Measuring the Wrong Things: How Security Reporting Has Become a Performance Rather Than a Practice
Photo: executive boardroom security metrics dashboard presentation report, via 2.bp.blogspot.com
Somewhere in a conference room right now, a CISO is presenting a slide deck to a board of directors. The deck shows that 94 percent of critical patches were applied within the SLA window last quarter. It shows that vulnerability scans ran on schedule across 98 percent of in-scope systems. It shows that access reviews were completed for all privileged accounts. The board nods. The CISO moves to the next slide. Everyone leaves the room confident that the organization's security posture is sound.
None of those numbers tell you whether the organization is actually secure.
This is the audit theater problem — the systematic substitution of activity metrics for outcome metrics in enterprise security reporting. It is not a new phenomenon, but it has grown more consequential as organizations have invested more heavily in compliance frameworks, GRC platforms, and security dashboards that make it easier than ever to produce numbers that look reassuring without requiring anyone to examine what those numbers actually represent.
What the Numbers Don't Say
Consider the patch completion rate, one of the most universally reported security metrics in enterprise environments. A 94 percent completion rate within SLA sounds impressive. What it does not reveal is which six percent of systems did not receive the patch — and whether those systems include the production database cluster that processes customer payment information, or the legacy authentication server that every internal application depends on.
It also does not reveal the remediation lag that frequently exists between when a vulnerability is detected and when patching actually begins. In practice, many organizations define SLA compliance from the moment a ticket is formally opened, not from the moment the vulnerability was identified. A two-month gap between detection and ticket creation is entirely compatible with a 94 percent SLA compliance figure. The metric is technically accurate. It is operationally meaningless.
Vulnerability scan coverage presents a similar distortion. Reporting that scans ran on 98 percent of in-scope systems sounds comprehensive. The operative phrase is "in-scope." Shadow IT assets, unmanaged cloud instances, developer-provisioned environments, and third-party integrations are frequently excluded from scope definitions — not because organizations have decided they are low-risk, but because including them would complicate the scan infrastructure and reduce the completion percentage. The metric incentivizes scope limitation rather than coverage expansion.
The Compliance Framework Contribution
It would be unfair to blame security teams for this dynamic without acknowledging the structural forces that created it. Compliance frameworks — SOC 2, PCI DSS, NIST CSF, ISO 27001 — are built around demonstrable, auditable controls. Auditors need evidence they can evaluate, and evidence that is easy to evaluate tends to be quantitative and process-oriented: did the scan run, was the patch applied, was the review completed. The frameworks were not designed to measure security outcomes. They were designed to create accountability for security processes.
The problem arises when organizations begin treating compliance as a proxy for security rather than a component of it. When the primary audience for security metrics is an external auditor or a board of directors with limited technical context, the reporting apparatus naturally optimizes for metrics that satisfy those audiences. The metrics that would actually inform security decision-making — mean time to detection, attacker dwell time, lateral movement exposure, detection coverage gaps — are harder to produce, harder to explain, and harder to defend when they reveal uncomfortable truths.
The Behaviors That Actually Drive Breaches
The Verizon Data Breach Investigations Report, one of the most consistently cited empirical sources on breach causation in the US security industry, has documented for years that the majority of successful breaches involve a small number of recurring patterns: stolen credentials, phishing, exploitation of known vulnerabilities, and abuse of legitimate access. What these patterns share is that they are largely invisible to activity-based security metrics.
A stolen credential that is used to access systems through a legitimate authentication pathway will not appear in a patch completion report. It may not appear in a vulnerability scan. It may pass an access review if the account itself is legitimate and the reviewer is not examining behavioral patterns. The metrics say everything is fine. The attacker is already inside.
Mean time to detection — the interval between an attacker gaining initial access and an organization identifying the intrusion — is perhaps the single most operationally significant security metric an enterprise can track. The industry average has hovered between weeks and months depending on the sector. Most monthly security reports do not include it, because measuring it accurately requires a level of detection infrastructure maturity and honest self-assessment that many organizations have not achieved.
What Genuine Security Measurement Looks Like
Shifting from audit theater to substantive security measurement requires a willingness to report on outcomes that are harder to look good on — at least initially.
Detection coverage mapping asks a different question than scan completion rates. Rather than tracking whether scans ran, it tracks what percentage of the environment would generate a detectable alert if an attacker were actively operating within it. This requires red team exercises, purple team collaboration, and honest gap analysis. It is uncomfortable. It is also informative.
Remediation velocity by asset criticality replaces aggregate patch rates with a more granular view: how quickly are vulnerabilities being closed on the systems that matter most, and how does that compare to the systems that matter least. Organizations frequently discover that their highest-criticality assets have the worst remediation velocity, because those systems are the hardest to patch without disrupting operations.
Behavioral anomaly detection rates measure whether the organization's detection tools are actually identifying suspicious activity patterns — unusual authentication sequences, abnormal data access volumes, unexpected service-to-service communication — rather than simply processing known-bad signatures. This metric requires investment in behavioral analytics, but it reflects something that signature-based scan counts cannot: whether the organization would notice an attacker who had already bypassed perimeter controls.
Access review effectiveness goes beyond completion rates to examine outcomes. Of the access reviews conducted last quarter, how many resulted in access being revoked? If the answer is consistently near zero, the reviews are a formality, not a control.
Changing the Conversation
The measurement problem is ultimately a communication problem. Security teams report activity metrics because those are the metrics leadership has historically accepted as evidence of program health. Changing the reporting framework requires educating leadership about why the current metrics are insufficient — and presenting alternative frameworks in terms that connect security outcomes to business risk.
A board that understands that a 94 percent patch rate tells them nothing about whether the organization's most critical systems are protected, and that a two-month detection lag means an attacker could operate undetected for the duration of an entire fiscal quarter, is a board that will start asking different questions. And organizations that ask different questions tend to build different — and more effective — security programs.
The goal is not to make security reporting look worse. The goal is to make it accurate. That distinction, consistently applied, is what separates genuine security investment from an elaborate performance staged for an audience that doesn't know what it's watching.