IT Metrics You Should Be Tracking

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Book a Consultation

According to Statistics Canada (2024), 46% of Canadian businesses monitor their network and business systems, and 26% keep a written cyber security policy. Those two numbers set the ceiling on IT reporting in this country. A metric nobody collects cannot be improved, and it cannot be defended to a regulator or an underwriter.

IT metrics are the quantitative measures that tell you whether your technology operations are healthy, efficient, and aligned with business goals. The five that matter most for a Canadian SMB: uptime percentage (target 99.5% or better), first-contact resolution rate (target 80% or better), mean time to repair critical issues, patch compliance rate (target 95% or better), and user satisfaction score.

KEY TAKEAWAYS

  • Only 46% of Canadian businesses monitor their network and business systems at all (Statistics Canada, 2024). Measurement is the gap, ahead of tooling.
  • Five metrics carry the load: uptime, first-contact resolution, mean time to repair, patch compliance, and user satisfaction.
  • A metric earns board time when it has an owner, a published target, a defined measurement window, and a decision attached to it.
  • Review quarterly with your managed IT services. Monthly data without quarterly analysis is noise.
Target benchmark ranges for five core SMB IT metrics. Uptime 99.5 percent, first-contact resolution 80 percent, patch compliance 95 percent, backup restore verification 100 percent, and satisfaction 4.5 out of 5. Five metrics, five published targets. Uptime.99.5% First-contact resolution.80% Patch compliance.95% Restore verification.100% User satisfaction.4.5/5 Fusion Computing target bands for managed Canadian SMB environments.
Target bands we hold managed Canadian SMB environments to. Restore verification is the only one set at 100%.

What is an IT metric, explained in plain English

An IT metric is a number with an owner. It has a definition, a measurement window, a published target, and one person accountable for the gap. Strip any of those four away and the number becomes decoration on a slide. In a Canadian SMB that distinction separates a reporting pack the board acts on from a dashboard nobody opens twice.

The word “metric” gets used loosely for three different things. A measure is raw output, such as 412 tickets closed. An indicator is that measure placed against a target, such as 412 closed against 430 opened. A metric is an indicator someone owns and reviews on a schedule. Canadian SMBs usually have plenty of measures and almost no metrics.

In our experience the fastest test is to ask who gets the email when the number moves. If the answer is a distribution list, the number has no owner. I have sat in quarterly reviews where four people could quote the uptime figure and none of them could say who owned the 0.4% that went missing.

That is why my first question in a reporting review is never about tooling. I ask which decision each number is supposed to trigger, and I work backwards from there. A Canadian SMB with 5 owned metrics beats one with 30 orphaned charts, and I have yet to see that ordering reversed.

Leading vs lagging IT metrics, and the five that matter

According to the Verizon Data Breach Investigations Report (2026), vulnerability exploitation now drives 31% of breaches, ahead of stolen credentials at 13%. That ordering is why leading metrics matter. Patch compliance, restore verification, and multi-factor authentication coverage predict incidents, while uptime and ticket volume only describe them.

Lagging metrics report what already happened, so uptime, mean time to repair, and ticket volume all sit in that group. Leading metrics report what is about to happen. A Canadian SMB reporting pack needs both, weighted toward the 3 leading indicators.

Metric Type Target band Measured against
Uptime by service Lagging 99.5% to 99.9% Business hours per critical service
First-contact resolution Lagging 78% to 85% Per ticket category
Mean time to repair Lagging Split by phase Detect, triage, remediate
Patch compliance Leading 95% or better A published patch window
Restore verification Leading 100% Tested restores, not backup jobs

Restore verification is the one target I refuse to set below 100%. A backup job that reports success proves a file was copied. A tested restore proves the business can come back. Across our 40 or so managed Canadian client environments, the recurring finding is that backup dashboards look healthier than restore evidence does.

How to baseline IT metrics at a 50-employee Canadian firm

Plan on six to eight weeks of disciplined collection before publishing any number to leadership. Statistics Canada classes a 50-employee firm as medium-sized, and that band is where informal IT reporting usually breaks down. The first two weeks belong to inventory: every endpoint, every server, and every SaaS account tied to a named human.

Printed IT metrics baseline spreadsheet on a Canadian small-business desk beside a calculator and a coffee mug
A printed baseline is the cheapest sign that metrics are no longer just a dashboard.

Inventory first, because an incomplete asset list invalidates everything downstream. A patch compliance rate of 96% means nothing when the denominator is missing nine laptops and a file server. The Canadian Centre for Cyber Security scopes its 13 baseline controls to organisations under 499 employees, and its patching control assumes you know what you own.

