This course teaches you how to measure cybersecurity. You will learn how to turn security work into numbers that everyone can understand. You will learn about metrics, key performance indicators (KPIs), dashboards, and reports. You will discover how companies know if their security is working. You will also learn how to use numbers to make better security decisions. No prior knowledge of metrics is needed. We use simple words, fun stories, and real examples from Nigeria and around the world. By the end, you will be a Cybersecurity Metrics Expert.
The course is divided into six modules. Each module can be taught over one to two weeks, depending on pace. Total time: about 10 to 12 weeks.
| Module | Title | Main Focus |
|---|---|---|
| Module One | Introduction to Cybersecurity Metrics | What metrics are, why they matter, and basic terms. |
| Module Two | Types of Cybersecurity Metrics | Technical, operational, and strategic metrics. |
| Module Three | Key Performance Indicators (KPIs) | What KPIs are, how to choose them, and how to use them. |
| Module Four | Collecting and Analyzing Security Data | Data sources, tools, and analysis methods. |
| Module Five | Dashboards and Reporting | Building dashboards and reporting to different audiences. |
| Module Six | Using Metrics to Improve Security | Making decisions, setting goals, and continuous improvement. |
At the end of all six modules, students who complete the activities and final project will receive a Certificate of Completion for "Cybersecurity Metrics Expert."
This course takes you from knowing nothing about cybersecurity metrics to understanding how to measure, report, and improve security using numbers. You start with the basics of metrics, learn about different types, explore KPIs, collect and analyze data, build dashboards, and use metrics to make decisions. Each module builds on the last. By the end, you will be a confident Cybersecurity Metrics Expert.
START
|
V
Module 1: Introduction
|
V
Module 2: Types of Metrics
|
V
Module 3: KPIs
|
V
Module 4: Data Collection
|
V
Module 5: Dashboards
|
V
Module 6: Improve Security
|
V
CERTIFICATE ๐
Welcome to Module One of Cybersecurity Metrics Expert! Have you ever counted how many goals your favorite footballer scored in a season? Or how many steps you took in a day using a fitness app? If you have, then you already understand the basic idea of metrics. Metrics are simply numbers that help us understand something.
Now think about cybersecurity. How do we know if our computers are safe? How do we know if we are doing a good job protecting our information? The answer is metrics. Cybersecurity metrics are numbers that tell us how safe we are, how well we are doing, and where we need to improve.
In this module, we will start from the very beginning. We will learn what metrics are, why they matter, and how they help us in cybersecurity. We will use simple words, fun stories, and examples you see every day in Nigeria and around the world. You do not need to know anything about computers or math to understand this. Just bring your curiosity and your thinking cap. Let us begin!
By the end of this module, you will be able to:
Once upon a time in Enugu, Nigeria, there lived a girl named Ada. Ada loved football. She played every day after school and watched every match on television. Her favorite team was the Super Eagles of Nigeria.
One Saturday, Ada went to watch a local match with her father. The stadium had a big scoreboard. Every time a team scored, the number on the scoreboard changed. Ada could see exactly how many goals each team had. She could also see the time. At the end of the match, the scoreboard showed the final score. Ada's team won 3 to 1.
Ada's father asked her, "Ada, how do you know which team won?" Ada laughed. "The scoreboard, Daddy! It shows the goals." Her father smiled and said, "Yes. The scoreboard gives us numbers. Those numbers tell us the story of the match. Without the scoreboard, we would not know who won or lost."
Ada thought about this. Numbers tell a story. They help us understand what is happening. The next day at school, her teacher asked the class, "How do we know if our computers are safe?" Ada raised her hand. "We need a scoreboard for security!" she said. The teacher was impressed. "Exactly, Ada. That scoreboard is called cybersecurity metrics."
And that is what we will learn about in this module. Cybersecurity metrics are like a scoreboard for safety. They tell us how we are doing and where we need to improve. Let us dive in!
Definition: A metric is a number that measures something. It helps us understand how much, how many, or how well.
Why it is important: Without metrics, we are guessing. With metrics, we know for sure.
Simple explanation: Think of a metric as a score. In a football match, the score is a metric. In school, your test score is a metric. In cybersecurity, the number of viruses blocked is a metric.
Real-life example: Your height in centimeters is a metric. It tells you how tall you are.
School example: Your exam score is a metric. It tells you how well you did.
Home example: The number of eggs in your fridge is a metric. It tells you how many you have.
Nigerian example: The number of goals the Super Eagles scored in a match is a metric.
METRIC
|
A number that measures something
|
+----+----+----+
| | | |
Height Score Goals Viruses
blocked
Mini summary: A metric is a number that measures something. It helps us understand.
Definition: Cybersecurity metrics are numbers that measure how safe our computers, networks, and information are.
Why it is important: They tell us if our security is working or if we need to do more.
Simple explanation: Think of cybersecurity metrics as a health check for your computer. Just like a doctor checks your temperature and blood pressure, cybersecurity metrics check the health of your digital life.
Real-life example: The number of phishing emails blocked by your email provider is a cybersecurity metric.
School example: The number of students who use strong passwords is a cybersecurity metric for your school.
Home example: The number of devices connected to your Wi-Fi with a password is a cybersecurity metric.
Nigerian example: The number of fraud attempts blocked by a Nigerian bank is a cybersecurity metric.
CYBERSECURITY METRICS
|
Numbers that measure safety
|
+----+----+----+
| | | |
Phishing Viruses Strong
blocked blocked passwords
Mini summary: Cybersecurity metrics are numbers that tell us how safe we are online.
Definition: We need cybersecurity metrics to know if our security is working and where to improve.
Why it is important: Without metrics, we cannot tell if we are safe or if we are wasting time and money.
Simple explanation: Imagine playing a football match without a scoreboard. You would not know who is winning. Cybersecurity metrics are the scoreboard for security.
Real-life example: A bank uses metrics to see how many fraud attempts are blocked each day.
School example: A school uses metrics to see how many students have completed cybersecurity training.
Home example: You use metrics to see how many devices are protected with antivirus.
Nigerian example: Telecom companies use metrics to see how many scam calls are blocked.
WHY METRICS?
|
+----+----+
| |
Know if Know where
safe to improve
| |
Scoreboard Health check
Mini summary: We need metrics to know if we are safe and where to improve.
Definition: A measure is a single number. A metric is a measure with context. An indicator is a metric that tells us something important.
Why it is important: Knowing the difference helps us use the right words.
Simple explanation: The number 5 is a measure. "5 viruses blocked today" is a metric. "We blocked 5 viruses, which is more than yesterday" is an indicator that something might be wrong.
Real-life example: Your height (170 cm) is a measure. Your growth rate (2 cm this year) is a metric.
School example: Your score (80%) is a measure. Your improvement (from 70% to 80%) is a metric.
Home example: The number of eggs (6) is a measure. The number of eggs used per week (6 eggs per week) is a metric.
Nigerian example: The number of scam calls (1,000) is a measure. The increase in scam calls (up 20%) is an indicator.
MEASURE vs METRIC vs INDICATOR
|
+----+----+----+
| | | |
Measure Metric Indicator
| | |
Single Measure Metric
number + context + meaning
Mini summary: A measure is a number. A metric is a number with context. An indicator tells us something important.
Definition: The language of numbers in security means using numbers to describe security.
Why it is important: Numbers are easier to understand than words. They help everyone agree.
Simple explanation: Instead of saying "We are safe," we say "We blocked 95% of attacks." Numbers tell the truth.
Real-life example: A company says "We had 10 security incidents this month." That is the language of numbers.
School example: A school says "80% of students use strong passwords." That is the language of numbers.
Home example: Your family says "We have 5 devices protected with antivirus." That is the language of numbers.
Nigerian example: A bank says "We blocked 1,000 fraud attempts last month." That is the language of numbers.
LANGUAGE OF NUMBERS
|
+----+----+
| |
Words Numbers
| |
"We are "We blocked
safe" 95% of attacks"
Mini summary: Numbers are the language of security. They help us understand and agree.
Definition: Many different people use cybersecurity metrics.
Why it is important: Different people need different metrics.
Simple explanation: Technical people need technical metrics. Managers need summary metrics. Everyone needs to understand.
Real-life example: A security analyst uses metrics to find attacks. A CEO uses metrics to decide budgets.
School example: A teacher uses metrics to see if students understand cybersecurity. A principal uses metrics to see if the school is safe.
Home example: Parents use metrics to see if their children are safe online.
Nigerian example: Bank managers use metrics to see if customer money is safe. Government uses metrics to see if national systems are safe.
WHO USES METRICS?
|
+----+----+----+----+
| | | | |
Analysts Managers CEO Parents Teachers
| | | | |
Find Decide Plan Check Teach
attacks budgets safety safety
Mini summary: Many people use cybersecurity metrics. Each has different needs.
Definition: Common mistakes are errors people make when using metrics.
Why it is important: Knowing the mistakes helps you avoid them.
Simple explanation: Do not use too many metrics. Do not use metrics that do not matter. Do not ignore what the metrics tell you.
Real-life example: A company tracks 100 metrics but only uses 3. That is a mistake.
School example: A school tracks test scores but not student safety. That is a mistake.
Home example: A family tracks how many devices they have but not how many are protected. That is a mistake.
Nigerian example: A bank tracks how many accounts it has but not how many fraud attempts it blocks. That is a mistake.
COMMON MISTAKES
|
+----+----+----+
| | | |
Too Wrong Ignore
many metrics results
metrics
Mini summary: Avoid common mistakes. Use the right metrics and act on them.
Definition: A Cybersecurity Metrics Expert is a person who measures, analyzes, and reports on cybersecurity.
Why it is important: They help companies understand their security and make good decisions.
Simple explanation: They are like a sports commentator. They watch the game, keep score, and explain what is happening.
Real-life example: A bank hires a Cybersecurity Metrics Expert to track fraud attempts and report to management.
School example: A school might have a teacher who tracks cybersecurity metrics for the school.
Home example: You can be the Cybersecurity Metrics Expert for your family.
Nigerian example: Nigerian banks, telecoms, and government agencies need Cybersecurity Metrics Experts.
CYBERSECURITY METRICS EXPERT
|
+----+----+
| |
Measure Report
security findings
| |
Collect Explain
data to others
Mini summary: A Cybersecurity Metrics Expert measures, analyzes, and reports on security.
Definition: Metrics matter for everyone, not just experts.
Why it is important: Everyone uses the internet. Everyone needs to be safe.
Simple explanation: Even at home, you can use metrics. Count how many devices have strong passwords. Count how many phishing emails you avoided.
Real-life example: You can track how many times you update your apps each month.
School example: You can track how many classmates use strong passwords.
Home example: You can track how many family members have antivirus.
Nigerian example: You can track how many scam messages you avoided.
METRICS FOR EVERYONE
|
+----+----+
| |
Home School
| |
Devices Classmates
protected using strong
passwords
Mini summary: Metrics matter for everyone. You can start using them today.
Definition: Turning security into numbers means taking security activities and measuring them.
Why it is important: Numbers are easier to understand and compare.
Simple explanation: Instead of saying "We did security training," say "We trained 50 people in security." The number tells the story.
Real-life example: A company says "We blocked 1,000 viruses this month." That is turning security into numbers.
School example: A school says "80% of students completed cybersecurity training." That is turning security into numbers.
Home example: Your family says "We have 5 devices with antivirus." That is turning security into numbers.
Nigerian example: A bank says "We blocked 500 fraud attempts this week." That is turning security into numbers.
TURNING SECURITY INTO NUMBERS
|
Security activity
|
+----+----+
| |
Words Numbers
| |
"We did "We trained
training" 50 people"
Mini summary: Turn security into numbers. It makes it easier to understand.
Definition: The scoreboard of security is a way to see how safe you are at a glance.
Why it is important: It helps you quickly see if you are winning or losing.
Simple explanation: Think of a dashboard in a car. It shows speed, fuel, and temperature. A security scoreboard shows how many threats were blocked, how many passwords are strong, and more.
Real-life example: A bank's security dashboard shows fraud attempts blocked, system uptime, and more.
School example: A school's security dashboard shows how many students completed training.
Home example: Your family's security dashboard shows how many devices are protected.
Nigerian example: A telecom company's dashboard shows how many scam calls were blocked.
SECURITY SCOREBOARD
|
+----+----+----+
| | | |
Threats Strong Updates
blocked passwords done
| | |
100 80% 95%
Mini summary: The security scoreboard shows how safe you are at a glance.
Definition: Metrics help us ask better questions about security.
Why it is important: Good questions lead to good answers and better security.
Simple explanation: Instead of asking "Are we safe?", ask "How many attacks did we block this week?" The number helps you ask the next question.
Real-life example: A bank asks "Why did fraud attempts increase this month?"
School example: A school asks "Why are only 60% of students using strong passwords?"
Home example: Your family asks "Why is one device not protected?"
Nigerian example: A telecom asks "Why did scam calls increase this week?"
METRICS HELP US ASK QUESTIONS
|
"Are we safe?"
|
Better question:
"How many attacks did we block?"
|
Even better:
"Why did attacks increase?"
Mini summary: Metrics help us ask better questions about security.
Definition: Metrics help build trust between people and organizations.
Why it is important: When a company shares metrics, customers trust them more.
Simple explanation: If a bank says "We blocked 1,000 fraud attempts," customers feel safer.
Real-life example: A company shares its security metrics in a report to show it is safe.
School example: A school shares how many students completed cybersecurity training.
Home example: Your family shares how many devices are protected.
Nigerian example: A bank shares how many fraud attempts it blocked to build customer trust.
METRICS BUILD TRUST
|
Company shares metrics
|
Customers feel safer
|
Trust grows
Mini summary: Metrics build trust. Sharing them shows you care about safety.
Definition: Metrics help companies decide how to spend money on security.
Why it is important: Security costs money. Metrics help spend it wisely.
Simple explanation: If metrics show many phishing attacks, spend more on email security.
Real-life example: A company spends more on antivirus because metrics show many viruses.
School example: A school spends more on training because metrics show students need it.
Home example: Your family buys antivirus because metrics show a device is unprotected.
Nigerian example: A bank invests in fraud detection because metrics show increased fraud attempts.
METRICS AND MONEY
|
Metrics show a problem
|
Company spends money to fix it
|
Security improves
Mini summary: Metrics help companies spend money on the right security.
Definition: Getting started means taking the first steps to use metrics.
Why it is important: Everyone starts somewhere. You can start today.
Simple explanation: Start small. Count one thing. For example, count how many devices in your home have strong passwords. Then count another thing.
Real-life example: A company starts by tracking one metric, like number of phishing emails blocked.
School example: A school starts by tracking how many students use strong passwords.
Home example: Your family starts by counting how many devices have antivirus.
Nigerian example: A small business starts by counting how many scam messages it avoids each week.
GETTING STARTED
|
Start small
|
Count one thing
|
Count another
|
Keep going
Mini summary: Start small. Count one thing. You are now using cybersecurity metrics.
| Word | Simple Definition |
|---|---|
| Metric | A number that measures something. |
| Measure | A single number. |
| Indicator | A metric that tells us something important. |
| Cybersecurity Metrics | Numbers that measure how safe our computers and information are. |
| Scoreboard | A way to see how you are doing at a glance. |
| Dashboard | A visual display of metrics. |
| Cybersecurity Metrics Expert | A person who measures, analyzes, and reports on cybersecurity. |
| Data | Facts and numbers collected for analysis. |
| Analysis | Looking at data to find patterns and meaning. |
| Report | A document that explains metrics to others. |
In 2021, a Nigerian bank started tracking how many phishing emails its customers reported. The metric showed that only 10% of customers reported suspicious emails. The bank started a training program. Six months later, the metric showed 60% of customers reported suspicious emails. The bank was safer because it used metrics. In another case, a school tracked how many students used strong passwords. The metric was 30%. After a cybersecurity week, it rose to 80%. These are real examples of how metrics improve security.
METRIC
|
A number that measures something
|
+----+----+----+
| | | |
Height Score Goals Viruses
blocked
Collect data
|
Turn into metrics
|
Analyze metrics
|
Find problems
|
Fix problems
|
Measure again
|
Security improves
1990s - First security metrics 2000s - KPIs become common 2010s - Dashboards and SIEM 2020s - AI and metrics Future - Predictive metrics
| Term | Definition | Example |
|---|---|---|
| Measure | A single number. | 5 |
| Metric | A number with context. | 5 viruses blocked today |
| Indicator | A metric that tells us something important. | 5 viruses blocked, up from 2 yesterday |
| Person | Why They Use Metrics |
|---|---|
| Security Analyst | To find and stop attacks. |
| Manager | To decide budgets and priorities. |
| CEO | To understand overall risk. |
| Parent | To check family safety online. |
| Teacher | To see if students are learning. |
| Metric | What It Measures |
|---|---|
| Number of phishing emails blocked | Email security |
| Number of viruses detected | Antivirus effectiveness |
| Percentage of strong passwords | Password security |
| Time to fix a security problem | Response speed |
| Number of trained employees | Security awareness |
| Common Mistake | Best Practice |
|---|---|
| Too many metrics | Focus on a few important ones |
| No context | Add context to every metric |
| Ignoring results | Act on what metrics tell you |
| Not sharing | Share with the right people |
| Never updating | Review and update regularly |
Each lesson above ended with a mini summary. Here they are again in one place:
In this module, you learned what cybersecurity metrics are and why they matter. You learned that a metric is a number that measures something. You learned that cybersecurity metrics measure how safe we are online. You learned the difference between measures, metrics, and indicators. You learned who uses metrics and why. You learned about common mistakes and best practices. You learned about the Cybersecurity Metrics Expert role. You learned how to turn security into numbers and how to start using metrics at home. Remember: metrics are the scoreboard of security. They help us know if we are safe and where to improve. You are now ready to learn more about cybersecurity metrics.
