Skip to content
Notifications
Clear all

Guide: Creating a report for management on ROI/attack surface reduction

2 Posts
2 Users
0 Reactions
11 Views
(@carlam)
Reputable Member
Joined: 2 months ago
Posts: 234
Topic starter   [#27757]

Alright folks, been deep in Cybereason for about six months now, and my CISO just asked for a "business value" report. We all know the drill—they want to see the ROI, not just that we blocked a bunch of stuff.

I found the key is to move beyond generic "threats prevented" and tie it directly to attack surface reduction and operational efficiency. Here's the framework I used, which management actually loved:

**Start with the Operational Metrics (The "How are we doing better?" section):**
* **Mean Time to Respond (MTTR):** This is gold. Compare your MTTR before and after Cybereason deployment. If you have a timeline from a recent incident, use that. Example: "Incident X took 4 hours to contain pre-Cybereason; similar incident Y took 45 minutes post-deployment."
* **Automation Rate:** How many alerts are now auto-remediated or require no analyst interaction? Cybereason's MalOp can give you a solid percentage here. This translates directly to analyst hours saved.
* **Alert Volume & Noise Reduction:** Show the reduction in low-fidelity alerts your SOC has to triage manually. Less noise = more focus on real threats.

**Then, Quantify the Attack Surface Reduction (The "Are we safer?" section):**
This is trickier but more impactful. Don't just say "we're more secure." Show it.
* **Critical Asset Coverage:** Percentage of your critical servers/endpoints now with EDR (vs. just legacy AV). This is a concrete risk reduction metric.
* **Vulnerability Exploitation Prevention:** Use the platform's data to show instances where it blocked an exploit attempt against a known, unpatched vulnerability. This directly ties to reducing the "patch gap" risk.
* **Lateral Movement Prevention:** Can you highlight a case where a MalOp graph showed an attempted lateral move that was blocked? This demonstrates protection beyond the initial endpoint.

**Finally, the Financial Angle (The "Why this is worth the money" section):**
Combine the operational metrics into a simple cost-savings model.
* Calculate the **labor cost savings** from reduced investigation time (MTTR improvement) and automated responses.
* If you have data, estimate the **potential cost avoided** from a prevented breach using one of the MalOp stories as a "what-if" scenario. There are industry averages for cost-per-incident you can reference cautiously.

My biggest tip? Use Cybereason's own dashboards and MalOp narratives for the concrete examples. A single, well-documented MalOp that shows the full attack chain and how it was stopped tells a more powerful story than a wall of numbers.

Has anyone else built a similar report? I'm curious how you quantified the "prevention" side, especially compared to something like CrowdStrike's benchmarks. Cheers, Carla


Benchmarking my way to better decisions


   
Quote
(@elliotv)
Reputable Member
Joined: 3 months ago
Posts: 380
 

That operational metrics framework is solid. I'd add a specific step to operationalize the automation rate metric for your financial calculations.

You can take the percentage of alerts auto-remediated and multiply it by your SOC analyst's fully burdened hourly rate. For example, if your team manually triaged 100 alerts per week before, and now 60% are auto-closed, that's 60 alerts. Estimate the average triage time per alert (e.g., 15 minutes), and you've got 15 analyst-hours saved weekly. That converts directly into a labor cost avoidance figure, which is the language finance understands.

Quantifying attack surface reduction is trickier. One method I've used is mapping prevented actions (like a blocked ransomware encryption process) to the potential cost of the business function it would have disrupted. This requires working with application owners to get downtime cost estimates per hour.


null


   
ReplyQuote