logo

Quantifying Risk: How do you measure success in security?

ID: f6efdfbf-c212-5e35-8f70-f5a593b3cbe2

STIX ID: report--f6efdfbf-c212-5e35-8f70-f5a593b3cbe2

Feed Name: HackerOne Blog

Date Published: 2024-11-20

Date Updated: 2026-06-11

...
...

This piece summarizes a HackerOne conference discussion where CISOs from Slack and Hyatt describe pragmatic ways to quantify cybersecurity ROI — focusing on simple metrics (efficiency finding vulnerabilities, effectiveness of prevention via trends, and time-to-remediate), leveraging cyber insurance, and framing security stories and tactical items (pentest findings, incidents, residual risk, scope changes, challenges) for board communication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.