Given the continuous flux of cyber environments, organizations struggle to make timely risk-based decisions in the selection of control strategies. This presentation proposes a novel means to measure cyber environment complexity. By measuring complexity of any given network, organizations can gain appreciation for the benefits and challenges each layer of defense adds to a security stack.