Cybersecurity needs a new KPI: it's time to measure our ability to adapt
Cyber resilience depends on more than response times. It's time to measure adaptation too.
For decades, cybersecurity has been a quantifiable field. Security executives can frequently cite the time it takes to recognize a breach, contain the threat and return operations to normal. These figures provide executives with a clear means of assessing progress, demonstrating that security investments are yielding tangible benefits.
Indicators such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have secured their positions in the industry's lexicon. They effectively illustrate the efficiency of security teams during an incident and have contributed to improved incident response across the sector. However, these metrics are not without their limitations.
They were developed in a time when technology evolved at a slower pace, attack methods evolved over extended periods and artificial intelligence had not yet become a significant factor. In today's rapidly evolving business landscape, characterized by frequent technological advancements, AI integration, expanding cloud environments and heightened interconnectivity, the traditional metrics may no longer provide a complete picture of an organization's security posture.
Cybersecurity professionals and board members need to regularly reassess the changing threat landscape and risk profile, questioning whether the established metrics continue to accurately reflect the current state of affairs. Every business aspires to detect threats promptly, contain them swiftly and restore operations with minimal disruption.
This underscores the importance of MTTD and MTTR as operational metrics, as they indicate the effectiveness of a security team once an incident has commenced. However, these metrics do not reveal whether the business is proactively enhancing its preparedness for future incidents, becoming more resilient and agile in its recovery process.
This is crucial, as cyber risk persists long after an incident has been mitigated. A UK Government survey in 2025/2026 revealed that 43% of UK businesses experienced a cyber breach or attack within the preceding year. This statistic highlights the reality of operating in an environment where incidents are an ongoing concern, whether they occur within an organization's own ecosystem or through its supply chain.
While swift incident response is vital, resilience is fostered by the actions taken before an incident even occurs. A business may recover rapidly from an attack, yet it may still take months to revise security policies, reassess supplier risks or reinforce controls based on the lessons learned. By the time these improvements are implemented, the threat landscape will have evolved once again.
To bridge this gap in preparedness, it is imperative that metrics evolve as well. Organizations should consider introducing a new benchmark alongside the existing ones: Mean Time to Adapt (MTTA). MTTA measures the time taken to identify meaningful changes in the threat landscape and convert that knowledge into action. This adaptation could involve technical adjustments, such as updating the rules governing security tools to detect emerging attack techniques, tightening access to critical systems following the discovery of a significant vulnerability, or adopting a proactive approach by learning from attacks on other organizations or sectors to assess the organization's own vulnerabilities.
Alternatively, adaptation may take an organizational form, including reviews of governance structures, modifications to how cyber risk is reported to the board, or updates to employee awareness programs to reflect the latest tactics employed by cybercriminals. Both technical and organizational responses contribute to overall resilience.
The most effective security programs combine technical enhancements with organizational transformations, enabling businesses to swiftly recognize change and respond accordingly. Closing this gap is not merely a technological challenge; it necessitates decision-making, leadership, and a commitment to continuously question whether existing assumptions remain valid.
Resilient organizations rarely assume that their current security program is complete. They anticipate that it will evolve due to the continually shifting business environment. This perspective is increasingly echoed throughout the cybersecurity industry. For instance, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management, and continuous improvement at the forefront of cyber resilience, recognizing that security is an ongoing organizational capability rather than a one-time achievement.
As a result, discussions in the boardroom will likely shift from a focus solely on incident response to encompassing preparedness and adaptation. While incident-related updates and phishing activity reports remain valuable, they may not always convey how well the business is responding to the evolving threat landscape itself. The conversation must transcend operational reporting and prioritize MTTA.
This shift would enable boards to gauge how rapidly an organization adapts to change, rather than merely evaluating its efficiency in handling incidents. Practically, this entails asking different questions. How swiftly does the business reassess risk in response to a significant new threat? How long does it take for new intelligence to influence security policies?
Have recent attacks prompted fundamental changes in the organization's operations, or have they merely been documented and set aside? By measuring adaptation rather than response alone, organizations can gain a more comprehensive understanding of their resilience and foster a broader perspective on cybersecurity. This approach extends beyond the realm of security teams and requires a collective commitment to ongoing improvement and preparedness.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.