Once inventory is locked, the next four weeks capture clean operating data. Uptime is measured per service rather than per server. First-contact resolution is measured per ticket category rather than as one rolled-up percentage. Mean time to repair splits into detection, triage, and remediation, so a slow vendor stays visible across all 3 phases.

By week eight the business has a defensible baseline. That baseline is what holds up under cyber insurance underwriting and under a privacy commissioner inquiry, and it is the standard Fusion Computing has applied to Canadian-owned operations since 2012.

The criteria a metric has to meet before it reaches the board

Four criteria decide whether a number belongs in a Canadian leadership pack. Anything failing 1 of the 4 stays in the operations review. This filter is what keeps a quarterly pack to a single page, and it is the same filter we apply before adding any indicator to a client report.

  1. Named owner. One person, by name, accountable for the gap between actual and target.
  2. Published target. Agreed in advance and written down, so nobody negotiates the target after seeing the result.
  3. Defined window. Business hours or calendar hours, stated. Uptime measured two ways produces two answers.
  4. Attached decision. A named action that triggers when the metric misses, such as a budget release or a scope change.

The 4th criterion is the one I see skipped most often across Canadian SMBs. A metric with no attached decision generates discussion instead of change. Our engineers found that once a patch compliance miss automatically triggered a scheduled maintenance window, the underlying number stopped drifting within two quarters.

Unsure which of your numbers clear all 4 criteria? Get in touch and we will mark up your last quarterly pack together.

Talk to Fusion

How Canadian regulators interact with IT-metric reporting

According to the Personal Information Protection and Electronic Documents Act, an organisation must report a breach of security safeguards to the Privacy Commissioner “as soon as feasible” (s.10.1). PIPEDA sets no 72-hour clock, and the practical burden falls on documented evidence of reasonable safeguards.

Printed regulator letter on a Canadian small-business owner desk beside a small Canadian flag on a stand and a coffee mug
A letter with a federal letterhead is when IT metrics stop being optional.

That evidence is made of metrics. Patch compliance, multi-factor authentication coverage, backup success and restore verification, and incident detection time are the indicators an investigator asks to see. The Information and Privacy Commissioner of Ontario applies comparable reasoning to PHIPA for health information custodians, and the Office of the Information and Privacy Commissioner of British Columbia does likewise under PIPA.

Federal guidance points the same way. The Canadian Centre for Cyber Security expects measurable evidence of patching cadence, account hardening, and logging coverage across its baseline controls. Innovation, Science and Economic Development Canada runs the CyberSecure Canada certification on top of those controls, and certified firms produce metric evidence on demand.

For incident metrics specifically, NIST SP 800-61 is the reference most Canadian auditors recognise. Revision 3 replaced revision 2 in April 2025, so a runbook still citing the older four-phase lifecycle is dated. Detection time and containment time remain the two numbers worth reporting.

“Our old report had 22 charts and told us nothing. The version with five owned numbers took ten minutes to review and actually changed what we funded that quarter.”

Finance director, 55-person professional services firm, Greater Toronto Area. Anonymized at the client’s request; quote shared with permission.

Industry benchmarks, insurer rewards, and the anti-patterns to avoid

According to Statistics Canada (2024), recovery spending after cyber security incidents doubled from roughly CA$600 million in 2021 to CA$1.2 billion in 2023. Benchmarks matter because that cost is now the downside case. Canadian professional services firms usually run uptime at 99.5% to 99.7%, with first-contact resolution in the 78% to 85% band.

Printed IT benchmarks document on a Canadian conference table beside a cyber-insurance renewal questionnaire
Benchmarks beside an insurance questionnaire is where most owners discover their controls have a price tag.

Manufacturing operations push uptime higher, because a stalled line costs far more than a stalled email session. Ticket volume there is dominated by shop-floor printers, ruggedized scanners, and systems adjacent to operational technology. Healthcare clinics and PHIPA-regulated practices sit between the two, with uptime targets near 99.8% and heavy weight on access logs, audit trails, and backup verification.

Cyber insurers have noticed. Statistics Canada recorded cyber risk insurance uptake rising from 16% of businesses in 2021 to 22% in 2023, and underwriters now reward documented metric evidence at renewal. Firms that can produce a 12-month patch compliance trend, an MFA coverage report covering every privileged account, and an incident response time history routinely see softer terms.

The anti-patterns repeat across all 3 verticals above. Tracking ticket volume without ticket category turns improvement work into a number that rises whenever headcount grows. Reporting uptime as one rolled-up percentage hides the single critical service that failed. Measuring patch compliance against the calendar rather than a published window punishes engineers who held a patch for valid stability reasons.

Mixing internal IT and vendor SLA time into 1 repair number is the 4th. Vendor delays disappear into the operations report, and the team carrying the ticket absorbs blame for a queue it does not control. Split the number, publish both halves, and the conversation moves to the vendor contract where it belongs.

