Thinking about OKRs vs metrics as a CISO


Hey there,

Navigating the intricate dance between strategic objectives and actionable metrics is a craft every CISO needs to master.

That's why this week, we're thrilled to bring you an article that dives into this relationship. Discover how OKRs and metrics complement each other and how to leverage them for enhanced security postures and organizational success.

OKRs and metrics can be a fantastic tool to communicate internally amongst a team or department but also across departments to our peers.


Action item

It's time to take inventory of your work here. If you don't yet have OKRs or a strategic plan, start by writing out some of your key goals and the things you can easily measure today. If you're in a more mature state, you might take an inventory of all your current metrics being reported on.

The action is not in creating an inventory, though.

Take the time to think critically about whether these metrics are serving the outcomes you want. It's really easy to fall into a mindset that numbers yield success, when in reality, if you're measuring the wrong thing or creating the wrong incentives, you may be way off track.


Keep growing,

- Rob & Frank

Soft Side of Cyber

LinkedIn | YouTube

https://www.softsideofcyber.com

113 Cherry St #92768, Seattle, WA 98104-2205
Unsubscribe · Preferences

Soft Side of Cyber

Empowering cybersecurity professionals with the non-technical skills they need to thrive.

Read more from Soft Side of Cyber

How often have you been in a room full of cybersecurity people, only to observe them mocking those who are "social" or "non-technical" in their skills? We don't train on it. We don't seem to value it. So why bother talking about emotional intelligence and social skills? It's because we believe it's at the core of actually getting things done in cybersecurity. It's the intangible yet valued things that separate the effective from the ineffective. In this week's article, Frank explores...

Hey there, Compliance is so often looked at in security circles as a burden. It’s a thing to do. It’s expensive. It’s not equating to actual security. Those are just a few of the many reasons that security teams are typically not the biggest fans of compliance. This week’s article focuses on how you can get the most out of compliance so it can actually help your business instead of hamper your team’s resources and energy levels. If you’re leading a security team or involved in the day-to-day...

Hey there, Are you aspiring to climb the ladder in your cybersecurity career but unsure where to start? Whether it’s the prestigious CISO role you’re eyeing or a leap into a more strategic position, understanding the intricacies of career advancement is crucial. Our latest article, "So You Want to Get Promoted in Cybersecurity?", is a treasure trove of insights tailored just for you. It delves into the different pathways you can take in the field, whether it’s the individual contributor or...