Match the word to its definition.
| Word | Definition |
|---|---|
| 1. Metric | A. A number with context |
| 2. Measure | B. A person who measures and reports security |
| 3. Indicator | C. A single number |
| 4. Cybersecurity Metrics Expert | D. A metric that tells us something important |
| 5. Dashboard | E. A visual display of metrics |
Answers: 1-A, 2-C, 3-D, 4-B, 5-E
In groups of four, create a "Security Scoreboard" for your classroom. Include at least five metrics and one ASCII diagram. Present to the class. Make it colorful and fun.
Write a short story about a character who used metrics to solve a security problem. Use at least five vocabulary words from this module. Share your story with the class.
Create a "Home Security Metrics Tracker." List five things to measure at home, like number of devices with strong passwords. Create a simple table to track them for one week. Write down what you learn.
With an adult, count how many devices in your home have strong passwords. Count how many have antivirus. Count how many are updated. Write down the numbers. Set a goal to improve one number next week.
In Module Two, we will learn about "Types of Cybersecurity Metrics." We will explore technical, operational, and strategic metrics. We will learn about leading and lagging indicators. We will see examples from Nigerian banks and telecoms. To prepare, think about the different types of numbers you see every day. Are they technical, like speed? Are they operational, like time? Are they strategic, like goals? See you in Module Two!
Welcome to Module Two of your journey to becoming a Cyber Security Metrics Expert!
In Module One, you learned what cyber security is and why it matters. You learned that cyber security is like protecting a house from bad people who want to steal things or cause problems.
Now, in Module Two, you are going to learn about metrics.
What is a metric?
A metric is a way to measure something. It is a number or a value that tells you how well something is doing.
Think about your school report card. Your teacher gives you scores in different subjects. Those scores are metrics. They tell you and your parents how well you are doing in school.
In cyber security, metrics help us understand how safe a computer system is. They help us know if we are winning or losing against cyber criminals. They help us make smart decisions about how to protect our computers, phones, and networks.
Imagine you are playing a football match. You want to know how many goals your team has scored and how many goals the other team has scored. The scoreboard is a metric. It tells you who is winning.
Cyber security metrics are like a scoreboard for computer safety. They tell us:
In this module, you will learn all about cyber security metrics. You will learn why they are important, how to understand them, and how to use them to make good decisions.
By the end of this module, you will be able to look at a cyber security report and understand what it is telling you. You will be able to ask smart questions. You will be able to help your school, your family, or even a company understand how safe their computers are.
Let us begin this exciting journey together!
After completing this module, you will be able to:
Once upon a time, in the bustling city of Lagos, Nigeria, there lived a young girl named Ada. Ada loved football. She played for her school team, the Lagos Lions.
One Saturday morning, Ada and her team were getting ready for a big match against the Abuja Eagles. Ada's coach, Coach Bello, called the team together.
"Listen up, Lions!" Coach Bello said. "Today, we need to play smart. We need to know how we are doing at every moment."
Ada raised her hand. "Coach, how do we know how we are doing?"
Coach Bello smiled. "Great question, Ada! We use metrics. A metric is a way to measure something. In football, our metrics are things like:
These numbers tell us how well we are playing. They help us decide what to do next. If we are losing, we might need to attack more. If we are winning, we might need to defend more."
Ada nodded. She understood. The scoreboard was a metric. The coach's notes were metrics. Everything was about measuring.
During the match, Ada kept looking at the scoreboard. At halftime, the score was Lagos Lions 2, Abuja Eagles 1. Ada's team was winning!
But Coach Bello looked at more than just the score. He looked at his notebook. He had written down other metrics:
"Ada," Coach Bello said, "we are winning, but look at our lost balls. We lost the ball 10 times. That is too many. We need to be more careful with our passes."
Ada understood. The score was good, but other metrics showed that the team could do better.
In the second half, the Lions played more carefully. They lost the ball only 3 times. They scored 2 more goals. The final score was Lagos Lions 4, Abuja Eagles 1.
After the match, Ada thought about what she had learned. Metrics were not just numbers. They told a story. They helped you understand what was happening and what to do next.
That night, Ada went home and thought about cyber security. She wondered, "If metrics can help a football team win, can they help keep computers safe?"
The answer is yes! And that is exactly what you will learn in this module.
Cyber security metrics are numbers or measurements that tell us how safe our computer systems are. They help us understand how well we are protecting our computers, phones, networks, and data from cyber criminals.
Imagine you are baking a cake. You want to know if the cake is good. You taste it. You look at it. You check if it is burnt. Those are all ways of measuring the cake. Cyber security metrics are like tasting and checking your computer systems to see if they are safe.
Without metrics, we are just guessing. We might think our computers are safe when they are not. We might spend money on the wrong things. Metrics help us make smart choices.
A metric is just a number that tells you something. For example:
All of these are cyber security metrics.
Think about a hospital. The hospital measures how many patients get better. They measure how many patients get sick again. They measure how long patients wait. These metrics help the hospital improve.
In the same way, a bank measures how many fake emails their customers report. They measure how many times someone tries to steal money online. These are cyber security metrics.
Your school might measure how many students use the school computers safely. They might measure how many students clicked on a fake email. These are cyber security metrics for your school.
At home, you might measure how many times you updated your phone. You might measure how many suspicious messages you received. These are simple cyber security metrics for your family.
In Nigeria, many people use mobile phones for banking. A Nigerian bank might measure how many customers received fake "your account has been blocked" messages. They might measure how many customers reported those messages. These metrics help the bank protect their customers.
Cyber Security Metrics
|
V
+-------------------+
| How many attacks? |
+-------------------+
|
V
+-------------------+
| How many stopped? |
+-------------------+
|
V
+-------------------+
| How many got in? |
+-------------------+
|
V
+-------------------+
| How fast fixed? |
+-------------------+
|
V
+-------------------+
| Are we safer now? |
+-------------------+
Cyber security metrics are numbers that tell us how safe our computer systems are. They help us make smart decisions. They are like a scoreboard for computer safety.
Metrics help us understand the health of our cyber security. They turn complicated information into simple numbers that anyone can understand.
Imagine you are driving a car. You have a dashboard with a speedometer, a fuel gauge, and a temperature gauge. These are metrics. They tell you how the car is doing. Without them, you would not know if you are running out of fuel or going too fast.
Cyber security metrics are like the dashboard of a computer system. They tell us if the system is healthy or if there is a problem.
We need metrics for three main reasons:
A school wants to know if their students are safe online. They measure how many students have completed cyber security training. If only 10 out of 100 students completed the training, they know they have a problem. They can then encourage more students to complete the training.
Your school library wants to know how many books are being borrowed. They count the books. That is a metric. In cyber security, your school might count how many computers have antivirus software. That is also a metric.
At home, your parents might want to know how many hours you spend on your phone. They measure it. That is a metric. In cyber security, you might measure how many times you change your password. That is also a metric.
A Nigerian company might want to know how many fake emails their workers received. They measure it. If the number is high, they know they need to train their workers to recognize fake emails.
Why We Need Metrics
|
V
+-------------------+
| To Know Truth |
+-------------------+
|
V
+-------------------+
| To Make Decisions |
+-------------------+
|
V
+-------------------+
| To Show Progress |
+-------------------+
|
V
+-------------------+
| To Stay Safe |
+-------------------+
We need metrics to know if we are safe, to make good decisions, and to show that we are improving. Metrics are like a health check for our computers.
There are many different types of cyber security metrics. Each type measures something different.
Just like a doctor checks your height, weight, and blood pressure, cyber security experts check different metrics to get a full picture of security health.
Here are the main types of cyber security metrics:
| Type of Metric | What It Measures | Example |
|---|---|---|
| Technical Metrics | How well the computers and software are working | Number of viruses blocked |
| Operational Metrics | How well the security team is working | Time taken to fix a problem |
| Human Metrics | How well people are following security rules | Number of people who use strong passwords |
| Strategic Metrics | How well the whole organization is doing | Money saved by stopping attacks |
A bank uses technical metrics to see how many fake emails were blocked. They use operational metrics to see how fast their team responded to an attack. They use human metrics to see how many workers completed security training. They use strategic metrics to see if their security spending is helping.
Your school might use technical metrics to count how many computers have updated software. They might use human metrics to count how many students know not to share their passwords.
At home, you might use technical metrics to count how many devices have antivirus. You might use human metrics to count how many family members know not to click on strange links.
A Nigerian e-commerce company might use technical metrics to see how many fake orders were blocked. They might use operational metrics to see how fast they responded to a data breach.
Types of Cyber Security Metrics
|
V
+---------------------------+
| Technical Metrics |
| (Computers & Software) |
+---------------------------+
|
V
+---------------------------+
| Operational Metrics |
| (Security Team) |
+---------------------------+
|
V
+---------------------------+
| Human Metrics |
| (People) |
+---------------------------+
|
V
+---------------------------+
| Strategic Metrics |
| (Whole Organization) |
+---------------------------+
There are four main types of cyber security metrics: technical, operational, human, and strategic. Each type measures a different part of security.
Lagging indicators are metrics that tell you what already happened. They look at the past.
Leading indicators are metrics that help you predict what will happen in the future. They look at the present to predict the future.
If you only look at lagging indicators, you are always reacting to problems after they happen. If you use leading indicators, you can prevent problems before they happen.
Think about your health. If you weigh yourself and see you gained weight, that is a lagging indicator. It tells you what already happened. If you count how many vegetables you eat each day, that is a leading indicator. It helps predict your future weight.
In cyber security, a lagging indicator might be "number of successful attacks last month." A leading indicator might be "number of employees who completed security training this month."
A lagging indicator in school is your exam score. A leading indicator is how many hours you studied each day.
A lagging indicator at home is how many times your phone broke. A leading indicator is how many times you used a phone case.
A Nigerian bank might use "number of customers who lost money to fraud last month" as a lagging indicator. They might use "number of customers who attended fraud awareness training" as a leading indicator.
Lagging Indicator Leading Indicator
| |
V V
+---------------+ +---------------+
| Looks at | | Looks at |
| the Past | | the Present |
+---------------+ +---------------+
| |
V V
+---------------+ +---------------+
| Tells you | | Predicts |
| what happened| | what may |
| | | happen |
+---------------+ +---------------+
| |
V V
+---------------+ +---------------+
| Example: | | Example: |
| Attacks last | | Training |
| month | | completed |
+---------------+ +---------------+
Lagging indicators look at the past. Leading indicators help predict the future. Both are important, but leading indicators help you prevent problems.
A Key Performance Indicator (KPI) is a special metric that shows how well you are doing at something important. It is a number that tells you if you are winning or losing.
There are many things you can measure. But some things are more important than others. KPIs help you focus on the most important things.
Imagine you are playing a video game. Your KPI might be your score. If your score is high, you are doing well. If your score is low, you need to improve.
In cyber security, a KPI might be "percentage of computers with updated antivirus." If this number is high, your security is good. If it is low, you have a problem.
A restaurant might have a KPI of "customer satisfaction score." A cyber security team might have a KPI of "number of critical vulnerabilities fixed within 30 days."
Your school might have a KPI of "percentage of students who passed the cyber security quiz." This tells the school how well students understand cyber security.
Your family might have a KPI of "number of devices with strong passwords." This tells your family how safe your home network is.
A Nigerian telecom company might have a KPI of "number of fraudulent SIM cards blocked per month." This tells them how well they are fighting fraud.
Key Performance Indicators (KPIs)
|
V
+---------------------------+
| Most Important Metrics |
+---------------------------+
|
V
+---------------------------+
| Show Winning or Losing |
+---------------------------+
|
V
+---------------------------+
| Help Focus on What |
| Matters Most |
+---------------------------+
|
V
+---------------------------+
| Example: % of computers |
| with updated antivirus |
+---------------------------+
KPIs are special metrics that show how well you are doing at important things. They help you focus on what matters most.
Mean Time to Detect (MTTD) is the average time it takes to notice that a cyber attack has happened.
The faster you detect an attack, the faster you can stop it. If it takes a long time to detect an attack, the attacker has more time to steal data or cause damage.
Imagine a thief breaks into your house. If you notice immediately, you can call for help. If you notice three days later, the thief is long gone. MTTD measures how fast you notice.
A company might have an MTTD of 2 hours. This means that on average, it takes 2 hours to notice an attack. A better MTTD would be 30 minutes or less.
If someone breaks into your school's computer system, how long does it take for the school to notice? That is MTTD.
If someone tries to access your family's Wi-Fi, how long does it take for you to notice? That is MTTD.
A Nigerian bank might have an MTTD of 1 hour for fraudulent transactions. This means they notice fraud within 1 hour on average.
Mean Time to Detect (MTTD)
|
V
+---------------------------+
| Attack Happens |
+---------------------------+
|
V
+---------------------------+
| Time Passes... |
+---------------------------+
|
V
+---------------------------+
| Attack Detected |
+---------------------------+
|
V
+---------------------------+
| MTTD = Time Between |
| Attack and Detection |
+---------------------------+
MTTD is the average time it takes to notice an attack. The smaller the MTTD, the better.
Mean Time to Respond (MTTR) is the average time it takes to fix a problem after you detect it.
Detecting an attack is good. But you also need to fix it quickly. If you detect an attack but take a long time to respond, the attacker can still cause damage.
Imagine you have a cut on your finger. You notice it (detect). Then you put a bandage on it (respond). MTTR measures how long it takes from noticing the cut to putting on the bandage.
A company might have an MTTR of 4 hours. This means that on average, it takes 4 hours to fix a problem after detecting it. A better MTTR would be 1 hour or less.
If a virus infects your school computers, how long does it take to remove the virus? That is MTTR.
If your phone gets a virus, how long does it take to clean it? That is MTTR.
A Nigerian bank might have an MTTR of 30 minutes for fraudulent transactions. This means they stop fraud within 30 minutes on average.
Mean Time to Respond (MTTR)
|
V
+---------------------------+
| Attack Detected |
+---------------------------+
|
V
+---------------------------+
| Time Passes... |
+---------------------------+
|
V
+---------------------------+
| Attack Fixed |
+---------------------------+
|
V
+---------------------------+
| MTTR = Time Between |
| Detection and Fix |
+---------------------------+
MTTR is the average time it takes to fix a problem after detecting it. The smaller the MTTR, the better.
A security dashboard is a screen or a page that shows all your important cyber security metrics in one place.
Instead of looking at many different reports, a dashboard shows you everything at a glance. It helps you quickly see if there is a problem.
Think about the dashboard in a car. It shows you the speed, the fuel level, and the temperature. You can see everything important in one place. A security dashboard does the same thing for cyber security.
A company might have a security dashboard that shows:
Your school might have a dashboard that shows how many students completed cyber security training and how many computers have antivirus.
Your family might have a simple dashboard that shows how many devices have strong passwords and how many updates are pending.
A Nigerian bank might have a dashboard that shows the number of fraudulent transactions blocked, the number of customer reports, and the average response time.
Security Dashboard
+------------------------------------------+
| Attacks Blocked Today: 1,234 |
| Attacks Got Through: 2 |
| Average Detect Time: 15 mins |
| Average Respond Time: 30 mins |
| Computers Updated: 95% |
| Staff Trained: 80% |
+------------------------------------------+
A security dashboard shows all your important metrics in one place. It helps you see the big picture quickly.
Not all metrics are useful. Good metrics help you make decisions. Bad metrics confuse you or mislead you.
If you use bad metrics, you might think you are safe when you are not. You might make wrong decisions. Good metrics tell you the truth.
A good metric is:
A bad metric is:
A good metric: "Percentage of computers with updated antivirus." This is clear, relevant, and actionable. If the number is low, you can update more computers.
A bad metric: "Total number of emails received." This is not useful for security. It does not tell you if you are safe.
A good metric: "Number of students who know not to share passwords."
A bad metric: "Number of pencils in the classroom."
A good metric: "Number of devices with strong passwords."
A bad metric: "Number of TV channels available."
A good metric for a bank: "Number of fraudulent transactions blocked."
A bad metric for a bank: "Number of pens in the office."
Good Metrics vs. Bad Metrics
|
V
+-------------------+ +-------------------+
| GOOD METRICS | | BAD METRICS |
+-------------------+ +-------------------+
| - Clear | | - Confusing |
| - Relevant | | - Irrelevant |
| - Actionable | | - Not actionable |
| - Timely | | - Late |
+-------------------+ +-------------------+
| |
V V
+-------------------+ +-------------------+
| Help you make | | Waste your time |
| good decisions | | and mislead you |
+-------------------+ +-------------------+
Good metrics are clear, relevant, actionable, and timely. Bad metrics are confusing, irrelevant, not actionable, and late. Always use good metrics.
Creating a metric means deciding what to measure and how to measure it.
If you do not create metrics, you will not have any data to help you make decisions. Creating metrics is the first step to becoming a Cyber Security Metrics Expert.
Here are the steps to create a simple metric:
A company wants to measure how many phishing emails are reported by employees. They create a metric: "Number of phishing emails reported per month." They set a target of 50 reports per month. They collect data and review it.
Your school wants to measure how many computers have updated antivirus. They create a metric: "Percentage of computers with updated antivirus." They set a target of 100%. They check each computer and count.
Your family wants to measure how many devices have strong passwords. They create a metric: "Number of devices with strong passwords." They set a target of all devices. They check each device.
A Nigerian company wants to measure how many workers completed cyber security training. They create a metric: "Percentage of workers who completed training." They set a target of 90%. They track who completes the training.
Steps to Create a Metric
|
V
+-------------------+
| 1. Choose What |
| to Measure |
+-------------------+
|
V
+-------------------+
| 2. Decide How |
| to Measure |
+-------------------+
|
V
+-------------------+
| 3. Set a Target |
+-------------------+
|
V
+-------------------+
| 4. Collect Data |
+-------------------+
|
V
+-------------------+
| 5. Review & Act |
+-------------------+
Creating a metric involves choosing what to measure, deciding how to measure it, setting a target, collecting data, and reviewing results.
Using metrics to tell a story means taking the numbers and explaining what they mean in a way that people can understand.
Numbers alone can be boring. But when you tell a story with the numbers, people understand better. They can see why the metrics matter.
Instead of saying, "We had 100 attacks last month," you could say, "Last month, we faced 100 attacks. We stopped 99 of them. But 1 got through. That 1 attack cost us 5 million naira. If we train our staff, we can stop all attacks and save money."
The second version tells a story. It explains why the numbers matter.
A security team tells their boss: "Last year, we had 50 attacks. We responded in 10 hours on average. This year, we had 100 attacks, but we responded in 2 hours on average. We are getting faster, but we are also getting more attacks. We need more staff."
A student tells the principal: "Last term, only 20% of students used strong passwords. This term, after our campaign, 60% use strong passwords. We are improving, but we want to reach 100%."
A child tells their parents: "Last month, we had 5 devices without antivirus. Now we have 0. Our home network is safer."
A Nigerian bank tells its customers: "Last year, we blocked 10,000 fraudulent transactions. This year, we blocked 25,000. We are protecting your money better."
Using Metrics to Tell a Story
|
V
+-------------------+
| Collect Numbers |
+-------------------+
|
V
+-------------------+
| Find Meaning |
+-------------------+
|
V
+-------------------+
| Explain to People|
+-------------------+
|
V
+-------------------+
| Inspire Action |
+-------------------+
Using metrics to tell a story means explaining what the numbers mean. It helps people understand why the metrics matter.
There are many common cyber security metrics that experts use. Here are some of the most important ones.
Knowing these metrics helps you understand cyber security reports. It helps you ask smart questions.
| Metric | What It Measures | Example |
|---|---|---|
| Number of Attacks Blocked | How many attacks were stopped | 1,234 attacks blocked today |
| Number of Successful Attacks | How many attacks got through | 2 attacks got through |
| Mean Time to Detect (MTTD) | How fast attacks are noticed | 15 minutes on average |
| Mean Time to Respond (MTTR) | How fast attacks are fixed | 30 minutes on average |
| Percentage of Updated Systems | How many computers have the latest software | 95% updated |
| Percentage of Trained Staff | How many people know about security | 80% trained |
| Number of Phishing Reports | How many fake emails were reported | 50 reports this month |
| Number of Vulnerabilities | How many weaknesses exist | 10 vulnerabilities found |
A company looks at these metrics every week. They see that MTTD is going up. This means it is taking longer to detect attacks. They decide to buy a better detection tool.
Your school looks at "percentage of trained students." If it is low, they organize a training session.
Your family looks at "percentage of updated devices." If it is low, they update all devices.
A Nigerian bank looks at "number of phishing reports." If it is high, they know their customers are aware. If it is low, they need more awareness campaigns.
Common Cyber Security Metrics
+------------------------------------------+
| Attacks Blocked: 1,234 |
| Successful Attacks: 2 |
| MTTD: 15 mins |
| MTTR: 30 mins |
| Systems Updated: 95% |
| Staff Trained: 80% |
| Phishing Reports: 50 |
| Vulnerabilities: 10 |
+------------------------------------------+
Common cyber security metrics include attacks blocked, successful attacks, MTTD, MTTR, percentage of updated systems, percentage of trained staff, number of phishing reports, and number of vulnerabilities.
Cyber security metrics are used all over the world, including in Nigeria. Here are some Nigerian examples.
Seeing examples from Nigeria helps you understand how metrics work in your own country.
Here are some Nigerian examples:
A Nigerian bank might report: "Last month, we blocked 5,000 fraudulent transactions. We saved our customers 2 billion naira. Our average response time was 20 minutes."
A Nigerian school might report: "Last term, 70% of our students completed cyber security training. This term, we want to reach 90%."
A Nigerian family might say: "All our devices now have strong passwords. Our home network is safer."
NITDA might report: "We detected 1,000 attacks on government websites last year. We blocked 950 of them. We are working to block all attacks."
Nigerian Cyber Security Metrics
+------------------------------------------+
| Bank Fraud Blocked: 5,000 |
| Money Saved: 2 billion naira|
| Fake SIM Cards Blocked: 10,000 |
| Government Attacks: 1,000 |
| Attacks Blocked: 950 |
| Students Trained: 70% |
+------------------------------------------+
Nigerian banks, telecoms, government agencies, schools, and businesses all use cyber security metrics to stay safe.
Cyber security metrics can be explained using fun examples that children understand.
When you use fun examples, learning becomes easier and more enjoyable.
Here are some fun examples:
Imagine you are playing a game where you have to protect a castle from enemies. Your metrics are:
Your school report card is a dashboard of metrics. It shows your scores in different subjects. It tells you how well you are doing.
Your phone's battery percentage is a metric. It tells you how much power is left. Cyber security metrics tell you how much protection is left.
In a Nigerian football match, the scoreboard is a metric. The number of yellow cards is a metric. The number of corner kicks is a metric. These help fans understand the game.
Fun Metrics Children Relate To
+------------------------------------------+
| Video Game Score: 10,000 |
| Football Goals: 3 |
| Social Media Likes: 500 |
| Test Scores: 85% |
| Phone Battery: 75% |
+------------------------------------------+
Metrics are everywhere. They are in video games, football, social media, school, and cooking. Cyber security metrics are just another type of metric.
Cyber security metrics are not just for big companies. They are also useful in everyday life.
When you understand metrics in everyday life, you can use them to stay safe.
Here are everyday examples:
You can create a simple metric for your phone: "Number of apps with unnecessary permissions." If the number is high, you can remove permissions.
Your school can create a metric: "Number of students who know not to click on suspicious links." If the number is low, they can teach more about it.
Your family can create a metric: "Number of devices with automatic updates turned on." If the number is low, they can turn on automatic updates.
A Nigerian family can create a metric: "Number of family members who know not to share OTP (One Time Password) with anyone." If the number is low, they can talk about it.
Everyday Cyber Security Metrics
+------------------------------------------+
| Apps with Location Access: 5 |
| Accounts with Strong Passwords: 8 |
| Spam Emails Received: 20 |
| Devices Connected to Wi-Fi: 6 |
| Suspicious Links Received: 3 |
+------------------------------------------+
Cyber security metrics are useful in everyday life. You can measure phone security, password security, email security, Wi-Fi security, and social media security.
| Word | Simple Definition |
|---|---|
| Metric | A number that measures something |
| Cyber Security | Protecting computers and data from bad people |
| KPI | Key Performance Indicator - an important metric |
| MTTD | Mean Time to Detect - how fast you notice a problem |
| MTTR | Mean Time to Respond - how fast you fix a problem |
| Lagging Indicator | A metric that looks at the past |
| Leading Indicator | A metric that predicts the future |
| Dashboard | A screen that shows all important metrics in one place |
| Vulnerability | A weakness that a hacker can use |
| Phishing | A fake email or message that tries to steal information |
| Attack | When someone tries to break into a computer system |
| Detection | Noticing that an attack has happened |
| Response | Fixing a problem after detecting it |
| Target | The number you want to reach |
| Data | Information |
A bank in Lagos uses metrics to track fraud. They measure:
A school in Abuja uses metrics to track cyber security awareness. They measure:
A family in Port Harcourt uses metrics to stay safe online. They measure:
Banks like GTBank, Zenith, and Access Bank use metrics to fight fraud. They measure how many fraudulent transactions they block and how much money they save.
Companies like MTN, Glo, and Airtel use metrics to fight SIM card fraud. They measure how many fake SIM cards they block.
NITDA uses metrics to track attacks on government websites. They measure how many attacks happen and how many they block.
Schools like Covenant University and University of Lagos use metrics to track cyber security training. They measure how many students complete the training.
Companies like Jumia and Konga use metrics to track fake orders and fraudulent payments. They measure how many fake orders they block.
In a video game, your score, health, and level are all metrics. They tell you how well you are doing. Cyber security metrics do the same thing for computer systems.
In football, goals, passes, and possession are metrics. They tell you how well your team is playing. Cyber security metrics tell you how well your computer system is protected.
On social media, likes, comments, and shares are metrics. They tell you how popular a post is. Cyber security metrics tell you how safe your account is.
Your test scores, attendance, and homework completion are metrics. They tell you how well you are doing in school. Cyber security metrics tell you how well you are doing at staying safe online.
How many apps have access to your location? How many apps have permissions they do not need? These are metrics.
How many of your accounts have strong passwords? How many have two-factor authentication? These are metrics.
How many spam emails did you receive? How many did you report? These are metrics.
How many devices are connected to your Wi-Fi? How many have updated software? These are metrics.
How many strangers sent you friend requests? How many suspicious links did you receive? These are metrics.
+-------------------+
| Attack Happens |
+-------------------+
|
V
+-------------------+
| Detection (MTTD) |
+-------------------+
|
V
+-------------------+
| Response (MTTR) |
+-------------------+
|
V
+-------------------+
| Recovery |
+-------------------+
|
V
+-------------------+
| Metrics Review |
+-------------------+
|
V
+-------------------+
| Improvement |
+-------------------+
Past Present Future
| | |
V V V
+----------------+ +----------------+ +----------------+
| Lagging | | Current | | Leading |
| Indicators | | Metrics | | Indicators |
+----------------+ +----------------+ +----------------+
| | |
V V V
+----------------+ +----------------+ +----------------+
| Attacks last | | Attacks today | | Training |
| month | | | | completed |
+----------------+ +----------------+ +----------------+
| Metric | Current Value | Target | Status |
|---|---|---|---|
| Attacks Blocked | 1,234 | 1,000 | Good |
| Attacks Got Through | 2 | 0 | Needs Work |
| MTTD | 15 mins | 10 mins | Needs Work |
| MTTR | 30 mins | 20 mins | Needs Work |
| Systems Updated | 95% | 100% | Good |
| Staff Trained | 80% | 90% | Needs Work |
| Feature | Lagging Indicator | Leading Indicator |
|---|---|---|
| Looks at | Past | Present/Future |
| Purpose | Tells what happened | Predicts what may happen |
| Example | Attacks last month | Training completed |
| Action | React | Prevent |
| Feature | Good Metric | Bad Metric |
|---|---|---|
| Clarity | Clear | Confusing |
| Relevance | Relevant | Irrelevant |
| Actionable | Actionable | Not actionable |
| Timeliness | Timely | Late |
Cyber security metrics are numbers that tell us how safe our computer systems are. They help us make smart decisions.
We need metrics to know if we are safe, to make good decisions, and to show that we are improving.
There are four main types of cyber security metrics: technical, operational, human, and strategic.
Lagging indicators look at the past. Leading indicators help predict the future.
KPIs are special metrics that show how well you are doing at important things.
MTTD is the average time it takes to notice an attack. Smaller is better.
MTTR is the average time it takes to fix a problem after detecting it. Smaller is better.
A security dashboard shows all your important metrics in one place.
Good metrics are clear, relevant, actionable, and timely. Bad metrics are confusing, irrelevant, not actionable, and late.
Creating a metric involves choosing what to measure, deciding how to measure it, setting a target, collecting data, and reviewing results.
Using metrics to tell a story means explaining what the numbers mean.
Common cyber security metrics include attacks blocked, successful attacks, MTTD, MTTR, percentage of updated systems, percentage of trained staff, number of phishing reports, and number of vulnerabilities.
Nigerian banks, telecoms, government agencies, schools, and businesses all use cyber security metrics.
Metrics are everywhere, from video games to football to social media.
Cyber security metrics are useful in everyday life, from phone security to Wi-Fi security.
Congratulations! You have completed Module Two: Cyber Security Metrics Expert.
In this module, you learned that metrics are numbers that measure something. You learned that cyber security metrics measure how safe our computer systems are.
You learned that we need metrics for three main reasons: to know if we are safe, to make good decisions, and to show progress.
You learned about four types of metrics: technical, operational, human, and strategic.
You learned about lagging indicators and leading indicators. Lagging indicators look at the past. Leading indicators predict the future.
You learned about KPIs, which are the most important metrics.
You learned about MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond).
You learned about security dashboards, which show all important metrics in one place.
You learned about good metrics and bad metrics. Good metrics are clear, relevant, actionable, and timely.
You learned how to create a simple metric.
You learned how to use metrics to tell a story.
You learned about common cyber security metrics.
You learned about Nigerian examples of cyber security metrics.
You learned about fun examples and everyday examples.
You are now a Cyber Security Metrics Expert in training!
A cyber security metric is a number that measures how safe a computer system is. It tells you if you are protected or if you have problems.
We need metrics to know if we are safe, to make good decisions, and to show that we are improving.
A lagging indicator looks at the past. A leading indicator predicts the future. Leading indicators help you prevent problems.
A KPI is a Key Performance Indicator. It is a special metric that shows how well you are doing at something important.
MTTD stands for Mean Time to Detect. It is the average time it takes to notice an attack.
MTTR stands for Mean Time to Respond. It is the average time it takes to fix a problem after detecting it.
A security dashboard is a screen or page that shows all your important cyber security metrics in one place.
A good metric is clear, relevant, actionable, and timely. It helps you make good decisions.
Yes! You can create metrics to measure anything, including your own cyber security habits.
Nigerian banks, telecoms, and government agencies use metrics to track fraud, block attacks, and measure security training.
| Word | Definition |
|---|---|
| 1. Metric | A. A metric that looks at the past |
| 2. MTTD | B. A number that measures something |
| 3. MTTR | C. A metric that predicts the future |
| 4. Lagging Indicator | D. Mean Time to Detect |
| 5. Leading Indicator | E. Mean Time to Respond |
| 6. Dashboard | F. A special metric that shows important performance |
| 7. KPI | G. A screen that shows all important metrics |
Answers: 1-B, 2-D, 3-E, 4-A, 5-C, 6-G, 7-F
Your school computer lab has 50 computers. Last month, 10 computers got a virus. The school wants to reduce this number.
Question: What metric could the school use to measure improvement?
Answer: The school could use "Number of computers with viruses per month." They could set a target of 0 viruses. They could also use "Percentage of computers with updated antivirus" as a leading indicator.
Your family Wi-Fi has been slow. You suspect someone is using it without permission.
Question: What metric could you use to check?
Answer: You could use "Number of devices connected to Wi-Fi." If the number is higher than expected, someone might be using it without permission.
A Nigerian bank wants to reduce fraud. They want to know how fast they detect fraud.
Question: What metric should they use?
Answer: They should use Mean Time to Detect (MTTD). They should also use Mean Time to Respond (MTTR).
Instructions:
Time: 30 minutes
Instructions:
Goal: Create a dashboard that shows the cyber security health of your class.
Steps:
Time: 2 weeks
Instructions:
In Module Three, you will learn about Cyber Security Risk Management.
You will learn:
To prepare for Module Three, think about these questions:
See you in Module Three!
End of Module Two
Welcome to Module Three of your journey to becoming a Cyber Security Metrics Expert!
In Module One, you learned what cyber security is and why it matters. You learned that cyber security is like protecting a house from bad people who want to steal things or cause problems.
In Module Two, you learned about metrics. You learned that metrics are numbers that measure something. You learned that cyber security metrics help us understand how safe our computer systems are.
Now, in Module Three, you are going to learn about Cyber Security Risk Management.
What is risk?
Risk is the chance that something bad will happen. It is the possibility that you will lose something or that something will go wrong.
Think about crossing a busy road. There is a risk that a car might hit you. The risk is higher if you do not look both ways. The risk is lower if you use a pedestrian bridge.
In cyber security, risk is the chance that a hacker will break into your computer, steal your data, or cause damage. Risk management is how we reduce that chance.
Imagine you are playing a game where you have to protect a treasure chest. There are many dangers: thieves, traps, and bad weather. You need to think about each danger and decide how to protect the treasure. That is risk management.
Cyber security risk management is the same. We look at all the dangers to our computers and data. We decide which dangers are most serious. We choose the best ways to protect ourselves. We use metrics to measure how well we are doing.
In this module, you will learn all about cyber security risk management. You will learn how to identify risks, assess risks, and manage risks. You will learn how metrics help us make smart decisions about risk.
By the end of this module, you will be able to look at a computer system and spot the risks. You will be able to decide what to do about them. You will be able to use metrics to measure your success.
Let us begin this exciting journey together!
After completing this module, you will be able to:
Once upon a time, in the ancient city of Kano, Nigeria, there lived a wise old man named Baba Musa. Baba Musa had a beautiful treasure chest filled with gold, silver, and precious stones.
Baba Musa lived in a small house at the edge of the city. He loved his treasure, but he was always worried. He knew that thieves might try to steal it.
One day, Baba Musa called his three grandchildren: Amina, Chidi, and Tunde.
"My children," Baba Musa said, "I need your help. I want to protect my treasure from thieves. But I do not know where to start."
Amina, who was very smart, said, "Grandfather, let us think about the risks. What are the dangers?"
Baba Musa nodded. "Good question, Amina. Let us make a list."
They sat down together and made a list of all the dangers:
Chidi looked at the list and said, "Grandfather, there are so many dangers! How do we know which one is most important?"
Baba Musa smiled. "That is where risk assessment comes in. We need to think about two things: How likely is each danger? And how bad would it be if it happened?"
They made a table:
| Danger | How Likely? | How Bad? |
|---|---|---|
| Thief breaks door | Medium | Very Bad |
| Thief climbs window | High | Very Bad |
| Thief tricks Baba Musa | Medium | Very Bad |
| Fire | Low | Very Bad |
| Flood | Low | Very Bad |
| Family member steals | Low | Bad |
Tunde looked at the table and said, "Grandfather, the window is the biggest problem. It is very likely and very bad."
Baba Musa nodded. "You are right, Tunde. So what should we do?"
Amina said, "We can fix the window. We can put strong bars on it."
Chidi said, "We can also get a dog to guard the house."
Tunde said, "We can hide the treasure in a secret place."
Baba Musa smiled. "These are all good ideas. We are managing the risk. We are reducing the chance that a thief will steal our treasure."
They fixed the window. They got a dog. They hid the treasure. They also made a plan to check the house every night.
From that day on, Baba Musa felt safer. He knew that he had managed the risks. He had used metrics to measure the risks. He had made smart decisions.
That night, Baba Musa told his grandchildren, "You have learned a very important lesson. Risk management is not just for treasure. It is for everything. It is for your health, your money, and even your computer."
And that is exactly what you will learn in this module.
Risk is the chance that something bad will happen. It is the possibility that you will lose something or that something will go wrong.
If you do not understand risk, you cannot protect yourself. You might worry about the wrong things. You might ignore the real dangers.
Imagine you are walking to school. There are many risks:
Each of these is a risk. Some risks are small. Some risks are big. Risk is everywhere.
A bank has risks. Someone might try to rob the bank. Someone might try to hack the bank's computers. Someone might try to steal money using fake cards.
Your school has risks. A student might share their password. A computer might get a virus. Someone might steal a laptop.
Your home has risks. Someone might guess your Wi-Fi password. Your phone might get a virus. A family member might click on a fake link.
A Nigerian market has risks. A trader might be robbed. A customer might use fake money. A fire might destroy goods.
Risk is Everywhere
|
V
+-------------------+
| Walking to School|
+-------------------+
|
V
+-------------------+
| Risk of Falling |
+-------------------+
|
V
+-------------------+
| Risk of Lateness |
+-------------------+
|
V
+-------------------+
| Risk of Danger |
+-------------------+
Risk is the chance that something bad will happen. It is everywhere. Understanding risk helps us protect ourselves.
Cyber security risk is the chance that a hacker will break into your computer, steal your data, or cause damage.
Cyber security risk is important because our lives are on computers. We use computers for school, work, banking, and fun. If our computers are not safe, we can lose money, privacy, and trust.
Imagine you have a diary with all your secrets. You keep it in a locked drawer. The risk is that someone will find the key and read your diary. Cyber security risk is the same. Your computer has secrets. The risk is that a hacker will find a way in.
A hospital has cyber security risks. Hackers might steal patient records. They might change medical information. They might shut down the hospital's computers.
Your school has cyber security risks. Hackers might steal student grades. They might change exam results. They might send fake emails to parents.
Your home has cyber security risks. Hackers might access your Wi-Fi. They might steal your parents' bank information. They might watch you through your webcam.
A Nigerian bank has cyber security risks. Hackers might steal customer money. They might use fake emails to trick customers. They might attack the bank's website.
Cyber Security Risk
|
V
+-------------------+
| Your Computer |
+-------------------+
|
V
+-------------------+
| Hackers Want In |
+-------------------+
|
V
+-------------------+
| Risk of Theft |
+-------------------+
|
V
+-------------------+
| Risk of Damage |
+-------------------+
Cyber security risk is the chance that a hacker will break into your computer or steal your data. It is important because our lives are on computers.
These three words are often confused. Let us learn the difference.
If you understand these three words, you can understand cyber security better. You can see where problems come from.
Imagine a house. The threat is a thief. The vulnerability is an open window. The risk is the chance that the thief will climb through the open window.
If you close the window, you reduce the vulnerability. If you get a dog, you reduce the threat. If you do both, you reduce the risk.
A bank has a threat (hackers), a vulnerability (old software), and a risk (hackers using the old software to steal money).
A school has a threat (students who want to cheat), a vulnerability (weak passwords on school computers), and a risk (students using weak passwords to change grades).
A home has a threat (strangers), a vulnerability (Wi-Fi without a password), and a risk (strangers using the Wi-Fi to do bad things).
A Nigerian business has a threat (fraudsters), a vulnerability (employees who do not check emails carefully), and a risk (fraudsters tricking employees into sending money).
Threat, Vulnerability, and Risk
|
V
+-------------------+
| Threat: A Thief |
+-------------------+
|
V
+-------------------+
| Vulnerability: |
| Open Window |
+-------------------+
|
V
+-------------------+
| Risk: Thief Uses |
| Window to Enter |
+-------------------+
A threat is something that can cause harm. A vulnerability is a weakness. A risk is the chance that a threat will use a vulnerability to cause harm.
There are many types of cyber security risks. Each type is different.
Knowing the types of risks helps you prepare for them.
Here are the main types of cyber security risks:
| Type of Risk | What It Means | Example |
|---|---|---|
| Malware | Bad software that harms your computer | A virus that deletes files |
| Phishing | Fake emails or messages that trick you | An email pretending to be from your bank |
| Ransomware | Bad software that locks your files and asks for money | A message saying "Pay 1 million naira or lose your files" |
| Data Breach | When private information is stolen | Hackers stealing customer names and passwords |
| Insider Threat | When someone inside the company causes harm | An employee stealing company secrets |
| Denial of Service | When a website is flooded with traffic so it stops working | A website that cannot be accessed |
A bank faces many risks. They face malware, phishing, ransomware, data breaches, insider threats, and denial of service attacks.
Your school faces risks. A student might download malware. A teacher might click on a phishing email. A hacker might steal student data.
Your home faces risks. Your phone might get malware. You might receive a phishing message. Your Wi-Fi might be attacked.
A Nigerian company faces risks. Fraudsters might send phishing emails. Hackers might steal customer data. Employees might leak information.
Types of Cyber Security Risks
|
V
+---------------------------+
| Malware |
+---------------------------+
|
V
+---------------------------+
| Phishing |
+---------------------------+
|
V
+---------------------------+
| Ransomware |
+---------------------------+
|
V
+---------------------------+
| Data Breach |
+---------------------------+
|
V
+---------------------------+
| Insider Threat |
+---------------------------+
|
V
+---------------------------+
| Denial of Service |
+---------------------------+
There are many types of cyber security risks: malware, phishing, ransomware, data breaches, insider threats, and denial of service.
Risk assessment is the process of looking at risks and deciding how serious they are.
You cannot fix every risk. Some risks are small. Some risks are big. Risk assessment helps you focus on the big risks first.
Imagine you are cleaning your room. You have many things to do: make the bed, fold clothes, arrange books, and sweep the floor. Which should you do first? You might do the most important things first. Risk assessment is the same. You look at all the risks and decide which ones are most important.
A bank does a risk assessment. They look at all the ways they could lose money. They decide which risks are most serious. They spend more money on those risks.
Your school does a risk assessment. They look at all the ways student data could be stolen. They decide which risks are most serious.
Your family does a risk assessment. They look at all the ways your home network could be attacked. They decide which risks are most serious.
A Nigerian company does a risk assessment. They look at all the ways they could lose money to fraud. They decide which risks are most serious.
Risk Assessment Process
|
V
+-------------------+
| List All Risks |
+-------------------+
|
V
+-------------------+
| How Likely? |
+-------------------+
|
V
+-------------------+
| How Bad? |
+-------------------+
|
V
+-------------------+
| Prioritize |
+-------------------+
|
V
+-------------------+
| Take Action |
+-------------------+
Risk assessment is looking at risks and deciding how serious they are. It helps you focus on the most important risks.
To assess risk, you need to think about two things: likelihood and impact.
If you know the likelihood and impact, you can decide which risks to handle first.
Imagine you are going to play football. There is a risk that it will rain.
Now imagine there is a risk that a lion will escape from the zoo and come to the field.
Which risk should you worry about more? The rain, because it is more likely. But you should still be aware of the lion.
A bank assesses the risk of a hacker attack. The likelihood is medium. The impact is very high. They decide to spend a lot of money on protection.
Your school assesses the risk of a student sharing a password. The likelihood is high. The impact is medium. They decide to teach students about password safety.
Your family assesses the risk of someone guessing your Wi-Fi password. The likelihood is medium. The impact is medium. They decide to change the password to something stronger.
A Nigerian company assesses the risk of a phishing email. The likelihood is high. The impact is high. They decide to train all employees.
Risk Assessment Matrix
|
V
+-------------------+-------------------+
| | |
| High Likelihood | High Likelihood |
| Low Impact | High Impact |
| | |
+-------------------+-------------------+
| | |
| Low Likelihood | Low Likelihood |
| Low Impact | High Impact |
| | |
+-------------------+-------------------+
To assess risk, think about likelihood (how likely?) and impact (how bad?). This helps you prioritize risks.
A risk matrix is a table that helps you see which risks are most serious. It uses likelihood and impact.
A risk matrix makes it easy to see which risks need attention first.
Here is a simple risk matrix:
| Likelihood / Impact | Low Impact | Medium Impact | High Impact |
|---|---|---|---|
| High Likelihood | Medium Risk | High Risk | Very High Risk |
| Medium Likelihood | Low Risk | Medium Risk | High Risk |
| Low Likelihood | Very Low Risk | Low Risk | Medium Risk |
Risks in the top right are the most serious. Risks in the bottom left are the least serious.
A bank puts all their risks on a matrix. They see that "hacker attack" is in the "Very High Risk" box. They spend more money on that.
Your school puts all their risks on a matrix. They see that "student shares password" is in the "High Risk" box. They start a password safety campaign.
Your family puts all their risks on a matrix. They see that "Wi-Fi password is weak" is in the "Medium Risk" box. They change the password.
A Nigerian company puts all their risks on a matrix. They see that "phishing email" is in the "Very High Risk" box. They train all employees.
Risk Matrix
+-------------------+-------------------+-------------------+
| | | |
| High Likelihood | High Likelihood | High Likelihood |
| Low Impact | Medium Impact | High Impact |
| (Medium Risk) | (High Risk) | (Very High Risk) |
| | | |
+-------------------+-------------------+-------------------+
| | | |
| Medium Likelihood| Medium Likelihood| Medium Likelihood|
| Low Impact | Medium Impact | High Impact |
| (Low Risk) | (Medium Risk) | (High Risk) |
| | | |
+-------------------+-------------------+-------------------+
| | | |
| Low Likelihood | Low Likelihood | Low Likelihood |
| Low Impact | Medium Impact | High Impact |
| (Very Low Risk) | (Low Risk) | (Medium Risk) |
| | | |
+-------------------+-------------------+-------------------+
A risk matrix helps you see which risks are most serious. It uses likelihood and impact to prioritize risks.
Risk management strategies are the ways we deal with risks. There are four main strategies:
Not all risks can be removed. You need to choose the best strategy for each risk.
Imagine you are going to swim in a river. There is a risk of drowning.
A bank faces the risk of a hacker attack. They can:
Your school faces the risk of a student sharing a password. They can:
Your family faces the risk of someone guessing the Wi-Fi password. They can:
A Nigerian company faces the risk of phishing. They can:
Risk Management Strategies
|
V
+-------------------+
| Avoid |
+-------------------+
|
V
+-------------------+
| Reduce |
+-------------------+
|
V
+-------------------+
| Transfer |
+-------------------+
|
V
+-------------------+
| Accept |
+-------------------+
There are four risk management strategies: avoid, reduce, transfer, and accept. Choose the best one for each risk.
Metrics help us measure risk. They tell us how likely a risk is and how bad it could be.
Without metrics, we are guessing. Metrics help us make smart decisions about risk.
Imagine you want to know the risk of getting a virus on your computer. You can use metrics:
These metrics tell you how likely it is that a virus will infect your computer.
A bank uses metrics to measure the risk of fraud. They track:
Your school uses metrics to measure the risk of a data breach. They track:
Your family uses metrics to measure the risk of a Wi-Fi attack. They track:
A Nigerian company uses metrics to measure the risk of phishing. They track:
Using Metrics to Measure Risk
|
V
+-------------------+
| Collect Data |
+-------------------+
|
V
+-------------------+
| Analyze Numbers |
+-------------------+
|
V
+-------------------+
| Understand Risk |
+-------------------+
|
V
+-------------------+
| Make Decisions |
+-------------------+
Metrics help us measure risk. They tell us how likely a risk is and how bad it could be. They help us make smart decisions.
A risk register is a list of all the risks a person or company faces. It includes information about each risk.
A risk register helps you keep track of all your risks. You can see which ones are most serious. You can see what you are doing about them.
A risk register is like a to-do list for risks. It has columns for:
A bank's risk register might look like this:
| Risk | Likelihood | Impact | Action | Owner |
|---|---|---|---|---|
| Hacker attack | Medium | High | Install firewall | IT Team |
| Phishing | High | High | Train staff | HR Team |
| Data breach | Medium | Very High | Encrypt data | IT Team |
Your school's risk register might include risks like "student shares password," "computer gets virus," and "laptop is stolen."
Your family's risk register might include risks like "Wi-Fi password is weak," "phone gets virus," and "family member clicks on fake link."
A Nigerian company's risk register might include risks like "fraudulent transaction," "fake email," and "employee leaks data."
Risk Register
+-------------------+------------+----------+----------------+----------+
| Risk | Likelihood | Impact | Action | Owner |
+-------------------+------------+----------+----------------+----------+
| Hacker attack | Medium | High | Install firewall| IT Team |
| Phishing | High | High | Train staff | HR Team |
| Data breach | Medium | Very High| Encrypt data | IT Team |
+-------------------+------------+----------+----------------+----------+
A risk register is a list of all risks, with information about each one. It helps you keep track of your risks and what you are doing about them.
Risk communication is telling people about risks in a way they can understand.
If people do not understand the risks, they cannot help. Risk communication helps everyone work together to stay safe.
Imagine you are the captain of a ship. You see an iceberg ahead. You need to tell the crew. If you say, "There is a large mass of frozen water in our path," they might not understand. If you say, "There is a big ice block ahead. We might crash. We need to turn," they will understand.
Risk communication is about using simple words to explain risks.
A bank tells its customers: "Be careful of emails that ask for your password. We will never ask for your password by email. If you get such an email, do not reply. Report it to us."
Your school tells students: "Do not share your password with anyone. Even your best friend. If someone has your password, they can see your grades and change them."
Your parents tell you: "Do not click on links in messages from people you do not know. They might be trying to steal our information."
A Nigerian bank tells its customers: "Never share your OTP with anyone. Not even someone who says they are from the bank. If you share it, you might lose your money."
Risk Communication
|
V
+-------------------+
| Identify Risk |
+-------------------+
|
V
+-------------------+
| Explain Simply |
+-------------------+
|
V
+-------------------+
| Tell People What |
| To Do |
+-------------------+
|
V
+-------------------+
| Everyone Stays |
| Safe |
+-------------------+
Risk communication is telling people about risks in a simple way. It helps everyone work together to stay safe.
Risk management is used all over the world, including in Nigeria. Here are some Nigerian examples.
Seeing examples from Nigeria helps you understand how risk management works in your own country.
Here are some Nigerian examples:
A Nigerian bank might say: "We have a risk register. We list all the risks we face. We assess each risk. We decide what to do. We use metrics to measure our success."
A Nigerian school might say: "We have a risk register. We list all the risks to our computers. We teach students about strong passwords. We update our software."
A Nigerian family might say: "We have a risk register. We list all the risks to our home network. We use strong passwords. We update our devices."
NITDA might say: "We have a risk register for government websites. We list all the risks. We assess each risk. We use firewalls and monitor traffic."
Nigerian Risk Management
+------------------------------------------+
| Banks: Fraud risk management |
| Telecoms: SIM card fraud management |
| Government: Cyber attack management |
| Schools: Data breach management |
| Businesses: Fake order management |
+------------------------------------------+
Nigerian banks, telecoms, government agencies, schools, and businesses all use risk management to stay safe.
Risk management can be explained using fun examples that children understand.
When you use fun examples, learning becomes easier and more enjoyable.
Here are some fun examples:
Imagine you are playing a game where you have to protect a castle. The risks are:
Your school report card is a risk assessment. If your math score is low, you have a risk of failing. You manage this risk by studying more.
Your phone's battery percentage is a risk indicator. If it is low, you have a risk of your phone dying. You manage this risk by charging it.
In a Nigerian football match, the coach manages the risk of losing. He might change players. He might change tactics. He might tell the team to defend more.
Fun Risk Management
+------------------------------------------+
| Video Game: Buy armor |
| Football: Practice more |
| Social Media: Use strong password |
| School: Study harder |
| Cooking: Use low heat |
+------------------------------------------+
Risk management is everywhere. It is in video games, football, social media, school, and cooking. Cyber security risk management is just another type.
Risk management is not just for big companies. It is also useful in everyday life.
When you understand risk management in everyday life, you can use it to stay safe.
