Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & Training

Benchmarking is the missing link to cyber resilience

By James Hadley
people working together at conference table

Image via Unsplash

March 29, 2023

The magnitude of recent tech layoffs and budget cuts have hit business leaders hard. In addition to the human and business impacts, there are security ramifications as well, from disgruntled employees to understaffed cybersecurity teams. Couple these risks with cyber insurance agencies pulling back coverage, and organizations are faced with ever-increasing risks, with no end in sight. The only way to mitigate risk depends not only on employees being ready, but being able to prove that they’re ready.

This year, many security leaders will be expected to provide concrete evidence to their boards, customers and regulators that their security teams are truly prepared for potential cyber crises. This competency will be particularly important once the proposed SEC’s cybersecurity incident disclosure rules are implemented. 

Despite the demand for quantifiable evidence of cyber preparation, many of the world’s largest organizations don’t have the ability to determine individual and team capability. Without proper comparisons, it is impossible to know “what good looks like.” This lack of evidence results in organizations increasing cybersecurity spend without insight into whether technology and training investments are worth the price.

For an organization to achieve true cyber resilience, an understanding of skill level must be gained through benchmarking. This practice enables contextual measurement of team cyber skills and capability, offering visibility into strengths and weaknesses. Armed with data-driven insights, organizations can fill knowledge gaps and definitively prove cyber capability across the organization.

Benchmarking also enables visibility into industry-specific cybersecurity ability.  Armed with peer-to-peer performance metrics, leaders can make strategic investment decisions. 

For example, a major U.S. bank would want to know: 

  • How prepared am I for a cyberattack compared to my industry peers? What are my team’s strengths and weaknesses?
  • How do my people perform during crisis exercises?
  • Are skill performances changing over a six-month period?

By implementing targeted benchmarking, security leaders can gain data-driven answers to these questions and focus on filling gaps. Since benchmarking is ongoing, the assessment process can be repeated regularly, delivering real-time insight into workforce cyber resilience.  

Traditional cybersecurity training methods and certifications prioritize session completion over outcomes and don’t reflect adult learning patterns. When it comes to problem-solving and decision-making, capabilities degrade quickly. Maintaining competence in cybersecurity skills requires a regular exercising cadence, which is why annual crisis training is not enough to build lasting resilience.

Additionally, traditional training cannot be benchmarked, as the practice relies solely on a ticked-box mentality. To successfully benchmark cyber capability, organizations must reduce reliance on industry certifications, replacing traditional training methods with a focus on measurable, real-world skills. As the threat landscape accelerates, organizations must focus on building and upskilling human cyber capabilities. 

Since cyberattacks are a matter of when, not if, continuous real-world organizational exercising is crucial, as it allows them to assess, build and prove cyber resilience against a variety of threats. Continuous exercising shouldn’t be limited to any single group, team or individual. Security leaders need to apply continuous exercising across the entire organization. This includes crisis training for the board, C-level and management; technical training for security implementers and application developers and tailored hands-on labs for all levels of stakeholders. Individuals and teams improve by doing, not watching. By safely exposing the entire organization to realistic cyber scenarios, they can be better prepared to act in concert against potential real-world crises. 

To ensure engagement, exercises must be dynamic, with decisions resulting in differing outcomes. The more teams practice, the better their ability to predict the next issue. Through ongoing exercising, team ability to make decisions and respond will improve, ultimately building the people-centric resilience organizations need.

This approach to exercising also builds the cognitive agility needed to respond to unexpected threats. One byproduct of regular exercising is that teams are constantly “battle-tested” — seeking to not only succeed in attack prevention, but also to improve their offense in terms of proactivity and checking for vulnerabilities.

Benchmarking enables CISOs to develop a more targeted cyber resilience strategy. By measuring cyber defense and crisis management capabilities compared to industry benchmarks with data-backed evidence, security leaders are able to more effectively reduce risk and enable compliance across the organization. 

The quantitative data gleaned from continuous exercising is not only necessary for reporting, but it also provides a definitive answer to the question on every security leader’s mind: “How do you really know the team is ready in the face of a cybersecurity crisis?” 

KEYWORDS: cyber defense cyber resilience cyberattack employee training threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

James headshot

James Hadley is CEO and Founder of Immersive Labs.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Photograph of apartment complex patios

Enhancing Residential Building Security

2026 Women in Security

Security’s 2026 Women in Security

Northland Controls sponsored content

The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Trust

Building Public Trust in AI‑Enabled Security

Handcuffs and cash

Mass Kidnapping Increased 154% from 2020 to 2025

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • AI chip up close

    Human Oversight Is the Missing Link in GenAI Trust

    See More
  • Human brain formed from connections

    Stay a step ahead with the missing link in cybercrime defense: OSINT

    See More
  • Business meeting

    5 commitments CISOs can make to boost cyber resilience

    See More

Related Products

See More Products
  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

  • The Complete Guide to Physical Security

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing