Useful metrics connect a defined measurement to a decision: patch latency, detection coverage, mean time to detect and respond, control test results, exception counts, and exposure trends. Weak metrics count activity — tickets closed, alerts processed — without showing whether risk changed.
Key points
Precise definitionsName the data source, population, time window, owner, and the decision the number informs.
Outcomes over activityMeasure coverage, correctness, and timeliness rather than volume of work performed.
Important limitationMetrics are models of security, not proof of it. Goodhart’s law applies — once a number becomes a target, teams optimize the number instead of the protection it was meant to represent.