• United States



by Robert Lemos

Security pros launch cybersecurity index

May 09, 20113 mins
Application SecurityCloud SecurityCybercrime

The index will track the overall sentiment of a group of cybersecurity experts to offer a measure of cyber risk.

Are attacks up, spending on network defenses down, or national hacking on the rise? The Index of Cybersecurity could help indicate the general trend in the risks to corporate networks and information in the future.

The index, launched by two security professionals, is a survey that attempts to gauge the state of cybersecurity by measuring the overall sentiment of operational experts. Much like the consumer confidence index that measures U.S. citizen’s optimism of their economic future, the index focuses on experts’ overall perception of current threats and defenses.

The index is an experiment that could prove to be a useful way to gauge the overall security situation online, says Dan Geer, the co-creator of the index and the chief security officer of In-Q-Tel, the investment arm of the Central Intelligence Agency. While Geer has attempted to create other indices based on measures of threat, good data was not always available, he said.

Also see: Security metric techniques: How to answer the ‘so what?’

“It is not like we are overwhelmed with useful numbers; we are short on them,” he says. His conclusion: Focus on the data that you know you can get.

“Maybe we shouldn’t be trying to measure the concrete, but trying to measure the opinion of people who know something,” he says. “Because it may well be that the opinion of people that know something may have more coherence than anything we know how to measure, or have the permission to measure, on a wide scale.”

The cybersecurity index measures the outlook of 300 or so security operations managers — from chief risk officers and chief security information officers to academicians and security firm chief scientists. The index measures their responses over time. Questions vary from whether certain threats — such as malware, insider threats, or industrial espionage — have become worse to whether information sharing and defenses have improved. Each respondent answers on a five-point scale: falling fast, falling, static, rising, or rising fast.

Geer and co-creator Mukul Pareek, a risk professional who asked that his company not be identified, believe that the cybersecurity risk index could have practical uses. Cyber risk insurers could use the metric as a way to hedge their risks, for example.

“This is something that we do not have an answer to yet,” Pakeet says. “But it is clearly at the top of our minds, we are thinking about it. In the coming months, we should come up with some ideas” about how to use the index.

In April, the index rose to 1,021.6, up 2 percent from the March baseline of 1,000, indicating that experts’ perception of the cybersecurity situation has worsened. The fastest rising threats are malware, nation-state-sponsored attacks and risks from suppliers and service providers. The most significant cybersecurity improvement comes from the perception that information sharing is getting better.