life knowledge · stories
Turning Cybersecurity Metrics into Decisions
The W's of the Story.
01
Nathan arrived at COMSUBRON 4 with only a communications chief available for IT support and needed an objective way to decide which units required help first. A network representative had previously created a weighted cybersecurity compliance scorecard, but leaders had not understood its value. Nathan expanded the scorecard, used it to identify units needing assistance, and gave the commodore clear, data-supported reasons for directing limited resources toward specific crews. After an IT specialist joined the team, they refined and elevated the model. The East Coast submarine force adopted it as a recurring assessment standard, helping leaders interpret compliance data, target assistance, and improve preparation for formal cybersecurity inspections.
02
From 2013 through 2016 at COMSUBRON 4, Nathan supported cybersecurity readiness across multiple submarine crews while the squadron initially had only a communications chief available for information-technology support.
03
Limited expertise and competing needs made it difficult to determine which units required assistance first. A weighted cybersecurity compliance scorecard already existed, but leaders did not yet understand how to use it to make resource and readiness decisions.
04
Nathan expanded the scorecard, interpreted its weighted indicators, and used the results to give the commodore clear, data-supported reasons for directing limited assistance toward specific crews. After an IT specialist joined the team, they refined and elevated the model together.
05
Metrics create value only when they clarify a decision. A scorecard should do more than report conditions; it should help leaders understand risk, compare competing needs, and direct limited resources toward the actions that matter most.