# Cybersecurity Benchmarking: Why, Why Not, When and How

DevFeed: [Cybersecurity Benchmarking: Why, Why Not, When and How](<https://devfeed.tech/articles/cybersecurity-benchmarking-why-why-not-when-and-how-39487.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/cybersecurity-benchmarking-why-why-not-when-and-how>)

Author: Phil Venables

Published: 2026-09-05T15:27:39Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [performance](<https://devfeed.tech/tags/performance.md>), [risk](<https://devfeed.tech/tags/risk.md>)

## AI overview

The article argues that cybersecurity benchmarking is unhelpful when it focuses only on inputs such as budgets instead of outcomes such as control effectiveness. It recommends comparing leading indicators and examining how they influence lagging performance indicators, while noting that budget comparisons may not be meaningfully comparable.

## Source excerpt

tl;dr Benchmarking is a waste of time when focused solely on inputs (e.g. budgets) rather than outcomes (e.g. effectiveness of controls). The budget comparisons are never "apples for apples" and may often end up setting risk tolerance only marginally ahead of others who may be in a bad state to begin with. Instead, we need to decouple this and compare leading not lagging indicators of performance to show (i) how those leading indicators drive the lagging indicators in the right direction and...