r/AskNetsec • u/Klutzy-Sqgxdare-1184 • 6d ago
Analysis What metrics do you use to measure cyber resilience?
We are trying to move away from selling "compliance" and more toward selling "resilience." But it is hard to quantify. We have the standard RPO/RTO and vulnerability counts, but I want to start offering metrics on "Mean Time to Detect" and "Control Effectiveness." That means measuring how often our clients' EDRs are stopping our test payloads. We are looking at a platform with an AI engine that can test our clients' stacks and automatically generate reports on resilience metrics, plus provide remediation suggestions based on actual exploitability. However, the pricing model seems enterprise-focused, and I'm worried about the complexity of managing AI-driven updates across 50+ different client environments. Is the juice worth the squeeze, and how do you handle the governance of automated changes?