Twitter, RSS and Facebook logos

  Connect with Security Magazine!
     Follow us on Twitter and Facebook or subscribe to our newsletters or RSS feeds.

Leadership and Management

Performance Metrics: Why Businesses Want Them and Security Needs Them

Performance metrics are “critically important” to business leaders, says Greg Niehaus, Professor of Finance and Insurance for the Moore School of Business, University of South Carolina. “In my view it’s very important for business functions to have metrics that tie back to the objectives of the organization – that measure the impact on value and value creation.” If a function fails to develop and effectively communicate performance metrics, says Niehaus, “their contributions to the organization will likely be not appreciated, which, in down times, could lead to cutting of responsibilities or jobs and hurting the value of the organization.”

Yet according to George Campbell, author of the book Measures and Metrics in Corporate Security and a faculty member of the Security Executive Council, “there’s a general void within security of leaders who fully appreciate the need for and the application of metrics. Too many see their incident counts as metrics, not what the analysis of those counts is telling them about risk and program performance. Security management talks about performance, but it’s almost as if they don’t think of metrics as having anything to do with performance.”

If performance metrics are critically important to business leaders, and security leaders fail to recognize their importance, why aren’t business leaders demanding performance metrics from security in the same way they do for so many other business functions? Often it’s because management doesn’t view security as a valuable element of the business, says Campbell. “It’s part of the cost equation that sits on the side, and it’s not seen as part of the business or governance infrastructure.” In these cases, the lack of demand for metrics is simply the symptom of a much greater problem.

This ought to be a sobering possibility for many security leaders. If management lacks respect for security as a business function, the security leader can earn only limited influence, and security as an organization can accomplish only limited success. Creating performance metrics isn’t a silver bullet solution, but security leaders who undertake the development of meaningful metrics can enhance management’s perception of the value of security, while adding to that value by building a greater understanding of the security function and the business.

Some forward-thinking security leaders who have risen to the challenge of metrics development are sharing their experiences to assist others in their endeavors. Dave Komendat, VP and Chief Security Officer of The Boeing Company, and Pam Dost, his Senior Manager of Strategy Development, viewed the creation of their metrics suite as an opportunity to show the value security brings to the company.

Komendat is the winner of a CSO Compass Award and one of Securitymagazine’s Most Influential People in Security for 2011; his security organization has been recognized internally and externally as a value enhancer and a business enabler. But metrics would provide another, more succinct way to show management how security contributes. “When you have limited time with the most senior leaders in the company, metrics provide a way to communicate value simply and efficiently. It’s very meaningful for them to see fact-based data that shows the value of the cost avoidance, quality improvement and risk mitigation that your organization is bringing to the company,” Komendat says.

Pam Dost, who heads up the metrics initiative at Boeing, remarks that the education that security managers are getting from the process has been an unexpected but notable side benefit. “We invested a significant amount of time up front to educate the (security) leaders on why we need to provide metrics and how they would increase the credibility of our organization,” she says. “When we started this journey, our (security) leaders were very aware of their functional responsibilities and collecting data. But they hadn’t had a lot of exposure to the corporate interest level or how to leverage the data to tell a higher value story about risk and overall benefit. Since we launched the metrics initiative, the passion and interest in understanding the bigger picture of business has inspired our leaders to look for additional high value metric examples we can share with our corporate leaders. I think one of the biggest advantages is how developing this broader view – exposing these risks in a different way – broadens their skills and helps them become better leaders.”

Nihaus, Komendat and Campbell are collaborating to develop a course on developing and communicating security performance metrics for the Security Executive Council’s Next Generation Security Leader curriculum, set to launch in January. To learn more or to register, visit www.securityexecutivecouncil.com/nextgen.   

Marleah Blades is senior editor for the Security Executive Council, an innovative problem-solving research and services organization. The Council works with Tier 1 Security Leaders™ to reduce risk and add to corporate profitability in the process. To learn about becoming involved, e-mail contact@secleader.com or visit www.securityexecutivecouncil.com/sm. You can also follow the Council on Facebook and Twitter.

Recent Articles by Marleah Blades

You must register or login in order to post comments.

Multimedia

Videos

Image Galleries

Stanley Customer Appreciation Event at ASIS 2011

Customers enjoyed the annual Stanley customer appreciation event during ASIS 2011 in Orlando.

Podcasts

The New Age of Video Surveillance
In this podcast, Bill Lawrence, director of Service Solutions and Platforms for ADT Security Services, explains the growing interest in video surveillance by both government agencies as well as businesses of every stripe. He discusses what any organization should consider before investing heavily in the technology. Lawrence is a 25-year veteran of both the information technology and physical security industries, with extensive experience in network video surveillance and physical security convergence.
More Podcasts

Your Time

On a daily basis, how much work time do you estimate that you spend addressing an emergency or crisis within your organization?
See Poll Results Poll Archive

THE SECURITY STORE

comptiahighriseproductphoto
CompTIA Security+ Certification Study Guide
CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.
More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.

Vertical Sector Focus: Critical Infrastructures

criticalhomepagethumbFrom terrorism to vandalism, it’s preparedness, response, training and partnerships. Learn about some of the critical security issues facing this sector.

Visit the Critical Infrastructure page to read more.  

STAY CONNECTED

facebooklogo twitterlogo  linkedinlogo  YouTube icon