- Complete Security, Delivered with Accountability/
- Security Insights & Advisories/
- Security Metrics Boards Actually Need: Beyond Vanity Counts/
Security Metrics Boards Actually Need: Beyond Vanity Counts
Table of Contents
Board members ask a reasonable question when presented with a quarterly security report: what am I supposed to do with this? Too often, the honest answer is nothing. The report contains blocked email counts, training completion percentages, and a threat landscape slide recycled from a vendor. It is activity reporting, not assurance, and it leaves directors exactly where they started: unable to judge whether the organisation is resilient or merely busy.
The metrics that move the needle for boards share one property. They measure capability under stress, not effort expended. A board does not need to know how many phishing emails were filtered last month. It needs to know whether, if ransomware lands tomorrow, the business survives the week.
Why most security reporting fails #
Security teams usually report what their tools count, because that is what is easy to extract. The result is a dashboard full of numbers that rise steadily and mean nothing:
- Blocked threats. A bigger number mostly means you receive more spam. Every mail platform blocks millions of messages; the interesting question is what got through, and no tool counts that honestly.
- Training completion rates. Completion measures attendance, not behaviour. An organisation can hit 100% completion and still fail a real social engineering test the following week.
- Vulnerability counts in the thousands. Raw counts are meaningless without exposure context. Ten thousand low-severity findings on internal test systems matter less than two critical findings on internet-facing payment infrastructure.
- Alert volumes. More alerts means more noise, not more security. If anything, high alert counts with slow triage indicate the opposite of readiness.
None of these answer a director’s actual fiduciary question: are we prepared, and how would we know?
What resilience looks like as a number #
Boards govern outcomes: continuity, legal exposure, and reputation. The metrics worth board time measure those directly.
Detection and response speed #
How long between compromise and containment? Mean time to detect (MTTD) and mean time to respond (MTTR), measured from real incidents and tested scenarios, are the closest thing security has to a vital sign. Industry research consistently links breach cost to containment speed: organisations that contain within weeks pay dramatically less than those that take months. If these numbers are not known, that itself is the finding for the board.
Recovery proof #
Backups nobody has restored are hopes, not controls. The metric that matters: when did we last restore a full production service from backup, and how long did it take? Add immutable backup coverage for the systems ransomware would target first. A tested restore within an agreed recovery time objective is worth more to a director than any threat statistic, because it is direct evidence the business survives destructive attack.
Rehearsal and its results #
When did the executive team last rehearse a cyber crisis, and what gaps did it expose? Tabletop exercises produce findings: missing decision authority, unreachable vendors, unclear customer communication ownership. Track the same way you track audit findings: identified, assigned, closed. A board that sees exercise findings closing on schedule knows the organisation learns faster than attackers evolve.
Exposure that actually matters #
Replace vulnerability counts with exposure metrics tied to consequence:
- Critical or high vulnerabilities on internet-facing systems, patched within SLA: percentage and trend.
- Age of the oldest unpatched critical on any revenue-facing system.
- Percentage of privileged accounts covered by MFA and just-in-time access.
These numbers connect directly to breach likelihood, which connects to the news headlines directors are managing against.
Third-party exposure #
For many organisations, the next breach arrives through a vendor. Boards should see: how many critical suppliers have been assessed, how many current assessments are past due, and whether contractual incident notification terms exist with each critical provider. This maps cleanly onto existing vendor-risk governance directors already understand.
Keeping the business out of the news #
Directors often describe their security goal plainly: do not become the next breach story. That goal decomposes into measurable components, none of which require technical fluency to interpret:
| Outcome the board cares about | Metric that evidences it |
|---|---|
| We would detect an intrusion quickly | MTTD trend; monitoring coverage of critical systems |
| We would contain it before major damage | MTTR trend; lateral movement contained in tests |
| We would survive ransomware | Tested restore time vs RTO; immutable backup coverage |
| We would meet legal duties | Breach notification procedure tested; regulator obligations mapped |
| Our partners trust us | Critical vendor assessments current; framework attestations valid |
A quarterly report containing only this table, with trends and exceptions, gives a board more genuine assurance than forty slides of tool statistics.
How to get honest numbers #
These metrics require engineering honesty, which is partly why they are rare:
- Measure through exercises, not assumptions. Restore times come from real restores. Response times come from simulated intrusions. If nobody has run the test, report “unknown”, which is itself actionable information for a board.
- Report trends, not snapshots. Single values invite gaming; trajectories reveal whether the programme is improving.
- Pair every red number with a decision request. Boards govern by allocating resources. “Restore testing fails our RTO; we need two engineers for six weeks” is a governing sentence. “Risk remains high” is not.
- Keep it short. One page of metrics with trends, one page of decisions requested. If the pack needs a pre-briefing, it is too complicated.
Organisations that adopt this style of reporting typically discover something useful: the conversation shifts from “is IT spending enough?” to specific, decidable questions about recovery objectives, staffing, and third-party risk. That shift is what governance is supposed to feel like.
Our vCISO advisory builds board-level reporting that directors can act on, and our cyber crisis tabletop exercises generate the rehearsal findings that make those reports honest. Or schedule an Engineering & Scoping Session to start the conversation.