DATE

September 6, 2026

"We blocked 10,000 attacks this quarter" sounds impressive and tells the board almost nothing. Most security reporting is full of metrics that are easy to collect but don't actually indicate whether risk is going up or down. Here's what to report instead.

Retire These Vanity Metrics

Number of attacks blocked, number of vulnerabilities identified, and antivirus detection counts all share the same flaw: they measure activity, not outcome, and they almost always go up as your visibility improves rather than as your risk changes. A board that hears "we found 200 more vulnerabilities than last quarter" reasonably wonders whether the environment is getting worse or whether the scanning just got better — and most security teams can't answer that clearly.

The Metrics That Actually Matter

Instead ofReportWhy It's Better
Attacks blockedMean Time to Detect (MTTD)Shows how fast you'd actually notice a real incident
Vulnerabilities found% of critical vulns patched within SLAMeasures whether known risk is being closed, not just found
Phishing emails stoppedPhishing simulation click-rate trendTracks human risk reduction over time, not filter performance
Antivirus detectionsMean Time to Respond (MTTR)Shows containment speed once something is confirmed
"We're secure"Essential 8 / NIST maturity level trendGives an external, auditable reference point

Mean Time to Detect and Respond

These two figures, tracked quarter over quarter, tell the board more than almost any other pair of numbers. A shrinking MTTD means your monitoring is genuinely improving. A shrinking MTTR means your team and processes are getting faster at containment once something is found. Both are directly tied to financial outcomes — industry data consistently shows that faster containment correlates with dramatically lower breach costs, often by seven figures at enterprise scale.

Patch SLA Compliance, Not Just Vulnerability Counts

Track the percentage of critical and high vulnerabilities remediated within your defined SLA window (for example, 14 days for critical, 30 for high). This single metric captures both how many issues exist and how disciplined your remediation process actually is — and it's the exact evidence an auditor or insurer will ask for.

IT security manager reviewing dashboard metrics in a meeting

Third-Party and Vendor Risk Exposure

Given how many recent major breaches originated through a shared vendor rather than the victim's own network, a simple tracked metric — number of critical vendors with a current security assessment on file — is now a board-relevant figure in its own right, not just a procurement checkbox.

How Often to Report, and to Whom

  • Board / executive committee: Quarterly, trend-focused, 4–6 metrics maximum, always with a one-line "what this means" next to each number.
  • Operational security team: Weekly or monthly, more granular, including in-progress remediation status.
  • After any significant incident: A dedicated update regardless of the normal reporting cycle — boards respond far better to timely bad news than to a surprise buried in a quarterly deck.

Turn Metrics Into a Narrative

A single snapshot number rarely persuades anyone. "Our average patch time for critical vulnerabilities dropped from 45 days to 12 days after we implemented automated patch management" is a story with a before, an action, and an after — and it's far more likely to earn continued investment than a static compliance percentage on its own.

How Red Team Intelligence Can Help

Our vulnerability management engagements are built around exactly this kind of trend reporting, not one-off scan results, and our penetration testing and Essential 8 assessments give you a credible, externally validated baseline to measure progress against year over year. Get in touch if your current reporting isn't giving your board the picture it needs.