ciso.diy

Free · one page · no email required

The Twelve

The security metrics every examiner, insurer and board asks for first — with the target that counts as good in 2026, the export to pull for each number, the formula, and the trap that makes it quietly wrong.

Start here at any maturity. These twelve are simultaneously the insurable baseline, the NYDFS certification core, the evidence behind an SEC Item 1C narrative, and what a new CISO should baseline in their first hundred days. Everything else phases in later.

Download the PDF

Two pages. Nothing to fill in.

What's on it

  1. 1 MFA enforced everywhere Enforced, not enabled — email, remote access, admin, backup console
  2. 2 EDR coverage Against the asset inventory, not against what the EDR console already knows
  3. 3 Restore tests A backup that has never been restored is a hypothesis
  4. 4 Immutable backups Immutable and offline, verified — not "the vendor says so"
  5. 5 Vulnerability SLA attainment Remediated inside your own stated window
  6. 6 KEV older than 7 days Known exploited, still open. The number a regulator starts with
  7. 7 Internet-facing exposures What an attacker can see without authenticating
  8. 8 Vendors assessed Of the tier that matters, with evidence, currently
  9. 9 Notifications on time Every regulatory clock met, measured from discovery
  10. 10 Incidents trended Direction over time beats a count in a quarter
  11. 11 Mean time to respond From detection to containment, with the denominator stated
  12. 12 Programme maturity trended One framework, scored the same way each time

Page two is the working half: for each metric, the system to export from, how to compute it, and the trap. The most common one is the denominator — 98% EDR coverage measured across the machines EDR already knows about is a tautology, not coverage. Denominators come from the inventory, never from the tool.

If you want the rest of it