Here are everyday examples:
You manage the risk of getting a virus by:
Your school manages the risk of a data breach by:
Your family manages the risk of a Wi-Fi attack by:
A Nigerian family manages the risk of OTP fraud by:
Everyday Risk Management
+------------------------------------------+
| Crossing Road: Look both ways |
| Riding Bike: Wear helmet |
| Using Phone: Keep safe |
| Going Online: Use antivirus |
| Sharing Info: Be careful |
+------------------------------------------+
Risk management is useful in everyday life. You can manage risks when crossing the road, riding a bike, using a phone, going online, and sharing information.
A risk management plan is a document that explains how you will handle risks.
A plan helps you stay organized. It helps you remember what to do. It helps you measure your success.
A risk management plan has these parts:
A bank's risk management plan includes:
Your school's risk management plan includes:
Your family's risk management plan includes:
A Nigerian company's risk management plan includes:
Risk Management Plan
|
V
+-------------------+
| List Risks |
+-------------------+
|
V
+-------------------+
| Assess Risks |
+-------------------+
|
V
+-------------------+
| Choose Strategy |
+-------------------+
|
V
+-------------------+
| Set Metrics |
+-------------------+
|
V
+-------------------+
| Assign Owner |
+-------------------+
|
V
+-------------------+
| Review Regularly |
+-------------------+
A risk management plan explains how you will handle risks. It includes a list of risks, assessment, strategies, metrics, responsibilities, and a review schedule.
| Word | Simple Definition |
|---|---|
| Risk | The chance that something bad will happen |
| Threat | Something that can cause harm |
| Vulnerability | A weakness that a threat can use |
| Risk Assessment | Looking at risks and deciding how serious they are |
| Likelihood | How likely something is to happen |
| Impact | How bad something will be if it happens |
| Risk Matrix | A table that helps you prioritize risks |
| Risk Register | A list of all risks |
| Risk Management | Doing things to reduce risks |
| Avoid | Stop doing the thing that causes the risk |
| Reduce | Make the risk smaller |
| Transfer | Give the risk to someone else |
| Accept | Decide the risk is small and do nothing |
| Metrics | Numbers that measure something |
| Plan | A document that explains what you will do |
A bank in Lagos uses risk management to protect against fraud. They:
A school in Abuja uses risk management to protect student data. They:
A family in Port Harcourt uses risk management to stay safe online. They:
Banks like GTBank, Zenith, and Access Bank use risk management to fight fraud. They list risks, assess them, and choose strategies.
Companies like MTN, Glo, and Airtel use risk management to fight SIM card fraud. They check IDs and monitor usage.
NITDA uses risk management to protect government websites. They use firewalls and monitor traffic.
Schools like Covenant University and University of Lagos use risk management to protect student data. They train students and update software.
Companies like Jumia and Konga use risk management to fight fake orders. They check payments and monitor accounts.
In a video game, you manage risks by buying armor, learning to fight, and saving your game. Cyber security risk management is the same.
In football, you manage risks by practicing, playing defense, and following the rules. Cyber security risk management is the same.
On social media, you manage risks by using strong passwords and not sharing too much. Cyber security risk management is the same.
In school, you manage risks by studying, keeping your work safe, and asking for help. Cyber security risk management is the same.
The risk is being hit by a car. You manage it by looking both ways.
The risk is falling. You manage it by wearing a helmet.
The risk is the phone being stolen. You manage it by keeping it in a safe place.
The risk is getting a virus. You manage it by using antivirus software.
The risk is someone using your information badly. You manage it by being careful what you share.
+-------------------+
| Identify Risks |
+-------------------+
|
V
+-------------------+
| Assess Risks |
+-------------------+
|
V
+-------------------+
| Prioritize Risks |
+-------------------+
|
V
+-------------------+
| Choose Strategy |
+-------------------+
|
V
+-------------------+
| Implement |
+-------------------+
|
V
+-------------------+
| Monitor & Review |
+-------------------+
|
V
+-------------------+
| Improve |
+-------------------+
Past Present Future
| | |
V V V
+----------------+ +----------------+ +----------------+
| Identify Risks | | Assess Risks | | Monitor Risks |
+----------------+ +----------------+ +----------------+
| | |
V V V
+----------------+ +----------------+ +----------------+
| List all risks | | Likelihood & | | Metrics & |
| | | Impact | | Review |
+----------------+ +----------------+ +----------------+
| Risk | Likelihood | Impact | Action | Owner |
|---|---|---|---|---|
| Hacker attack | Medium | High | Install firewall | IT Team |
| Phishing | High | High | Train staff | HR Team |
| Data breach | Medium | Very High | Encrypt data | IT Team |
| Insider threat | Low | High | Monitor access | Security Team |
| Denial of service | Medium | Medium | Use protection | IT Team |
| Feature | Threat | Vulnerability | Risk |
|---|---|---|---|
| Definition | Something that can cause harm | A weakness | Chance that harm will happen |
| Example | A hacker | A weak password | Hacker using weak password |
| Action | Reduce the threat | Fix the weakness | Manage the risk |
| Strategy | What It Means | Example |
|---|---|---|
| Avoid | Stop doing the risky thing | Do not use public Wi-Fi |
| Reduce | Make the risk smaller | Use antivirus software |
| Transfer | Give the risk to someone else | Get cyber insurance |
| Accept | Decide the risk is small | Use a weak password for a game |
Risk is the chance that something bad will happen. It is everywhere.
Cyber security risk is the chance that a hacker will cause harm. It is important because our lives are on computers.
A threat is something that can cause harm. A vulnerability is a weakness. A risk is the chance that a threat will use a vulnerability.
There are many types of cyber security risks: malware, phishing, ransomware, data breaches, insider threats, and denial of service.
Risk assessment is looking at risks and deciding how serious they are.
To assess risk, think about likelihood and impact.
A risk matrix helps you see which risks are most serious.
There are four risk management strategies: avoid, reduce, transfer, and accept.
Metrics help us measure risk. They tell us how likely a risk is and how bad it could be.
A risk register is a list of all risks, with information about each one.
Risk communication is telling people about risks in a simple way.
Nigerian banks, telecoms, government agencies, schools, and businesses all use risk management.
Risk management is everywhere, from video games to football.
Risk management is useful in everyday life, from crossing the road to going online.
A risk management plan explains how you will handle risks. It includes strategies, metrics, and responsibilities.
Congratulations! You have completed Module Three: Cyber Security Risk Management.
In this module, you learned that risk is the chance that something bad will happen. You learned that cyber security risk is the chance that a hacker will cause harm.
You learned about the difference between a threat, a vulnerability, and a risk.
You learned about the types of cyber security risks: malware, phishing, ransomware, data breaches, insider threats, and denial of service.
You learned about risk assessment. You learned that risk assessment uses likelihood and impact.
You learned about the risk matrix, which helps you prioritize risks.
You learned about four risk management strategies: avoid, reduce, transfer, and accept.
You learned how metrics help us measure risk.
You learned about the risk register, which is a list of all risks.
You learned about risk communication, which is telling people about risks simply.
You learned about Nigerian examples of risk management.
You learned about fun examples and everyday examples.
You learned how to build a risk management plan.
You are now a Cyber Security Risk Management Expert in training!
Risk is the chance that something bad will happen.
Cyber security risk is the chance that a hacker will break into your computer or steal your data.
A threat is something that can cause harm. A vulnerability is a weakness. A risk is the chance that a threat will use a vulnerability.
Risk assessment is looking at risks and deciding how serious they are.
A risk matrix is a table that helps you prioritize risks using likelihood and impact.
Avoid, reduce, transfer, and accept.
Metrics help us measure how likely a risk is and how bad it could be. They help us make smart decisions.
A risk register is a list of all risks, with information about each one.
Nigerian banks, telecoms, and government agencies use risk management to fight fraud and protect data.
Yes! You can use risk management to stay safe online and in everyday life.
| Word | Definition |
|---|---|
| 1. Risk | A. Something that can cause harm |
| 2. Threat | B. A weakness |
| 3. Vulnerability | C. The chance that something bad will happen |
| 4. Likelihood | D. How bad something will be |
| 5. Impact | E. How likely something is |
| 6. Risk Matrix | F. A list of all risks |
| 7. Risk Register | G. A table that helps prioritize risks |
Answers: 1-C, 2-A, 3-B, 4-E, 5-D, 6-G, 7-F
Your school computer lab has 50 computers. Last month, 10 computers got a virus. The school wants to reduce this risk.
Question: What risk management strategy should the school use?
Answer: The school should use the "reduce" strategy. They can install antivirus software, update software regularly, and teach students not to click on bad links.
Your family Wi-Fi has been slow. You suspect someone is using it without permission.
Question: What risk management strategy should your family use?
Answer: Your family should use the "reduce" strategy. They can change the Wi-Fi password to something strong and check who is connected.
A Nigerian bank wants to reduce fraud. They want to know how fast they detect fraud.
Question: What metrics should they use?
Answer: They should use Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). They should also track the number of fraud attempts blocked.
Instructions:
Time: 30 minutes
Instructions:
Goal: Create a risk management plan for your class.
Steps:
Time: 2 weeks
Instructions:
In Module Four, you will learn about Cyber Security Metrics and Risk Communication.
You will learn:
To prepare for Module Four, think about these questions:
See you in Module Four!
End of Module Three
Welcome to Module Four of your journey to becoming a Cyber Security Metrics Expert!
In Module One, you learned what cyber security is and why it matters. You learned that cyber security is like protecting a house from bad people who want to steal things or cause problems.
In Module Two, you learned about metrics. You learned that metrics are numbers that measure something. You learned that cyber security metrics help us understand how safe our computer systems are.
In Module Three, you learned about risk management. You learned that risk is the chance that something bad will happen. You learned how to identify risks, assess risks, and manage risks.
Now, in Module Four, you are going to learn about Cyber Security Metrics and Risk Communication.
What is risk communication?
Risk communication is telling people about risks in a way they can understand. It is about sharing information so that everyone can work together to stay safe.
Imagine you are the captain of a ship. You see a big storm coming. You need to tell the crew. If you say, "There is a severe meteorological disturbance approaching," they might not understand. If you say, "There is a big storm coming. We need to prepare. Put on your life jackets and secure the sails," they will understand.
Risk communication is about using simple words to explain risks. It is about helping people understand what the danger is and what they can do about it.
In cyber security, risk communication is very important. If people do not understand the risks, they cannot help. If they do not know what to do, they might make mistakes. Good risk communication helps everyone stay safe.
In this module, you will learn all about cyber security metrics and risk communication. You will learn how to use metrics to tell a story about risk. You will learn how to communicate risk to different people. You will learn how to create risk reports and dashboards. You will learn how to present risk information to leaders.
By the end of this module, you will be able to look at a cyber security report and understand what it is telling you. You will be able to explain risks to your friends, your family, and your teachers. You will be able to help your school, your family, or even a company understand how safe their computers are.
Let us begin this exciting journey together!
After completing this module, you will be able to:
Once upon a time, in a small village near the River Niger, there lived a wise chief named Chief Okafor. Chief Okafor loved his village. He wanted everyone to be safe and happy.
One day, a traveler came to the village. The traveler was very tired and very scared. He told Chief Okafor, "There is a big flood coming down the river. It will reach your village in three days. You must prepare."
Chief Okafor thanked the traveler. He called a village meeting. Everyone came: the farmers, the traders, the children, and the elders.
Chief Okafor stood up and said, "My people, there is a big flood coming. It will reach our village in three days. We need to prepare."
The people were scared. They started talking all at once. "What should we do?" "Where should we go?" "Will our houses be destroyed?"
Chief Okafor raised his hand. "Listen," he said. "We will prepare together. Here is the plan."
He drew a picture in the sand. It showed the river, the village, and the hill behind the village.
River
|
V
+-------------------+
| Village |
+-------------------+
|
V
+-------------------+
| Hill |
+-------------------+
"The flood will come from the river," Chief Okafor said. "It will cover the village. But the hill is high. The flood will not reach the hill. So we will move to the hill."
He continued, "We have three days. Here is what we will do:"
The people understood. They were still scared, but they knew what to do. They worked together. They gathered food. They moved animals. They moved to the hill.
On the third day, the flood came. It covered the village. But everyone was safe on the hill.
After the flood, Chief Okafor called another meeting. "My people," he said, "we survived because we communicated. I told you about the risk. I explained it simply. I gave you a plan. We worked together."
The people cheered. They learned a very important lesson. Risk communication saves lives.
That night, Chief Okafor told the children, "Communication is powerful. When you tell people about a risk in a way they understand, they can help. They can prepare. They can stay safe."
And that is exactly what you will learn in this module.
Risk communication is telling people about risks in a way they can understand. It is about sharing information so that everyone can work together to stay safe.
If people do not understand the risks, they cannot help. If they do not know what to do, they might make mistakes. Good risk communication helps everyone stay safe.
Imagine you are playing a game with your friends. You see a trap ahead. You need to tell your friends. If you say, "There is a trap," they will understand. If you say, "There is a potential hazardous situation," they might not understand. Risk communication is about using simple words.
A bank tells its customers: "Be careful of emails that ask for your password. We will never ask for your password by email. If you get such an email, do not reply. Report it to us."
Your school tells students: "Do not share your password with anyone. Even your best friend. If someone has your password, they can see your grades and change them."
Your parents tell you: "Do not click on links in messages from people you do not know. They might be trying to steal our information."
A Nigerian bank tells its customers: "Never share your OTP with anyone. Not even someone who says they are from the bank. If you share it, you might lose your money."
Risk Communication
|
V
+-------------------+
| Identify Risk |
+-------------------+
|
V
+-------------------+
| Explain Simply |
+-------------------+
|
V
+-------------------+
| Tell People What |
| To Do |
+-------------------+
|
V
+-------------------+
| Everyone Stays |
| Safe |
+-------------------+
Risk communication is telling people about risks in a simple way. It helps everyone work together to stay safe.
Risk communication matters because it helps people understand dangers and take action. Without it, people might ignore risks or panic.
If people do not know about a risk, they cannot protect themselves. If they do not understand the risk, they might do the wrong thing. Good communication helps people make smart choices.
Imagine there is a fire in a building. If no one tells the people inside, they might not know to leave. If someone shouts, "Fire! Leave the building!" everyone will understand and act. Risk communication is like that shout. It tells people what is happening and what to do.
A hospital tells its staff: "There is a new virus going around. Wash your hands often. Wear a mask. Stay home if you are sick." This communication helps keep everyone safe.
Your school tells students: "There is a new rule. Do not use your phone during exams. If you are caught, you will fail." This communication helps students follow the rules.
Your parents tell you: "Do not open the door for strangers. If someone knocks, call us first." This communication helps keep you safe.
A Nigerian bank tells its customers: "There is a new scam. Fraudsters are sending fake emails. Do not click on links. Call us if you are not sure." This communication helps customers avoid losing money.
Why Risk Communication Matters
|
V
+-------------------+
| People Don't Know|
| About Risk |
+-------------------+
|
V
+-------------------+
| They Cannot |
| Protect Themselves|
+-------------------+
|
V
+-------------------+
| Risk Communication|
| Tells Them |
+-------------------+
|
V
+-------------------+
| They Stay Safe |
+-------------------+
Risk communication matters because it helps people understand dangers and take action. It helps people stay safe.
Your audience is the people you are communicating with. Different audiences need different types of communication.
If you talk to a child the same way you talk to a teacher, the child might not understand. If you talk to a teacher the same way you talk to a child, the teacher might feel insulted. Knowing your audience helps you communicate better.
Imagine you want to explain a football game to someone. If you are explaining to a football player, you can use words like "offside" and "penalty." If you are explaining to someone who has never watched football, you need to use simple words.
In cyber security, you might communicate with:
A bank communicates with customers using simple words. They communicate with technical experts using detailed reports. They communicate with leaders using summaries and metrics.
Your school communicates with students using simple words. They communicate with teachers using detailed information. They communicate with parents using letters and meetings.
Your parents communicate with you using simple words. They communicate with other adults using more detailed words.
A Nigerian bank communicates with customers in English, Pidgin, and local languages. They use simple words so everyone can understand.
Know Your Audience
|
V
+-------------------+
| Children: Simple |
| Words, Fun |
+-------------------+
|
V
+-------------------+
| Teachers: Clear |
| Words, School |
+-------------------+
|
V
+-------------------+
| Parents: Practical|
| Words, Home |
+-------------------+
|
V
+-------------------+
| Leaders: Business|
| Words, Metrics |
+-------------------+
Know your audience. Different people need different types of communication. Use simple words for children. Use business words for leaders.
Using metrics to tell a story means taking the numbers and explaining what they mean in a way that people can understand.
Numbers alone can be boring. But when you tell a story with the numbers, people understand better. They can see why the metrics matter.
Instead of saying, "We had 100 attacks last month," you could say, "Last month, we faced 100 attacks. We stopped 99 of them. But 1 got through. That 1 attack cost us 5 million naira. If we train our staff, we can stop all attacks and save money."
The second version tells a story. It explains why the numbers matter.
A security team tells their boss: "Last year, we had 50 attacks. We responded in 10 hours on average. This year, we had 100 attacks, but we responded in 2 hours on average. We are getting faster, but we are also getting more attacks. We need more staff."
A student tells the principal: "Last term, only 20% of students used strong passwords. This term, after our campaign, 60% use strong passwords. We are improving, but we want to reach 100%."
A child tells their parents: "Last month, we had 5 devices without antivirus. Now we have 0. Our home network is safer."
A Nigerian bank tells its customers: "Last year, we blocked 10,000 fraudulent transactions. This year, we blocked 25,000. We are protecting your money better."
