These metrics reliably show improvement because the activities they measure are within organizational control. What they do not reliably show is whether the improvement in measured activities is producing a corresponding improvement in the organization's actual security and privacy posture.
Why This Matters Now
Metrics-driven governance has never been more prevalent. Boards want dashboards. Leadership wants trends. Regulators want quantitative evidence. The response has been a proliferation of governance metrics that are measurable, reportable, and manageable. The measurement infrastructure is sophisticated. The governance question is whether the measured activities are the right activities and whether improvement in those activities translates to reduced organizational exposure.
The governance concern is not with metrics. It is with metric selection and metric interpretation. Metrics that measure activity rather than outcome show that the governance program is active. Metrics that measure outcome show whether the program is effective. Most governance metric programs heavily favor the first category.
Activity metrics improve because organizations put effort into them. Outcome metrics improve when the effort produces results. Organizations that measure activity assume the results. The assumption deserves scrutiny.
The Governance Problem Beneath the Surface
Metric selection is a governance decision with significant consequences. The metrics selected define what the organization measures, what it manages, and what it reports. Metrics that are easy to measure and consistently improvable are organizationally attractive. Metrics that are hard to measure and may reveal uncomfortable realities are organizationally resistible.
The result is metric portfolios dominated by process metrics, activity metrics, and completion rates. These are genuinely measurable and genuinely manageable. They also create the systematic illusion that the governance program is improving when what has been demonstrated is that the program's activities are increasing.
What This Actually Means in Enterprise Practice
Patch Coverage Metrics Hide What Is Not Patched
Patch coverage metrics report the percentage of systems current with required patches. They are reported as percentages and typically show improvement as patch management processes mature. What patch coverage metrics do not show is the absolute count and criticality of unpatched systems, the time-to-exploit of vulnerabilities on unpatched systems, and whether systems outside patch coverage include the organization's highest-value targets.
Training Completion Rates Do Not Show Behavior Change
Security awareness training completion rates are one of the most universally reported governance metrics. They are consistently improvable through reminder campaigns and consequence management for non-completion. They do not measure whether training produced the behavioral changes it was designed to produce. Phishing simulation results, which do measure behavioral outcomes, frequently show limited correlation with training completion rates.
An organization with a 96 percent training completion rate and a 24 percent phishing simulation click rate has demonstrated that training was completed, not that it was effective. These are different measurements that governance programs frequently conflate.
Vulnerability Closure Rates Do Not Reflect Residual Exposure
Vulnerability closure velocity metrics show how quickly vulnerabilities are closed after identification. They are improvable by investing in remediation resources and may show strong improvement while residual exposure remains material. If the vulnerability population is growing faster than the closure rate, the absolute unpatched vulnerability count may be increasing while the closure rate metric improves.
Audit Score Trends Do Not Capture Post-Audit Drift
Governance audit scores reported as trends show the scored control posture at audit time. Post-audit drift, the reduction in control diligence that occurs between audit periods, is not captured in audit score metrics. Organizations may show improving audit scores while their between-audit control posture is static or declining.
How Different Teams See This: Where They All Miss
The governance program's metric portfolio reflects what was easy to measure and comfortable to report. Outcome metrics that might reveal uncomfortable realities are less represented. This is a rational response to organizational incentives. It is poor governance practice.
Framework Control Reference
The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.
These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.
The Enterprise Reality Gap
The enterprise governance metrics reality gap is the difference between what the metric portfolio shows and what the actual risk posture is. This gap is systematically created by metric selection that favors activity over outcome. The program can show improving metrics in every reported category while the actual exposure grows in areas that the metrics do not measure.
A metric portfolio that shows only improvement is a signal worth examining. Programs genuinely improving risk posture will see some metrics plateau as baseline coverage is achieved and others reveal persistent challenges. Consistent improvement across all metrics may indicate the metrics measure what the program can control rather than what it should produce.
