
Key Takeaways
- 01Vanity metrics (policy count, identities under MFA) do not survive board scrutiny. Outcome metrics do: blast radius reduction, mean time to detect lateral movement, real-time-signal coverage of access decisions, crown-jewel exposure from low-trust networks, and the investment-to-impact curve.
- 02Each metric must come from a test, not an assumption. Quarterly purple-team exercises should produce the same metric the same way — that is what makes the trend line trustworthy.
- 03The investment-to-impact curve is the metric the board actually wants. It tells them where the next dollar stops moving any of the other metrics — i.e., when you should stop spending.
- 04Report progress against the same five metrics every quarter for at least four quarters before changing the dashboard. Boards trust the trend line, not the chart redesign.
Cybersecurity metrics for boards are often a dashboard of activity, not outcome. Zero Trust progress is particularly susceptible to vanity reporting (number of policies, number of identities under MFA). Here is a more useful set.
Outcome metrics that resonate
- 01Blast radius reduction — average number of resources reachable from a compromised identity, by quartile
- 02Mean time to detect lateral movement, against a tested baseline
- 03Percentage of access requests evaluated with real-time risk signal
- 04Critical asset exposure — count of crown-jewel resources reachable from low-trust networks
- 05Investment-to-impact curve — where the next dollar stops moving any of the above
Tested, not asserted
Each metric should come from a test, not an assumption. Run quarterly purple-team exercises that produce the same metric in the same way; the board will trust the trend line.
#Board Reporting#Metrics#Governance


