The Metrics Mess: Why the Lack of Clear and Common KPIs is Undermining SecOps (and How We Can Fix It)

Eric Olson

BSides NYC 2023 (0x04) · Day 1 · Talk - Blue

Eric Olson, a self-described "NBA bean counter weenie" who accidentally found his way into cybersecurity in 1999, delivered a compelling talk at BSides NYC addressing a fundamental flaw in the security industry: the absence of clear, common **Key Performance Indicators (KPIs)** for **Security Operations (SecOps)**. Olson, whose remit at JetBlue Airways spans threat intelligence, threat hunting, SOC, incident response, attack simulation, and detection engineering, argues that this "metrics mess" is a significant impediment to effective security. Without standardized definitions and a shared language for measuring incident response, organizations are unable to accurately assess their performance, identify bottlenecks, or demonstrate improvement.

AI review

Olson identifies a real and underappreciated problem — the industry genuinely can't agree on what MTTD and MTTR mean, and that's embarrassing — and he backs it up with actual primary research across 12 vendor sources. The B6 model is sensible and practitioner-friendly, but it's not novel enough to be a conference-defining moment; this is a well-argued blog post with a stage.

Watch on YouTube