Using Metrics to Tell a Story
|
V
+-------------------+
| Collect Numbers |
+-------------------+
|
V
+-------------------+
| Find Meaning |
+-------------------+
|
V
+-------------------+
| Explain to People|
+-------------------+
|
V
+-------------------+
| Inspire Action |
+-------------------+
Using metrics to tell a story means explaining what the numbers mean. It helps people understand why the metrics matter.
A risk report is a document that explains the risks a person or company faces. It includes metrics and recommendations.
A risk report helps leaders understand the risks. It helps them make decisions. It helps them know where to spend money.
A risk report has these parts:
A bank's risk report might say: "We face risks from hackers, phishing, and insider threats. Last month, we blocked 1,000 attacks. But 2 got through. We recommend training all staff and updating our software."
Your school's risk report might say: "We face risks from password sharing and malware. Last term, 30% of students shared passwords. We recommend a password safety campaign."
Your family's risk report might say: "We face risks from weak Wi-Fi passwords and phishing. Last month, we received 5 suspicious messages. We recommend changing the Wi-Fi password and teaching everyone about phishing."
A Nigerian company's risk report might say: "We face risks from phishing and fake orders. Last quarter, we received 100 phishing emails. 10 employees clicked. We recommend training all employees."
Risk Report Structure
|
V
+-------------------+
| Title |
+-------------------+
|
V
+-------------------+
| Summary |
+-------------------+
|
V
+-------------------+
| Risks |
+-------------------+
|
V
+-------------------+
| Metrics |
+-------------------+
|
V
+-------------------+
| Recommendations |
+-------------------+
|
V
+-------------------+
| Conclusion |
+-------------------+
A risk report explains risks, includes metrics, and gives recommendations. It helps leaders make decisions.
A risk dashboard is a screen or page that shows all your important risk metrics in one place.
Instead of looking at many different reports, a dashboard shows you everything at a glance. It helps you quickly see if there is a problem.
Think about the dashboard in a car. It shows you the speed, the fuel level, and the temperature. You can see everything important in one place. A risk dashboard does the same thing for cyber security risks.
A company might have a risk dashboard that shows:
Your school might have a dashboard that shows how many students completed cyber security training and how many computers have antivirus.
Your family might have a simple dashboard that shows how many devices have strong passwords and how many updates are pending.
A Nigerian bank might have a dashboard that shows the number of fraudulent transactions blocked, the number of customer reports, and the average response time.
Risk Dashboard
+------------------------------------------+
| Attacks Blocked Today: 1,234 |
| Attacks Got Through: 2 |
| Average Detect Time: 15 mins |
| Average Respond Time: 30 mins |
| Computers Updated: 95% |
| Staff Trained: 80% |
+------------------------------------------+
A risk dashboard shows all your important metrics in one place. It helps you see the big picture quickly.
Presenting risk to leaders means explaining risks to people who make decisions. Leaders need clear information to make good choices.
Leaders control money and resources. If they do not understand the risks, they might not spend money on security. If they understand, they can make smart decisions.
When you present to leaders, remember these rules:
A security team tells the CEO: "We face a high risk from phishing. Last month, 10 employees clicked on fake emails. If a hacker gets in, we could lose 50 million naira. We recommend training all employees. The training will cost 1 million naira. It will save us 50 million naira."
A student tells the principal: "We face a risk from password sharing. 30% of students share passwords. If a hacker gets in, they could change grades. We recommend a password safety campaign."
A child tells their parents: "We face a risk from weak Wi-Fi passwords. If a hacker gets in, they could steal our information. We recommend changing the password."
A Nigerian company tells its board: "We face a risk from fake orders. Last quarter, we lost 5 million naira to fake orders. We recommend checking all payments carefully. This will save us money."
Presenting Risk to Leaders
|
V
+-------------------+
| Be Brief |
+-------------------+
|
V
+-------------------+
| Use Numbers |
+-------------------+
|
V
+-------------------+
| Show Impact |
+-------------------+
|
V
+-------------------+
| Give Recommendations|
+-------------------+
|
V
+-------------------+
| Be Honest |
+-------------------+
When presenting risk to leaders, be brief, use numbers, show impact, give recommendations, and be honest.
Using simple language means avoiding complicated words. It means explaining things in a way that everyone can understand.
If people do not understand your words, they cannot understand the risk. Simple language helps everyone.
Instead of saying "The system has been compromised by a malicious actor," say "A hacker broke into our computer."
Instead of saying "We need to mitigate the vulnerability," say "We need to fix the weakness."
Instead of saying "The probability of a data breach is high," say "There is a high chance that someone will steal our data."
A bank tells its customers: "Do not share your password. If someone has your password, they can take your money." This is simple and clear.
Your school tells students: "Do not click on strange links. They can give your computer a virus." This is simple and clear.
Your parents tell you: "Do not tell anyone your password. Even your friends." This is simple and clear.
A Nigerian bank tells its customers: "Never share your OTP. If you share it, you will lose your money." This is simple and clear.
Using Simple Language
|
V
+-------------------+
| Complicated Word |
| "Mitigate" |
+-------------------+
|
V
+-------------------+
| Simple Word |
| "Fix" |
+-------------------+
|
V
+-------------------+
| Everyone |
| Understands |
+-------------------+
Use simple language. Avoid complicated words. Explain things in a way that everyone can understand.
Good risk communication helps people understand and act. Bad risk communication confuses people or makes them panic.
If you communicate badly, people might ignore the risk. Or they might panic. Good communication helps people stay calm and take action.
Good risk communication is:
Bad risk communication is:
Good: "There is a new virus. Wash your hands often. Stay home if you are sick."
Bad: "There is a terrible virus. We are all going to die. There is nothing we can do."
Good: "There is a new rule. Do not use your phone during exams. If you are caught, you will fail."
Bad: "Phones are banned. If we see your phone, you will be in big trouble."
Good: "Do not open the door for strangers. Call us first."
Bad: "Never open the door. Strangers will hurt you."
Good: "Be careful of fake emails. Do not click on links. Call us if you are not sure."
Bad: "Hackers are everywhere. They will steal your money. You cannot stop them."
Good vs. Bad Risk Communication
|
V
+-------------------+ +-------------------+
| GOOD | | BAD |
+-------------------+ +-------------------+
| - Clear | | - Confusing |
| - Honest | | - Dishonest |
| - Timely | | - Late |
| - Actionable | | - Not actionable |
| - Calm | | - Panicky |
+-------------------+ +-------------------+
| |
V V
+-------------------+ +-------------------+
| People Understand | | People Panic or |
| and Act | | Ignore |
+-------------------+ +-------------------+
Good risk communication is clear, honest, timely, actionable, and calm. Bad risk communication is confusing, dishonest, late, not actionable, and panicky.
Risk communication is used all over the world, including in Nigeria. Here are some Nigerian examples.
Seeing examples from Nigeria helps you understand how risk communication works in your own country.
Here are some Nigerian examples:
A Nigerian bank might send a text message: "Dear customer, beware of fake emails asking for your password. We will never ask for your password. Do not reply. Call us if you are not sure."
A Nigerian school might tell students: "Do not share your password with anyone. If someone has your password, they can change your grades. Keep your password safe."
A Nigerian family might tell their children: "Do not click on strange links. They can give your phone a virus. If you see a strange link, tell us."
NITDA might post on social media: "Be careful of fake websites. They look like real websites, but they are not. Always check the website address before you enter your password."
Nigerian Risk Communication
+------------------------------------------+
| Banks: Text messages about fraud |
| Telecoms: Messages about SIM fraud |
| Government: Social media warnings |
| Schools: Assemblies about passwords |
| Businesses: Messages about fake orders |
+------------------------------------------+
Nigerian banks, telecoms, government agencies, schools, and businesses all use risk communication to keep people safe.
Risk communication can be explained using fun examples that children understand.
When you use fun examples, learning becomes easier and more enjoyable.
Here are some fun examples:
Imagine you are playing a game where you have to protect a castle. You see enemies coming. You tell your team, "Enemies are coming from the left! We need to defend the left side!" This is risk communication.
Your teacher tells the class, "There will be a fire drill tomorrow. When you hear the alarm, line up quietly and walk outside." This is risk communication.
Your parents tell you, "Do not tell anyone on the phone that you are alone at home. Say your parents are busy." This is risk communication.
In a Nigerian football match, the coach tells the players, "The other team has a very good striker. Watch him closely." This is risk communication.
Fun Risk Communication
+------------------------------------------+
| Video Game: "Watch out! Monster!" |
| Football: "Watch number 10!" |
| Social Media: "Do not click that link!" |
| School: "Study hard. Exam is tough!" |
| Cooking: "Do not touch. It is hot!" |
+------------------------------------------+
Risk communication is everywhere. It is in video games, football, social media, school, and cooking. Cyber security risk communication is just another type.
Risk communication is not just for big companies. It is also useful in everyday life.
When you understand risk communication in everyday life, you can use it to stay safe.
Here are everyday examples:
You communicate risk when you tell your friend, "Do not eat that food. It smells bad. You might get sick."
Your school communicates risk when they tell students, "Do not run in the hallway. You might fall and get hurt."
Your family communicates risk when they tell you, "Do not touch the stove. It is hot."
A Nigerian family communicates risk when they tell their children, "Do not go out at night. It is not safe."
Everyday Risk Communication
+------------------------------------------+
| Crossing Road: "Look both ways!" |
| Riding Bike: "Wear a helmet!" |
| Using Phone: "Not while crossing!" |
| Going Online: "Do not share info!" |
| Sharing Info: "Keep it secret!" |
+------------------------------------------+
Risk communication is useful in everyday life. You can communicate risk when crossing the road, riding a bike, using a phone, going online, and sharing information.
A risk communication plan is a document that explains how you will communicate about risks.
A plan helps you stay organized. It helps you remember what to say. It helps you reach the right people.
A risk communication plan has these parts:
A bank's risk communication plan includes:
Your school's risk communication plan includes:
Your family's risk communication plan includes:
A Nigerian company's risk communication plan includes:
Risk Communication Plan
|
V
+-------------------+
| Audience |
+-------------------+
|
V
+-------------------+
| Message |
+-------------------+
|
V
+-------------------+
| Channel |
+-------------------+
|
V
+-------------------+
| Timing |
+-------------------+
|
V
+-------------------+
| Metrics |
+-------------------+
A risk communication plan explains who you will communicate with, what you will say, how you will say it, when you will say it, and how you will measure success.
Measuring risk communication success means checking if your communication worked. Did people understand? Did they take action?
If you do not measure success, you do not know if your communication is helping. Measuring helps you improve.
You can measure risk communication success with metrics:
A bank measures: "We sent 10,000 text messages. 8,000 customers read them. 5,000 customers reported fewer fraud attempts. Our communication worked."
Your school measures: "We held an assembly. 90% of students attended. 80% of students can explain why password sharing is bad. Our communication worked."
Your family measures: "We had a meeting. Everyone attended. Everyone knows not to click on strange links. Our communication worked."
A Nigerian company measures: "We sent a training email. 70% of employees completed the training. Phishing reports increased. Our communication worked."
Measuring Risk Communication Success
|
V
+-------------------+
| Reach |
+-------------------+
|
V
+-------------------+
| Understanding |
+-------------------+
|
V
+-------------------+
| Action |
+-------------------+
|
V
+-------------------+
| Change |
+-------------------+
Measure risk communication success by checking reach, understanding, action, and change. This helps you improve.
A case study is a real-life example that helps us learn. Let us look at a Nigerian bank.
Case studies help us see how risk communication works in real life.
A Nigerian bank noticed that many customers were losing money to fraud. Fraudsters were sending fake emails and text messages. The bank decided to improve its risk communication.
Here is what they did:
After six months, the bank saw results:
The bank learned that good risk communication saves money and protects customers.
The bank shared its success with other banks. They all started using simple messages and multiple channels.
Your school can use the same approach. Identify the audience (students), create a simple message ("Do not share your password"), use multiple channels (assembly, posters, emails), and measure success (fewer password sharing incidents).
Your family can use the same approach. Identify the audience (family members), create a simple message ("Do not click on strange links"), use multiple channels (family meeting, text messages), and measure success (fewer suspicious links clicked).
Nigerian banks like GTBank, Zenith, and Access Bank all use similar risk communication strategies. They send regular messages and track their success.
Case Study: Nigerian Bank
|
V
+-------------------+
| Problem: Fraud |
+-------------------+
|
V
+-------------------+
| Solution: Risk |
| Communication |
+-------------------+
|
V
+-------------------+
| Audience, Message,|
| Channel, Timing, |
| Metrics |
+-------------------+
|
V
+-------------------+
| Result: 40% less |
| fraud, happier |
| customers |
+-------------------+
A Nigerian bank used risk communication to reduce fraud by 40%. They identified their audience, created simple messages, used multiple channels, and measured success.
| Word | Simple Definition |
|---|---|
| Risk Communication | Telling people about risks in a way they can understand |
| Audience | The people you are communicating with |
| Message | What you want to say |
| Channel | How you communicate (email, text, meeting) |
| Metrics | Numbers that measure something |
| Risk Report | A document that explains risks |
| Risk Dashboard | A screen that shows all important risk metrics |
| Simple Language | Words that everyone can understand |
| Reach | How many people received your message |
| Understanding | How many people understood your message |
| Action | What people do after receiving your message |
| Case Study | A real-life example that helps us learn |
| OTP | One Time Password - a special code for one use |
| Fraud | Tricking people to steal money |
| Phishing | Fake emails or messages that try to steal information |
A bank in Lagos uses risk communication to warn customers about fraud. They send text messages, emails, and social media posts. They use simple words. They track how many customers report fraud. They measure their success.
A school in Abuja uses risk communication to teach students about password safety. They hold assemblies, put up posters, and send emails to parents. They use simple words. They track how many students share passwords. They measure their success.
A family in Port Harcourt uses risk communication to stay safe online. They have family meetings, send text messages, and put up reminders. They use simple words. They track how many suspicious messages they receive. They measure their success.
Banks like GTBank, Zenith, and Access Bank use risk communication to warn customers about fraud. They send text messages and emails with simple warnings.
Companies like MTN, Glo, and Airtel use risk communication to warn customers about SIM card fraud. They send messages like "Never share your SIM with anyone."
NITDA uses risk communication to warn the public about cyber attacks. They post warnings on social media and websites.
Schools like Covenant University and University of Lagos use risk communication to teach students about password safety. They hold assemblies and send emails.
Companies like Jumia and Konga use risk communication to warn customers about fake orders. They send messages like "Always check the seller before you pay."
In a video game, you warn your teammates about enemies. You say, "Watch out! There is a monster behind you!" That is risk communication.
In football, the coach warns the team about the other team's best player. He says, "Watch number 10. He is very fast." That is risk communication.
On social media, you warn your friends about a scam. You say, "Do not click on that link. It is fake." That is risk communication.
In school, the teacher warns students about a difficult exam. She says, "Study hard. The exam will be tough." That is risk communication.
Your parents tell you, "Look both ways before you cross." This is risk communication.
Your parents tell you, "Wear a helmet. It will protect your head." This is risk communication.
Your parents tell you, "Do not use your phone while crossing the road." This is risk communication.
Your teacher tells you, "Do not share your personal information online." This is risk communication.
Your friend tells you, "Do not tell anyone my secret." This is risk communication.
+-------------------+
| Identify Risk |
+-------------------+
|
V
+-------------------+
| Know Audience |
+-------------------+
|
V
+-------------------+
| Create Message |
+-------------------+
|
V
+-------------------+
| Choose Channel |
+-------------------+
|
V
+-------------------+
| Communicate |
+-------------------+
|
V
+-------------------+
| Measure Success |
+-------------------+
|
V
+-------------------+
| Improve |
+-------------------+
Past Present Future
| | |
V V V
+----------------+ +----------------+ +----------------+
| Identify Risk | | Communicate | | Measure |
| | | Risk | | Success |
+----------------+ +----------------+ +----------------+
| | |
V V V
+----------------+ +----------------+ +----------------+
| List all risks | | Simple message | | Reach, |
| | | | | Understanding, |
| | | | | Action, Change |
+----------------+ +----------------+ +----------------+
| Audience | Message | Channel | Timing | Metrics |
|---|---|---|---|---|
| Customers | Never share your password | Text, Email | Weekly | Number of fraud reports |
| Students | Do not share your password | Assembly, Posters | Every term | Number of password sharing |
| Family | Do not click strange links | Meeting, Text | Monthly | Number of suspicious links |
| Employees | Report phishing emails | Email, Training | Quarterly | Number of reports |
| Feature | Good | Bad |
|---|---|---|
| Clarity | Clear | Confusing |
| Honesty | Honest | Dishonest |
| Timing | Timely | Late |
| Action | Actionable | Not actionable |
| Calm | Calm | Panicky |
| Audience | Style | Example |
|---|---|---|
| Children | Simple words, fun examples | "Do not share your password. It is like your toothbrush. Keep it to yourself." |
| Teachers | Clear words, school examples | "Password sharing can lead to grade changes. Teach students to keep passwords safe." |
| Parents | Practical words, home examples | "Check your children's devices. Make sure they use strong passwords." |
| Leaders | Business words, metrics | "We blocked 1,000 attacks. We saved 50 million naira. We need more training." |
| Experts | Technical words, details | "The MTTD is 15 minutes. The MTTR is 30 minutes. We need to improve." |
Risk communication is telling people about risks in a simple way. It helps everyone work together to stay safe.
