Cyber Metrics Platform¶
Continuous Security Assurance Through Automated Data-Driven Metrics
The Cyber Metrics Platform transforms raw security tool data into actionable business intelligence for cybersecurity teams. By automatically collecting data from your existing security stack and processing it through standardized metric definitions, the platform provides real-time visibility into security posture, control effectiveness, and operational performance.
What Makes This Different¶
From Data to Decisions: Rather than manual spreadsheet-based reporting, this platform automatically ingests data from security tools like CrowdStrike, Tenable, Okta, and Snyk, then applies SQL-based metric definitions to generate consistent, comparable measurements.
Operational Focus: Metrics are designed around real security operations - vulnerability management prioritization, incident response effectiveness, access control hygiene, and compliance posture - not just checkbox compliance.
Framework Alignment: Every metric maps to established frameworks (ISO 27001, CIS Controls, NIST CSF, Essential 8) while maintaining practical utility for day-to-day security operations.
Simple Architecture: Data is collected to Parquet files, and a dashboard runs the metrics against them and shows the current scores.
Platform Architecture¶
Two-Stage Pipeline¶
- Collect (
01-collectors/): Automated data extraction from security tools via posture posturecollectwrites every table from every configured source to Parquet-
See the supported sources
-
Measure (
02-metrics/,03-dashboard/): SQL-based metrics defined in YAML, run and displayed by the dashboard - DuckDB query engine with Jinja2 templating
- Standardized output schema (resource, compliance, detail)
- Configurable SLO thresholds and weighting
- Web scorecard with resource-level detail and filters
Example: Vulnerability Management¶
The platform includes comprehensive vulnerability management metrics that move beyond simple "count of critical vulnerabilities" to operationally useful measurements:
- Posture Metrics: "What percentage of systems have addressed patchable, exploitable OS vulnerabilities?"
- Performance Metrics: "Are we meeting our 7-day SLA for Patch Tuesday Priority vulnerabilities?"
- Categorization: Vulnerabilities classified by urgency matrix (Patchable+Exploitable = "Just bloody patch it")
How to use this guide¶
Types of Metrics¶
| KxI | Description | Example |
|---|---|---|
| A measure that tracks the implementation of actions, processes, or technologies designed to reduce or mitigate risks within the organization. | % of systems with MFA enforced | |
| A measure that provides visibility into existing or potential risks within the organization, helping to assess areas of vulnerability. | % of endpoints with critical vulnerabilities | |
| A measure that evaluates the efficiency and speed with which a team is executing and delivering on control implementations and operational tasks. | Time to deploy security patches |
Framework references¶
The following frameworks are used in the mapping of metrics
Getting Started¶
Quick Start¶
# 1. Collect data from your security tools
posturecollect --output data/source
# 2. Run the metrics and view them at http://127.0.0.1:5000
cd 03-dashboard && python app.py
Configuration¶
Set environment variables (or a .env file) for your security tool APIs. See 01-collectors/ for posture's settings and 03-dashboard/ for the dashboard's.
Creating Custom Metrics¶
Define new metrics using YAML files in 02-metrics/. Each metric specification includes:
- Metadata (title, description, compliance mapping)
- SQL query using {{ref('table_name')}} pattern
- SLO thresholds and performance targets
See schema.md for complete data source documentation.
Contribute¶
New Metrics: Define additional metrics using the YAML specification format
New Collectors: Add support for additional security tools in posture
Access Control¶
| Metric | Type |
|---|---|
| Access Control - Account Deactivation Timeliness | |
| Access Control - Leavers with Disabled Accounts |
Asset Management¶
| Metric | Type |
|---|---|
| Asset Management - Asset Discovery Coverage |
Data Protection¶
| Metric | Type |
|---|---|
| Data Protection - Volume Encryption Coverage |
Disaster Recovery¶
| Metric | Type |
|---|---|
| Disaster Recovery - Backup Configuration Coverage | |
| Disaster Recovery - Backup Success Rate |
Identity Management¶
Malware Protection¶
| Metric | Type |
|---|---|
| Malware Protection - Agent Deployment Coverage |
Network Security¶
Software Development¶
| Metric | Type |
|---|---|
| SDLC - Repositories with SAST / DAST scanning enabled | |
| SDLC - Repositories without exploitable vulnerabilities | |
| SDLC - Repositories without exploitable vulnerabilities remediated within SLO |
User Security¶
| Metric | Type |
|---|---|
| User Security - Awareness Training Completion | |
| User Security - Phishing Simulation Resilience |