You Spent on Security. Did It Work? Metrics Every SME Should Track
SME takeaway
If you cannot say what improved, you did not buy security. You bought hope with invoices attached.
A useful metric answers one question: are we harder to attack and easier to recover than we were last quarter?
Most SMEs I meet spend money on security every year. Antivirus. Backups. Awareness training. A pentest. A stack of policies. Sometimes ISO 27001 support on top.
Then six months pass, and nobody in the company can answer a basic question: are we actually harder to attack now, and easier to recover if something goes wrong? The invoices are clear. The result is not.
That is the real problem. Buying security is not the same as managing it. Without a small set of honest numbers, security decisions run on feelings: “we bought something”, “our IT provider handles it”, “we had a pentest”, “we passed a customer questionnaire”. That is not management. That is hope with invoices attached.
What a useful SME security metric looks like
You do not need an enterprise dashboard with forty charts. You need a handful of numbers that each answer a real question:
- Are we exposed?
- Can attackers get in easily?
- Would we notice?
- Can we recover?
- Are we improving over time?
- Is the money going into the right areas?
Anything that does not answer one of those is usually decoration. A metric earns its place only when it is understandable by management, tied to a business risk, owned by a named person, reviewed on a schedule, and connected to a decision.
The difference is easy to see once you look for it. “We detected 1,200 threats last month” tells an owner nothing useful. “98% of company laptops are protected, two are missing protection, and one of those belongs to finance” tells you exactly what to fix and why it matters. One is noise. The other is a decision waiting to happen.
None of this is new thinking. NIST CSF 2.0 treats measuring performance over time as part of running a security program, not an optional extra. The CIS Critical Security Controls are built to be focused and measurable, and CIS Implementation Group 1 is described as essential cyber hygiene. The point of all of them is the same: measure what reduces real risk, and stop admiring numbers that only look busy.
Start with ten metrics, not a hundred
If you track nothing today, do not try to build the perfect programme. Start with ten numbers, give each one an owner and a target, and review them honestly. A number nobody is responsible for is just more decoration.
The SME starter set
- % of devices known and managed
- % of users with MFA enabled
- Number of admin accounts
- Critical vulnerabilities older than 30 days
- Number of unsupported systems
- Date of last successful restore test
- Time to restore a critical system
- % of endpoints covered by EDR/AV
- % of critical suppliers reviewed
- Overdue security actions from past reviews and pentests
Two of these deserve a special note. The backup line is not “we have backups”. Everyone has backups until they need to restore. The metric is “we restored the invoicing system in four hours during the last test”. And the admin-accounts line is a business number, not a technical one: if a 40-person company has 12 admin accounts, that is not flexibility, it is uncontrolled privilege.
Metrics that look busy but change nothing
Some numbers are worse than useless, because they make security feel active while the real risk stays exactly where it was. Be suspicious of these:
- Number of blocked attacks. Usually vendor marketing. More blocked attacks does not mean you are safer.
- Number of vulnerabilities found. Without severity, asset criticality, and a fix, “3,421 vulnerabilities” is a scary number that tells you nothing.
- Training completion rate on its own. People can finish the course and still approve a fake invoice.
- Number of policies written. A policy that does not change behaviour protects nothing.
- A tool’s “security score”. Useful as a signal, dangerous as a business truth.
If a metric goes up and your actual exposure does not go down, it is theatre. Track the ones that move risk, not the ones that photograph well.
How often to look
You do not need to review everything every week. Match the cadence to how fast things change.
- Monthly: MFA coverage, admin accounts, critical vulnerabilities, backup success, endpoint coverage.
- Quarterly: supplier risk, the security roadmap, overdue actions, incident readiness.
- Annually: policies, a tabletop exercise, the full security baseline, and next year’s budget priorities.
The review matters more than the tool. A ten-minute monthly look at five numbers beats a beautiful platform nobody opens.
The bottom line
Security metrics are not about a pretty dashboard. They exist to tell you one thing: whether the company is becoming harder to attack, easier to recover, and less dependent on luck. That baseline-and-review rhythm, set once and kept honest, is exactly the kind of thing a retained security advisor keeps running so it does not quietly lapse after the first quarter.
Where to start depends on what you are being measured against. If the goal is practical hardening, the CIS Controls baseline sets the numbers worth tracking; if the goal is to keep them tracked month after month, that is the Retained Security Partner engagement.
If you cannot name what improved, the next step is not another tool. It is a measurable baseline.
Sources
Found this useful?