Risk communication matters because it helps people understand dangers and take action. It helps people stay safe.
Know your audience. Different people need different types of communication. Use simple words for children. Use business words for leaders.
Using metrics to tell a story means explaining what the numbers mean. It helps people understand why the metrics matter.
A risk report explains risks, includes metrics, and gives recommendations. It helps leaders make decisions.
A risk dashboard shows all your important metrics in one place. It helps you see the big picture quickly.
When presenting risk to leaders, be brief, use numbers, show impact, give recommendations, and be honest.
Use simple language. Avoid complicated words. Explain things in a way that everyone can understand.
Good risk communication is clear, honest, timely, actionable, and calm. Bad risk communication is confusing, dishonest, late, not actionable, and panicky.
Nigerian banks, telecoms, government agencies, schools, and businesses all use risk communication to keep people safe.
Risk communication is everywhere. It is in video games, football, social media, school, and cooking.
Risk communication is useful in everyday life. You can communicate risk when crossing the road, riding a bike, using a phone, going online, and sharing information.
A risk communication plan explains who you will communicate with, what you will say, how you will say it, when you will say it, and how you will measure success.
Measure risk communication success by checking reach, understanding, action, and change. This helps you improve.
A Nigerian bank used risk communication to reduce fraud by 40%. They identified their audience, created simple messages, used multiple channels, and measured success.
Congratulations! You have completed Module Four: Cyber Security Metrics and Risk Communication.
In this module, you learned that risk communication is telling people about risks in a simple way. You learned that it helps everyone work together to stay safe.
You learned why risk communication matters. It helps people understand dangers and take action.
You learned how to know your audience. Different people need different types of communication.
You learned how to use metrics to tell a story. Numbers alone are boring. Stories make them meaningful.
You learned how to create a risk report. A risk report explains risks, includes metrics, and gives recommendations.
You learned how to create a risk dashboard. A dashboard shows all important metrics in one place.
You learned how to present risk to leaders. Be brief, use numbers, show impact, give recommendations, and be honest.
You learned how to use simple language. Avoid complicated words.
You learned about good and bad risk communication. Good communication is clear, honest, timely, actionable, and calm.
You learned about Nigerian examples of risk communication.
You learned about fun examples and everyday examples.
You learned how to build a risk communication plan.
You learned how to measure risk communication success.
You learned from a case study of a Nigerian bank that reduced fraud by 40%.
You are now a Cyber Security Risk Communication Expert in training!
Risk communication is telling people about risks in a way they can understand.
It helps people understand dangers and take action. It helps people stay safe.
Your audience is the people you are communicating with. It could be children, teachers, parents, leaders, or experts.
Take the numbers and explain what they mean. Show how they affect people and what should be done.
A risk report is a document that explains risks, includes metrics, and gives recommendations.
A risk dashboard is a screen that shows all important risk metrics in one place.
Be brief, use numbers, show impact, give recommendations, and be honest.
If people do not understand your words, they cannot understand the risk. Simple language helps everyone.
Measure reach, understanding, action, and change.
Nigerian banks, telecoms, and government agencies use risk communication to warn people about fraud and cyber attacks.
| Word | Definition |
|---|---|
| 1. Risk Communication | A. The people you are communicating with |
| 2. Audience | B. How you communicate |
| 3. Message | C. Telling people about risks simply |
| 4. Channel | D. What you want to say |
| 5. Metrics | E. A screen that shows important metrics |
| 6. Risk Report | F. Numbers that measure something |
| 7. Risk Dashboard | G. A document that explains risks |
Answers: 1-C, 2-A, 3-D, 4-B, 5-F, 6-G, 7-E
Your school wants to communicate the risk of password sharing to students.
Question: What message should the school use? What channel?
Answer: The message should be simple: "Do not share your password. If someone has your password, they can change your grades." The channel could be an assembly, posters, and emails to parents.
Your family wants to communicate the risk of phishing to everyone.
Question: What message should the family use? What channel?
Answer: The message should be simple: "Do not click on strange links. They can steal our information." The channel could be a family meeting and text messages.
A Nigerian bank wants to communicate the risk of OTP fraud to customers.
Question: What message should the bank use? What channel?
Answer: The message should be simple: "Never share your OTP. If you share it, you will lose your money." The channel could be text messages, emails, and social media.
Instructions:
Time: 30 minutes
Instructions:
Goal: Create a dashboard that shows how well your class communicates about risk.
Steps:
Time: 2 weeks
Instructions:
In Module Five, you will learn about Cyber Security Metrics and Incident Response.
You will learn:
To prepare for Module Five, think about these questions:
See you in Module Five!
End of Module Four
Welcome to Module Five of your journey to becoming a Cyber Security Metrics Expert!
In Module One, you learned what cyber security is and why it matters. You learned that cyber security is like protecting a house from bad people who want to steal things or cause problems.
In Module Two, you learned about metrics. You learned that metrics are numbers that measure something. You learned that cyber security metrics help us understand how safe our computer systems are.
In Module Three, you learned about risk management. You learned that risk is the chance that something bad will happen. You learned how to identify risks, assess risks, and manage risks.
In Module Four, you learned about risk communication. You learned how to tell people about risks in a simple way. You learned how to use metrics to tell a story. You learned how to create risk reports and dashboards.
Now, in Module Five, you are going to learn about Cyber Security Metrics and Incident Response.
What is an incident?
An incident is something bad that happens. It is an event that causes harm or could cause harm. In cyber security, an incident is when a hacker breaks in, a virus infects a computer, or data is stolen.
What is incident response?
Incident response is what we do when an incident happens. It is our plan for dealing with the problem. It is how we detect the incident, stop it, fix it, and recover.
Imagine you are playing a football match. Suddenly, the other team scores a goal. That is an incident. What do you do? You do not panic. You follow your plan. You might change your tactics. You might substitute a player. You might encourage your team. That is incident response.
In cyber security, incident response is the same. When a hacker attacks, we do not panic. We follow our plan. We detect the attack. We stop the attack. We fix the damage. We recover. We learn from what happened.
Metrics are very important in incident response. They help us measure how well we are doing. They tell us how fast we detect incidents. They tell us how fast we respond. They tell us how much damage was caused. They help us improve.
In this module, you will learn all about cyber security metrics and incident response. You will learn how to prepare for incidents. You will learn how to detect incidents. You will learn how to respond to incidents. You will learn how to recover from incidents. You will learn how metrics help us measure our success.
By the end of this module, you will be able to look at an incident and know what to do. You will be able to use metrics to measure your response. You will be able to help your school, your family, or even a company respond to cyber incidents.
Let us begin this exciting journey together!
After completing this module, you will be able to:
Once upon a time, in the bustling city of Abuja, Nigeria, there was a school called Bright Future Academy. The school had many computers. Students used them for learning, research, and fun.
One Monday morning, something terrible happened. All the computers stopped working. The screens went black. No one could log in. The teachers were confused. The students were scared.
The principal, Mrs. Adeyemi, called the computer teacher, Mr. Okonkwo. "What is happening?" she asked.
Mr. Okonkwo looked at the computers. He saw a message on one screen. It said: "Your files have been locked. Pay 5 million naira or lose everything."
Mr. Okonkwo's face turned white. "We have been attacked," he said. "This is ransomware."
Mrs. Adeyemi took a deep breath. "What do we do?" she asked.
Mr. Okonkwo said, "We follow our incident response plan. Remember? We practiced this last term."
Mrs. Adeyemi nodded. She remembered. The school had a plan for incidents like this. They had prepared. They had practiced.
Here is what they did:
By 3:00 PM, the computers were working again. No money was paid. No data was lost.
Mrs. Adeyemi called a school assembly. She told the students, "Today, we faced an incident. But we were prepared. We had a plan. We followed the plan. We used metrics to measure our success. We detected the attack in 15 minutes. We responded in 30 minutes. We recovered in 6 hours. We learned from our mistake."
The students clapped. They learned a very important lesson. Incident response saves the day.
That night, Mrs. Adeyemi told her own children, "Preparation is key. If you prepare for an incident, you can handle it. If you do not prepare, you will panic."
And that is exactly what you will learn in this module.
An incident is something bad that happens. It is an event that causes harm or could cause harm. In cyber security, an incident is when a hacker breaks in, a virus infects a computer, or data is stolen.
If you do not know what an incident is, you cannot respond to it. Knowing what an incident is helps you prepare.
Imagine you are riding your bike. Suddenly, the tire goes flat. That is an incident. It is something bad that happened. You need to fix it. In cyber security, an incident is the same. It is something bad that happened to your computer.
A bank has an incident when a hacker steals customer money. A hospital has an incident when a virus locks patient records. A school has an incident when a student's password is stolen.
Your school has an incident when a computer gets a virus. Your school has an incident when someone hacks the school website. Your school has an incident when student data is stolen.
Your home has an incident when your Wi-Fi is hacked. Your home has an incident when your phone gets a virus. Your home has an incident when someone steals your password.
A Nigerian bank has an incident when fraudsters steal money. A Nigerian telecom has an incident when fake SIM cards are used. A Nigerian government agency has an incident when its website is attacked.
What is an Incident?
|
V
+-------------------+
| Something Bad |
| Happens |
+-------------------+
|
V
+-------------------+
| Harm is Caused |
+-------------------+
|
V
+-------------------+
| You Need to |
| Respond |
+-------------------+
An incident is something bad that happens. In cyber security, it is when a hacker breaks in, a virus infects a computer, or data is stolen.
Incident response is what we do when an incident happens. It is our plan for dealing with the problem. It is how we detect the incident, stop it, fix it, and recover.
If you do not have a plan, you will panic. If you panic, you might make mistakes. A good incident response plan helps you stay calm and fix the problem quickly.
Imagine there is a fire in your house. What do you do? You do not panic. You follow your fire plan. You call the fire service. You leave the house. You stay calm. Incident response is the same. It is your plan for dealing with cyber incidents.
A bank has an incident response plan. When a hacker attacks, they follow the plan. They detect the attack. They stop the attack. They fix the damage. They recover. They learn.
Your school has an incident response plan. When a virus infects the computers, they follow the plan. They disconnect the computers. They remove the virus. They restore the files. They learn.
Your family has an incident response plan. When your Wi-Fi is hacked, they follow the plan. They change the password. They check the devices. They learn.
A Nigerian bank has an incident response plan. When fraudsters attack, they follow the plan. They block the transactions. They alert customers. They recover the money. They learn.
What is Incident Response?
|
V
+-------------------+
| Incident Happens |
+-------------------+
|
V
+-------------------+
| Follow the Plan |
+-------------------+
|
V
+-------------------+
| Detect, Stop, |
| Fix, Recover |
+-------------------+
|
V
+-------------------+
| Learn and Improve|
+-------------------+
Incident response is what we do when an incident happens. It is our plan for dealing with the problem.
Incident response has several phases. Each phase is a step in the process.
If you follow the phases, you can handle any incident. You will not forget anything. You will not panic.
Here are the phases of incident response:
| Phase | What It Means |
|---|---|
| 1. Preparation | Get ready before an incident happens |
| 2. Detection | Notice that an incident has happened |
| 3. Containment | Stop the incident from spreading |
| 4. Eradication | Remove the cause of the incident |
| 5. Recovery | Restore normal operations |
| 6. Learning | Learn from the incident and improve |
A bank follows these phases. They prepare by training staff. They detect attacks using monitoring tools. They contain attacks by disconnecting systems. They eradicate attacks by removing malware. They recover by restoring data. They learn by writing reports.
Your school follows these phases. They prepare by teaching students. They detect viruses using antivirus. They contain viruses by disconnecting computers. They eradicate viruses by cleaning them. They recover by restoring files. They learn by writing reports.
Your family follows these phases. They prepare by using strong passwords. They detect problems by checking devices. They contain problems by disconnecting from Wi-Fi. They eradicate problems by removing viruses. They recover by restoring data. They learn by talking about what happened.
A Nigerian bank follows these phases. They prepare by training staff. They detect fraud using monitoring tools. They contain fraud by blocking transactions. They eradicate fraud by removing the fraudster. They recover by returning money. They learn by writing reports.
Phases of Incident Response
|
V
+-------------------+
| 1. Preparation |
+-------------------+
|
V
+-------------------+
| 2. Detection |
+-------------------+
|
V
+-------------------+
| 3. Containment |
+-------------------+
|
V
+-------------------+
| 4. Eradication |
+-------------------+
|
V
+-------------------+
| 5. Recovery |
+-------------------+
|
V
+-------------------+
| 6. Learning |
+-------------------+
Incident response has six phases: preparation, detection, containment, eradication, recovery, and learning.
Preparation is getting ready before an incident happens. It is the first phase of incident response.
If you are not prepared, you will panic. If you are prepared, you can handle the incident calmly.
Imagine you are going on a trip. You pack your bags. You check the weather. You plan your route. That is preparation. In cyber security, preparation means having a plan, training people, and using good tools.
A bank prepares by training staff, installing firewalls, and making backups. They also practice incident response drills.
Your school prepares by teaching students about cyber security, installing antivirus, and making backups.
Your family prepares by using strong passwords, updating software, and making backups.
A Nigerian bank prepares by training staff, using fraud detection tools, and making backups.
Preparation
|
V
+-------------------+
| Make a Plan |
+-------------------+
|
V
+-------------------+
| Train People |
+-------------------+
|
V
+-------------------+
| Use Good Tools |
+-------------------+
|
V
+-------------------+
| Practice Drills |
+-------------------+
Preparation is getting ready before an incident happens. It means having a plan, training people, and using good tools.
Detection is noticing that an incident has happened. It is the second phase of incident response.
The faster you detect an incident, the faster you can respond. If you do not detect it, the damage can get worse.
Imagine you are in a room and you smell smoke. You detect that there is a fire. If you did not smell the smoke, you might not know about the fire. In cyber security, detection means noticing that something is wrong.
A bank detects an attack when their monitoring tools alert them. They also detect attacks when customers report fraud.
Your school detects a virus when antivirus software alerts them. They also detect a virus when computers start acting strangely.
Your family detects a problem when the Wi-Fi is slow. They also detect a problem when they receive strange messages.
A Nigerian bank detects fraud when their monitoring tools alert them. They also detect fraud when customers call to report strange transactions.
Detection
|
V
+-------------------+
| Something is |
| Wrong |
+-------------------+
|
V
+-------------------+
| You Notice It |
+-------------------+
|
V
+-------------------+
| You Confirm It |
+-------------------+
|
V
+-------------------+
| You Report It |
+-------------------+
Detection is noticing that an incident has happened. The faster you detect it, the faster you can respond.
Containment is stopping the incident from spreading. It is the third phase of incident response.
If you do not contain the incident, it can spread and cause more damage. Containment limits the damage.
Imagine there is a fire in one room. You close the door to stop the fire from spreading to other rooms. That is containment. In cyber security, containment means stopping the attack from spreading to other computers.
A bank contains an attack by disconnecting affected computers from the network. They also block the hacker's access.
Your school contains a virus by disconnecting infected computers from the network. They also stop students from using those computers.
Your family contains a problem by disconnecting from Wi-Fi. They also change the Wi-Fi password.
A Nigerian bank contains fraud by blocking the fraudster's account. They also stop all transactions from that account.
Containment
|
V
+-------------------+
| Incident Happens |
+-------------------+
|
V
+-------------------+
| Stop It From |
| Spreading |
+-------------------+
|
V
+-------------------+
| Disconnect, Block|
+-------------------+
|
V
+-------------------+
| Limit the Damage |
+-------------------+
Containment is stopping the incident from spreading. It limits the damage.
Eradication is removing the cause of the incident. It is the fourth phase of incident response.
If you do not remove the cause, the incident can happen again. Eradication fixes the problem.
Imagine you have weeds in your garden. You pull them out. That is eradication. In cyber security, eradication means removing the virus, deleting the malware, or fixing the weakness.
A bank eradicates an attack by removing the malware from their computers. They also fix the weakness that allowed the attack.
Your school eradicates a virus by cleaning the infected computers. They also update the antivirus software.
Your family eradicates a problem by removing the virus from your phone. They also update the phone's software.
A Nigerian bank eradicates fraud by closing the fraudster's account. They also improve their fraud detection system.
Eradication
|
V
+-------------------+
| Find the Cause |
+-------------------+
|
V
+-------------------+
| Remove the Cause |
+-------------------+
|
V
+-------------------+
| Fix the Weakness |
+-------------------+
|
V
+-------------------+
| Prevent It From |
| Happening Again |
+-------------------+
Eradication is removing the cause of the incident. It fixes the problem and prevents it from happening again.
Recovery is restoring normal operations. It is the fifth phase of incident response.
After an incident, you need to get back to normal. Recovery helps you do that.
Imagine you were sick. You took medicine. Now you need to rest and get better. That is recovery. In cyber security, recovery means restoring files, fixing computers, and getting back to work.
A bank recovers by restoring data from backups. They also check that all systems are working properly.
Your school recovers by restoring files from backups. They also check that all computers are working.
Your family recovers by restoring data from backups. They also check that all devices are working.
A Nigerian bank recovers by returning money to customers. They also check that all systems are working.
Recovery
|
V
+-------------------+
| Restore Files |
+-------------------+
|
V
+-------------------+
| Fix Computers |
+-------------------+
|
V
+-------------------+
| Check Systems |
+-------------------+
|
V
+-------------------+
| Get Back to Work |
+-------------------+
Recovery is restoring normal operations. It means restoring files, fixing computers, and getting back to work.
Learning is studying the incident and improving. It is the sixth phase of incident response.
