Skip to main content

Understand the difference between the efficiency and the performance of a security measure

Discover the difference between the efficiency and the operational performance of a security measure, and how their combination determines their overall score.

Updated over 3 months ago

The security measures implemented in your security base are evaluated using a performance score.

This score is the result of two components: the efficiency and the operational performance of the measure.

Efficiency

Consider the efficiency of a security measure as your level of confidence in its proper current functioning.

  • If you believe it is working at its full potential, you can set it to 100%.

  • If you identify areas for improvement, you can create one or several improvement actions.

    • For each action, you indicate by how much it could increase the measure’s efficiency (for example, +25%).

    • When an improvement action is created, the current efficiency is automatically reduced by this percentage
      (100% − 25% = 75%).

💡 If several actions are in progress, their impacts are cumulative
(for example, two actions of 20% and 15% would lower the efficiency to 65%).

  • Each time an action is completed, the efficiency recovers the points from that action.

Operational Performance

Operational performance evaluates whether the security measure continues to work properly over time, based on regular checks.

These checks can be of two types:

  • Recurring tasks: to achieve a score of 100, all scheduled tasks must be completed.
    The score depends on the number of planned tasks and the number actually completed.

  • Performance indicators: you are assessed on measurable results, for example the percentage of people who do not click on a phishing campaign.
    The closer the result is to 100%, the more it shows that your security measure (e.g. an awareness program) is performing well.

🔎 A security measure can be monitored using one or more recurring tasks and/or performance indicators.

In Summary

  • Efficiency depends on whether improvement actions are currently in progress.

  • Operational performance reflects the results of your recurring checks.

The overall score of a security measure is obtained by multiplying these two dimensions.

🔎 Security measures that are still being implemented or not yet implemented do not have a performance score yet.

Did this answer your question?