Glossary
GLOSSARY Metric design

Normalized Metric

Last updated 27 Jul 2026

A normalized metric adjusts a raw measurement so that it can be compared across units of different size or shape. Without normalization, the largest business unit always looks worst and the smallest always looks best, regardless of how either is actually run.

Size masquerading as performance

A business unit with 12,000 endpoints reports 340 open critical findings. Another with 800 endpoints reports 45.

The raw numbers say the first unit is seven times worse. Per thousand endpoints, they are 28 and 56. The second unit is twice as bad and was being congratulated.

Any comparison between units, regions or time periods where the underlying population changed needs normalization, or the comparison is measuring size.

Choosing the denominator

Per asset works for exposure and coverage metrics.

Per user works for identity, access and awareness metrics.

Per critical asset, rather than per asset, is usually better for anything risk-weighted. A thousand exposed development servers is not a thousand exposed payment systems.

Per unit of revenue or per employee is common in benchmark studies and is weak for operational use. It normalizes for business size rather than for attack surface, and those diverge sharply between a bank and a manufacturer.

Whatever you choose, the denominator must be measured consistently across the units being compared. A per-asset figure where one region counts virtual machines and another does not is not normalized, it is disguised.

Where it still misleads

Normalization removes the size effect and leaves everything else. Two units with identical per-asset figures can have completely different risk profiles if one runs internet-facing payment infrastructure and the other runs internal file shares.

So normalize to make comparison possible, then segment to make it meaningful. Comparing like environments beats comparing normalized unlike ones.

In benchmarking

Almost every problem with external benchmarks is a normalization problem. Contributors of very different sizes report figures normalized differently, or not at all, and the resulting average describes nothing.

When citing a benchmark, check what it was normalized by before checking what it says.