What a defensible metrics programme requires from your MSP

A provider that reports on its own performance needs to show its working. The Canadian Centre for Cyber Security publishes ITSM.50.030 (October 2020), which sets out 10 areas to assess a managed service provider against, including audit reports and incident response.

  • Raw data access. You should be able to pull the underlying ticket and patch data yourself, without asking.
  • Stated measurement windows. Business hours or calendar hours, written into the report footer.
  • Third-party control mapping. Reporting mapped to CIS Controls v8.1, which defines 18 controls and 153 safeguards across three implementation groups.
  • Restore evidence. Tested restores with timestamps, rather than backup job success rates.

Ask any prospective Canadian provider for a sample report before signing. I read the footer first, because the measurement window tells you more than the headline figure does. If the sample carries no owner names and no restore evidence, that reporting will not survive an underwriter’s questions either.

Our own managed IT services start at CA$180 per user per month, typically around CA$230, from offices in Toronto, Hamilton, and Metro Vancouver. Reporting against the criteria above is part of that, and I sign off on the quarterly pack personally.

Want a second read on what your reporting actually proves? Talk to our team and we will walk your last Canadian quarterly pack against the 4 criteria above.

Where to start next week

Pick restore verification and run one tested restore before Friday. Record the date, the system, the operator, and the elapsed time in a single row. Repeat monthly. That one habit produces the evidence a Canadian underwriter, a privacy commissioner, and your own board all ask for, and it costs an hour a month to maintain.

Frequently asked questions

The IT metrics that move the needle for a Canadian SMB are mean time to resolution, first-contact resolution, uptime by service, patch compliance, and restore verification. Statistics Canada found 46% of Canadian businesses monitor their network and business systems, so measurement itself is the first gap to close. Source: Statistics Canada, 2024.

The most important IT metrics are mean time to resolution, first-contact resolution rate, uptime percentage by service, endpoint patch compliance, and backup restore verification. These 5 reveal whether an IT environment is improving or deteriorating. Reviewed 4 times a year, they support evidence-based decisions about technology investment.

What IT metrics should a small business track?

Track five: uptime percentage by service, first-contact resolution rate, mean time to repair for critical issues, patch compliance rate, and restore verification. Those 5 give a complete picture of IT health without drowning a Canadian leadership team in data. For planning around these numbers, see our IT strategic planning process.

Fusion Computing is a Canadian-owned managed IT and cybersecurity provider serving businesses with 15 to 200+ users since 2012. With a 93% first-contact resolution rate and CISSP-led security leadership, Fusion Computing delivers monitoring, help desk, and security services aligned to CIS Controls v8.1.

How often should IT metrics be reviewed?

Review monthly at the operations level and 4 times a year with your provider or internal IT lead. Monthly data without quarterly analysis is noise. The quarterly review is where trends connect to business outcomes and where budget decisions get made.

What is a good uptime target for a Canadian SMB?

99.5% measured per critical service during business hours is a reasonable floor, and 99.8% is common for PHIPA-regulated clinics. State the measurement window in the report. Uptime measured over calendar hours and uptime measured over business hours produce two different numbers from the same outage.

How is patch compliance rate calculated?

Divide the number of assets patched inside your published patch window by the total assets in scope, then report the exceptions by name. A 95% target is standard. The Canadian Centre for Cyber Security lists automatic patching of operating systems and applications among its 13 baseline controls for organisations under 499 employees.

What does mean time to repair actually measure?

Split it into 3 phases: time to detect, time to triage, and time to remediate. One blended number hides which of the 3 is slow. If vendor escalation is inside the measurement, report vendor time separately so internal performance and supplier performance stay distinguishable.

Do IT metrics affect cyber insurance renewals in Canada?

Underwriters increasingly ask for evidence rather than assertions. Statistics Canada recorded cyber risk insurance uptake rising from 16% of businesses in 2021 to 22% in 2023. A 12-month patch compliance trend, an MFA coverage report covering privileged accounts, and tested restore evidence are the three artifacts brokers ask about most. If a renewal is coming up, contact us before the questionnaire lands.

How much does managed IT reporting cost in Canada?

Reporting is normally bundled into a managed IT agreement rather than priced separately. Fusion Computing’s managed IT services start at CA$180 per user per month and typically run around CA$230, with cybersecurity services in the CA$180 to CA$250+ per user per month range. Ask any provider whether reporting is included before comparing rates.

Which IT metric should a 50-person firm start with?

Start with restore verification, because it is the cheapest to produce and the most persuasive. One documented, tested restore per month with a timestamp and a named operator builds a 12-row evidence trail in a year. Add patch compliance next, then uptime by service.

Related Resources


Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611