If you do not learn from an incident, it can happen again. Learning helps you get better.
Imagine you failed a test. You study the questions you got wrong. You learn from your mistake. That is learning. In cyber security, learning means writing a report, finding out what went wrong, and improving.
A bank learns from an incident by writing a report. They find out how the hacker got in. They improve their security.
Your school learns from an incident by writing a report. They find out how the virus got in. They teach students about it.
Your family learns from an incident by talking about it. They find out how the problem happened. They change their habits.
A Nigerian bank learns from an incident by writing a report. They find out how the fraud happened. They improve their fraud detection system.
Learning
|
V
+-------------------+
| Write a Report |
+-------------------+
|
V
+-------------------+
| Find Out What |
| Went Wrong |
+-------------------+
|
V
+-------------------+
| Improve |
+-------------------+
|
V
+-------------------+
| Prevent It From |
| Happening Again |
+-------------------+
Learning is studying the incident and improving. It helps prevent the incident from happening again.
Metrics for incident response are numbers that measure how well you handle incidents.
Metrics tell you if you are getting better. They help you improve your incident response.
Here are important metrics for incident response:
| Metric | What It Measures |
|---|---|
| MTTD (Mean Time to Detect) | How fast you notice an incident |
| MTTR (Mean Time to Respond) | How fast you respond to an incident |
| MTTC (Mean Time to Contain) | How fast you stop an incident from spreading |
| MTTE (Mean Time to Eradicate) | How fast you remove the cause |
| MTTR (Mean Time to Recover) | How fast you restore normal operations |
| Number of Incidents | How many incidents happened |
| Number of Incidents Resolved | How many incidents were fixed |
| Cost of Incidents | How much money was lost |
A bank measures MTTD, MTTR, and cost of incidents. They see that MTTD is going down. This means they are detecting incidents faster.
Your school measures MTTD and MTTR. They see that MTTR is going down. This means they are responding faster.
Your family measures how many incidents happen and how fast they fix them.
A Nigerian bank measures how many fraud incidents happen and how much money is lost. They use these metrics to improve.
Metrics for Incident Response
+------------------------------------------+
| MTTD: 15 minutes |
| MTTR: 30 minutes |
| MTTC: 1 hour |
| MTTE: 2 hours |
| MTTR: 6 hours |
| Incidents: 10 |
| Resolved: 10 |
| Cost: 5 million naira |
+------------------------------------------+
Metrics for incident response include MTTD, MTTR, MTTC, MTTE, MTTR, number of incidents, number resolved, and cost.
Incident response is used all over the world, including in Nigeria. Here are some Nigerian examples.
Seeing examples from Nigeria helps you understand how incident response works in your own country.
Here are some Nigerian examples:
A Nigerian bank might report: "Last month, we detected a fraud incident in 10 minutes. We contained it in 30 minutes. We eradicated it in 1 hour. We recovered in 4 hours. We learned and improved."
A Nigerian school might report: "Last term, we detected a virus in 20 minutes. We contained it in 1 hour. We eradicated it in 2 hours. We recovered in 5 hours. We learned and improved."
A Nigerian family might report: "Last month, we detected a Wi-Fi problem in 1 hour. We contained it in 2 hours. We eradicated it in 3 hours. We recovered in 1 day. We learned and improved."
NITDA might report: "Last year, we detected 100 attacks. We contained 95. We eradicated 95. We recovered 95. We learned and improved."
Nigerian Incident Response
+------------------------------------------+
| Banks: Fraud response |
| Telecoms: SIM fraud response |
| Government: Cyber attack response |
| Schools: Data breach response |
| Businesses: Fake order response |
+------------------------------------------+
Nigerian banks, telecoms, government agencies, schools, and businesses all use incident response to stay safe.
Incident response can be explained using fun examples that children understand.
When you use fun examples, learning becomes easier and more enjoyable.
Here are some fun examples:
Imagine you are playing a game where you have to protect a castle. The enemy breaks through the gate. You do not panic. You send soldiers to the gate. You fix the gate. You recover. You learn. That is incident response.
Your teacher gives a pop quiz. You are not prepared. You do not panic. You answer the questions you know. You learn from the experience. That is incident response.
Your phone battery dies. You do not panic. You charge it. That is incident response.
In a Nigerian football match, the coach sees the other team scoring. He changes the formation. He substitutes a player. That is incident response.
Fun Incident Response
+------------------------------------------+
| Video Game: Use health pack |
| Football: Change tactics |
| Social Media: Change password |
| School: Study harder |
| Cooking: Start again |
+------------------------------------------+
Incident response is everywhere. It is in video games, football, social media, school, and cooking. Cyber security incident response is just another type.
Incident response is not just for big companies. It is also useful in everyday life.
When you understand incident response in everyday life, you can use it to stay safe.
Here are everyday examples:
You lose your phone. You detect it. You contain it by calling your phone. You eradicate it by finding it. You recover by using it again. You learn by keeping it in a safe place.
You forget your lunch. You detect it. You contain it by borrowing from a friend. You eradicate it by buying lunch. You recover by eating. You learn by checking your bag.
Your Wi-Fi stops working. You detect it. You contain it by checking the router. You eradicate it by restarting the router. You recover by connecting again. You learn by keeping the router updated.
Your family has a power outage. You detect it. You contain it by using a generator. You eradicate it by calling the electric company. You recover by using electricity again. You learn by keeping the generator ready.
Everyday Incident Response
+------------------------------------------+
| Lose Keys: Find them |
| Get Sick: Take medicine |
| Miss Bus: Find another |
| Break Glass: Clean it up |
| Forget Homework: Do it |
+------------------------------------------+
Incident response is useful in everyday life. You can use it when you lose your keys, get sick, miss the bus, break a glass, or forget your homework.
An incident response plan is a document that explains what to do when an incident happens.
A plan helps you stay calm. It helps you remember what to do. It helps you respond quickly.
An incident response plan has these parts:
A bank's incident response plan includes:
Your school's incident response plan includes:
Your family's incident response plan includes:
A Nigerian company's incident response plan includes:
Incident Response Plan
|
V
+-------------------+
| Team |
+-------------------+
|
V
+-------------------+
| Phases |
+-------------------+
|
V
+-------------------+
| Tools |
+-------------------+
|
V
+-------------------+
| Metrics |
+-------------------+
|
V
+-------------------+
| Communication |
+-------------------+
|
V
+-------------------+
| Review |
+-------------------+
An incident response plan explains who is responsible, what the phases are, what tools to use, how to measure success, who to communicate with, and when to review.
A case study is a real-life example that helps us learn. Let us look at a Nigerian bank.
Case studies help us see how incident response works in real life.
A Nigerian bank noticed that fraudsters were attacking their customers. The bank decided to improve its incident response.
Here is what they did:
After six months, the bank saw results:
The bank learned that good incident response saves money and protects customers.
The bank shared its success with other banks. They all started using similar incident response plans.
Your school can use the same approach. Prepare by teaching students. Detect viruses quickly. Contain them by disconnecting computers. Eradicate them by cleaning. Recover by restoring files. Learn by writing reports.
Your family can use the same approach. Prepare by using strong passwords. Detect problems quickly. Contain them by disconnecting from Wi-Fi. Eradicate them by removing viruses. Recover by restoring data. Learn by talking about what happened.
Nigerian banks like GTBank, Zenith, and Access Bank all use similar incident response strategies. They detect fraud quickly, contain it, eradicate it, recover, and learn.
Case Study: Nigerian Bank
|
V
+-------------------+
| Problem: Fraud |
+-------------------+
|
V
+-------------------+
| Solution: Incident|
| Response |
+-------------------+
|
V
+-------------------+
| Preparation, |
| Detection, |
| Containment, |
| Eradication, |
| Recovery, Learning|
+-------------------+
|
V
+-------------------+
| Result: 50% less |
| fraud, happier |
| customers |
+-------------------+
A Nigerian bank used incident response to reduce fraud by 50%. They prepared, detected, contained, eradicated, recovered, and learned.
| Word | Simple Definition |
|---|---|
| Incident | Something bad that happens |
| Incident Response | What we do when an incident happens |
| Preparation | Getting ready before an incident |
| Detection | Noticing that an incident has happened |
| Containment | Stopping the incident from spreading |
| Eradication | Removing the cause of the incident |
| Recovery | Restoring normal operations |
| Learning | Studying the incident and improving |
| MTTD | Mean Time to Detect - how fast you notice an incident |
| MTTR | Mean Time to Respond - how fast you respond to an incident |
| MTTC | Mean Time to Contain - how fast you stop an incident from spreading |
| MTTE | Mean Time to Eradicate - how fast you remove the cause |
| MTTR | Mean Time to Recover - how fast you restore normal operations |
| Backup | A copy of your data |
| Ransomware | Bad software that locks your files and asks for money |
A bank in Lagos uses incident response to handle fraud. They detect fraud in 10 minutes. They contain it in 30 minutes. They eradicate it in 1 hour. They recover in 4 hours. They learn and improve.
A school in Abuja uses incident response to handle viruses. They detect viruses in 20 minutes. They contain them in 1 hour. They eradicate them in 2 hours. They recover in 5 hours. They learn and improve.
A family in Port Harcourt uses incident response to handle Wi-Fi problems. They detect problems in 1 hour. They contain them in 2 hours. They eradicate them in 3 hours. They recover in 1 day. They learn and improve.
Banks like GTBank, Zenith, and Access Bank use incident response to handle fraud. They detect, contain, eradicate, recover, and learn.
Companies like MTN, Glo, and Airtel use incident response to handle SIM card fraud. They detect, contain, eradicate, recover, and learn.
NITDA uses incident response to handle cyber attacks. They detect, contain, eradicate, recover, and learn.
Schools like Covenant University and University of Lagos use incident response to handle data breaches. They detect, contain, eradicate, recover, and learn.
Companies like Jumia and Konga use incident response to handle fake orders. They detect, contain, eradicate, recover, and learn.
In a video game, if your character gets hurt, you use a health pack. That is incident response.
In football, if the other team scores, you change your tactics. That is incident response.
On social media, if your account is hacked, you change your password and report it. That is incident response.
In school, if you fail a test, you study harder. That is incident response.
The incident is losing your keys. You detect it. You contain it by checking your pockets. You eradicate it by finding the keys. You recover by using the keys. You learn by keeping them in a safe place.
The incident is getting sick. You detect it. You contain it by resting. You eradicate it by taking medicine. You recover by getting better. You learn by taking care of your health.
The incident is missing the bus. You detect it. You contain it by finding another bus. You eradicate it by getting on the bus. You recover by arriving at school. You learn by leaving earlier next time.
The incident is breaking a glass. You detect it. You contain it by not stepping on the glass. You eradicate it by cleaning it up. You recover by using a new glass. You learn by being more careful.
The incident is forgetting your homework. You detect it. You contain it by telling your teacher. You eradicate it by doing the homework. You recover by submitting it late. You learn by checking your bag before school.
+-------------------+
| Preparation |
+-------------------+
|
V
+-------------------+
| Detection |
+-------------------+
|
V
+-------------------+
| Containment |
+-------------------+
|
V
+-------------------+
| Eradication |
+-------------------+
|
V
+-------------------+
| Recovery |
+-------------------+
|
V
+-------------------+
| Learning |
+-------------------+
|
V
+-------------------+
| Improve |
+-------------------+
Past Present Future
| | |
V V V
+----------------+ +----------------+ +----------------+
| Preparation | | Detection | | Recovery |
+----------------+ +----------------+ +----------------+
| | |
V V V
+----------------+ +----------------+ +----------------+
| Train, Plan, | | Notice, Report,| | Restore, Fix, |
| Backup | | Confirm | | Learn |
+----------------+ +----------------+ +----------------+
| Metric | What It Measures | Example |
|---|---|---|
| MTTD | How fast you notice an incident | 15 minutes |
| MTTR | How fast you respond to an incident | 30 minutes |
| MTTC | How fast you stop an incident from spreading | 1 hour |
| MTTE | How fast you remove the cause | 2 hours |
| MTTR | How fast you restore normal operations | 6 hours |
| Number of Incidents | How many incidents happened | 10 |
| Number Resolved | How many incidents were fixed | 10 |
| Cost of Incidents | How much money was lost | 5 million naira |
| Feature | Good | Bad |
|---|---|---|
| Preparation | Prepared with a plan | Not prepared |
| Detection | Detects quickly | Detects slowly |
| Containment | Contains quickly | Does not contain |
| Eradication | Removes the cause | Does not remove the cause |
| Recovery | Recovers quickly | Recovers slowly |
| Learning | Learns and improves | Does not learn |
| Phase | What It Means | Example |
|---|---|---|
| Preparation | Getting ready | Training staff, making backups |
| Detection | Noticing an incident | Antivirus alerts, customer reports |
| Containment | Stopping the spread | Disconnecting computers |
| Eradication | Removing the cause | Deleting malware |
| Recovery | Restoring normal | Restoring files |
| Learning | Improving | Writing reports |
An incident is something bad that happens. In cyber security, it is when a hacker breaks in, a virus infects a computer, or data is stolen.
Incident response is what we do when an incident happens. It is our plan for dealing with the problem.
Incident response has six phases: preparation, detection, containment, eradication, recovery, and learning.
Preparation is getting ready before an incident happens. It means having a plan, training people, and using good tools.
Detection is noticing that an incident has happened. The faster you detect it, the faster you can respond.
Containment is stopping the incident from spreading. It limits the damage.
Eradication is removing the cause of the incident. It fixes the problem and prevents it from happening again.
Recovery is restoring normal operations. It means restoring files, fixing computers, and getting back to work.
Learning is studying the incident and improving. It helps prevent the incident from happening again.
Metrics for incident response include MTTD, MTTR, MTTC, MTTE, MTTR, number of incidents, number resolved, and cost.
Nigerian banks, telecoms, government agencies, schools, and businesses all use incident response to stay safe.
Incident response is everywhere. It is in video games, football, social media, school, and cooking.
Incident response is useful in everyday life. You can use it when you lose your keys, get sick, miss the bus, break a glass, or forget your homework.
An incident response plan explains who is responsible, what the phases are, what tools to use, how to measure success, who to communicate with, and when to review.
A Nigerian bank used incident response to reduce fraud by 50%. They prepared, detected, contained, eradicated, recovered, and learned.
Congratulations! You have completed Module Five: Cyber Security Metrics and Incident Response.
In this module, you learned that an incident is something bad that happens. You learned that incident response is what we do when an incident happens.
You learned about the six phases of incident response: preparation, detection, containment, eradication, recovery, and learning.
You learned about preparation. It means having a plan, training people, and using good tools.
You learned about detection. It means noticing that an incident has happened.
You learned about containment. It means stopping the incident from spreading.
You learned about eradication. It means removing the cause of the incident.
You learned about recovery. It means restoring normal operations.
You learned about learning. It means studying the incident and improving.
You learned about metrics for incident response: MTTD, MTTR, MTTC, MTTE, MTTR, number of incidents, number resolved, and cost.
You learned about Nigerian examples of incident response.
You learned about fun examples and everyday examples.
You learned how to build an incident response plan.
You learned from a case study of a Nigerian bank that reduced fraud by 50%.
You are now a Cyber Security Incident Response Expert in training!
An incident is something bad that happens. In cyber security, it is when a hacker breaks in, a virus infects a computer, or data is stolen.
Incident response is what we do when an incident happens. It is our plan for dealing with the problem.
Preparation, detection, containment, eradication, recovery, and learning.
Preparation is getting ready before an incident happens. It means having a plan, training people, and using good tools.
Detection is noticing that an incident has happened.
Containment is stopping the incident from spreading.
Eradication is removing the cause of the incident.
Recovery is restoring normal operations.
Learning is studying the incident and improving.
MTTD, MTTR, MTTC, MTTE, MTTR, number of incidents, number resolved, and cost.
| Word | Definition |
|---|---|
| 1. Incident | A. Noticing that an incident has happened |
| 2. Incident Response | B. Stopping the incident from spreading |
| 3. Preparation | C. Something bad that happens |
| 4. Detection | D. What we do when an incident happens |
| 5. Containment | E. Removing the cause of the incident |
| 6. Eradication | F. Restoring normal operations |
| 7. Recovery | G. Getting ready before an incident |
| 8. Learning | H. Studying the incident and improving |
Answers: 1-C, 2-D, 3-G, 4-A, 5-B, 6-E, 7-F, 8-H
Your school computer lab has a virus. The computers are slow. Files are missing.
Question: What should the school do?
Answer: The school should follow the incident response phases. Detect the virus. Contain it by disconnecting computers. Eradicate it by cleaning the computers. Recover by restoring files. Learn by writing a report.
Your family Wi-Fi is hacked. Someone is using it without permission.
Question: What should your family do?
Answer: Your family should follow the incident response phases. Detect the problem. Contain it by changing the Wi-Fi password. Eradicate it by removing the hacker. Recover by connecting again. Learn by using a stronger password.
A Nigerian bank is attacked by fraudsters. Customers are losing money.
Question: What should the bank do?
Answer: The bank should follow the incident response phases. Detect the fraud. Contain it by blocking the fraudster's account. Eradicate it by removing the fraudster. Recover by returning money. Learn by improving their system.
Instructions:
Time: 30 minutes
Instructions:
Goal: Create a dashboard that shows how well your class responds to incidents.
Steps:
Time: 2 weeks
Instructions:
In Module Six, you will learn about Cyber Security Metrics and Compliance.
You will learn:
To prepare for Module Six, think about these questions:
See you in Module Six!
End of Module Five