Enterprise Scenario
What the metrics do not show: Phishing simulation click rates have remained flat at 22 percent for three years despite training completion improvement. The 9 percent unpatched systems include three legacy servers with known exploitable vulnerabilities in the EHR integration path. The 4 percent of access reviews not completed represent 47 contractor accounts including several with unmonitored access to patient data.
The metrics show improvement. They do not show that the improvement is producing better security outcomes. The phishing vulnerability, the unpatched legacy systems, and the unreviewed contractor accounts represent the risk that exists alongside the improving metrics.
Industry Signal
Governance metrics research has consistently found that organizations with improving security metrics experience breaches at rates not significantly lower than organizations with static metrics. This finding reflects the gap between activity metrics and security outcomes: improving measured activities does not reliably reduce actual attack surface if the metrics do not measure the attack surface.
Metrics that improve reliably are metrics of what the organization controls. The risk that remains is in what those metrics do not measure. Both need to be in the governance picture.
Enabling Capabilities
- Outcome metrics alongside activity metrics: Adding phishing simulation results, breach simulation outcomes, and control effectiveness testing to the metric portfolio alongside completion and coverage rates.
- Absolute exposure metrics: Reporting absolute counts of ungoverned assets, unpatched systems, and unreviewed access alongside percentage coverage metrics.
- Attack surface measurement: External attack surface monitoring that measures what adversaries see, not only what the governance program measures.
- Metric effectiveness review: Regular assessment of whether the metric portfolio is measuring what the governance program needs to know, not only what the program is doing.
A Practical Starting Point
For each activity metric in your current portfolio, define the outcome metric that would reveal whether the activity is producing its intended result. Training completion: what is the corresponding phishing simulation click rate? Patch coverage: what is the average time-to-patch for critical vulnerabilities? Access review completion: what is the overprivileged access reduction rate? The outcome metrics reveal what the activity metrics assume.
For every activity metric, define the outcome metric that answers whether the activity worked. The outcome metrics reveal what the activities should be producing. If you do not have them, that is the metric gap to fill.
Questions Leaders Should Be Asking
- For each major activity metric we report, do we have a corresponding outcome metric that tells us whether the activity is producing the results we intend?
- When our security metrics show consistent improvement, do we have any basis for assessing whether that improvement corresponds to reduced organizational exposure, or are we measuring activity and assuming outcomes?
- What metrics in our current portfolio could show consistent improvement while our actual risk posture deteriorates?
- Are the metrics we report to the board designed to demonstrate program activity or to reveal organizational risk posture? Are we providing both?
What to Require From Vendors
Ask directly:
"Beyond coverage and completion metrics, what outcome metrics does your platform provide that reveal whether the security activities it measures are producing their intended security results?"
Expect as evidence:
- Outcome metrics alongside activity metrics in standard reporting
- Attack surface or exposure measurement capabilities
- Effectiveness testing or validation capabilities
A vendor whose reporting capabilities are exclusively activity and coverage metrics has built a program measurement tool. Ask for effectiveness measurement capabilities alongside activity measurement.
Demonstrating Diligence
- Documentation: Metric portfolio design documentation showing outcome metrics alongside activity metrics; metric effectiveness review records; exposure measurement methodology.
- Process: Regular metric effectiveness review; outcome metric development for each major activity metric; board reporting that distinguishes activity from outcome.
- Technical evidence: Phishing simulation results alongside training completion; attack surface assessment outputs; outcome metric trend analysis.
Governance metrics diligence requires demonstrating that the metric portfolio reveals actual risk posture, not only governance program activity.
Closing Perspective
Governance metrics are essential tools. They focus organizational attention, drive resource allocation, and provide the information base for governance decisions. Their value depends entirely on whether they measure what the organization needs to know.
Metrics that measure what the organization can control are easy to improve. Metrics that measure whether that control is producing results are harder to build and harder to present. Build both.
Progress metrics tell you what the program is doing. Outcome metrics tell you whether it is working. Govern with both.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
