefinitionTargetMeasurement
Training completion% of employees who completed mandatory training100%Annually
Management trainingManagement has completed cybersecurity trainingYesAnnually
Phishing click rate% of employees clicking on simulated phishing< 5%Semi-annually

Reporting Structure

ReportContentRecipientInterval
Security DashboardAll KPIs at a glanceISOContinuous
Monthly Security ReportKPI trends, open findings, incidentsISO + IT LeadMonthly
Quarterly Management ReportKPI summary, risk status, measuresManagementQuarterly
Annual Security ReportOverall assessment, audit results, improvement planManagementAnnually

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT