A board deck gets a green checkmark on Monday. By Thursday, one number is wrong by four full points — in a direction that changed the story the slide was telling. Nobody caught it in the room.
By Metric Maestro
TL;DR
A board deck survives the room on Monday with a green checkmark. By Thursday, one number is wrong by four full points — traced back to a retired compensating control nobody noticed in the CSV. The failure was not an error; it was the arithmetic sum of three reasonable decisions and one silent assumption. The fix is not a smarter review cycle. It is the same formula, the same source, the same cadence, every time.
The board deck was approved on Monday. By Thursday, one of the numbers on it was wrong. Not stale, not misinterpreted, not off by a rounding decimal — actually wrong, by four full points, in a direction that changed the story the slide was telling. Nobody caught it in the room. The trend line pointed the right way, the footnote cited the right control framework, and the CFO nodded. The room moved on to the next slide, and the deck went into the archive with a green checkmark next to it. That checkmark is the part that should keep you up at night, because the number underneath it had already started to rot before the meeting adjourned.
Here is what the post-mortem turned up. An analyst pulled a CSV the previous Friday to get ahead of the weekend. A second analyst, working from a different inbox thread, reshaped that CSV in a shadow spreadsheet to match the board template. A third person — the one who actually built the slide — pulled the reshaped file into the deck on Sunday night, trusting that upstream work was current. Somewhere in that chain, a compensating control had been retired, and the export predated the change. Nobody did anything wrong in isolation. Everyone did their piece. The number that reached the board was the arithmetic sum of three reasonable decisions and one silent assumption, and it did not survive contact with a fresh query on Wednesday night.
This is the specific failure mode that manual assembly produces. It does not generate loud failures. It generates plausible ones. Every hand that touched the number can point to the hand before it. The analyst was on PTO. The spreadsheet was the latest one in the thread. The export was labeled with the right quarter. Nobody lied. Nobody cut corners. And yet the output was wrong by four points in a direction that told a different story about program health than the truth warranted.
Review cycles do not catch this class of failure. A reviewer reads for typos, formatting, and narrative coherence. They do not re-pull the source data. They do not audit which version of the file made it into the slide. They trust the upstream process the same way the slide-builder trusted the reshaped CSV. That trust is not careless — it is how humans coordinate complex work under deadline. It is also how a plausible number replaces a true one without anyone being the villain.
Once the number is wrong and someone figures that out, deniability is the only currency left — and the disturbing thing is that nobody manufactured it on purpose. The CISO cannot say “I own this number” with real conviction, because the number was assembled by committee across three inboxes and two file versions. Ownership got distributed until it evaporated. The analyst who pulled the original CSV can point to the second analyst’s reshaping step. The second analyst can point to the inbox thread they were working from. The slide-builder can point to the file they were handed. Everyone is telling the truth about their piece. The number, as a whole, belongs to no one.
This is not a governance failure in the conventional sense. Nobody skipped a required step or bypassed a control. The provenance dissolved gradually, across a normal weekend’s worth of reasonable handoffs, and by Monday morning it was gone. The green checkmark did not approve the number. It approved the deck that contained the number, and the deck looked fine.
This story is not unusual. In conversations with security leaders over the last year, roughly two out of three describe some version of it: a board-facing metric that moved between the deck being approved and the next internal review, traced back to a manual step that seemed harmless in the moment. The common thread is never a bad analyst or a sloppy team. It is that the formula was reconstructed from memory or from a template, the source was chosen by whoever happened to be closest to the data, and the timing was governed by whenever the export happened to land. Three variables, none of them locked, all of them capable of moving the answer.
The frequency matters. If this were a one-in-ten occurrence, process discipline could absorb it. When it shows up in two out of three programs, it is not a discipline problem — it is a structural one. The structure of manual assembly guarantees it. Every week, every reporting cycle, every board prep, the same variables are unlocked, and the probability that at least one of them moves the number compounds.
The instinct is to add a review step. A second sign-off on the export. A confirmation email to the upstream analyst. A checklist before the deck goes to the printer. These things help at the margins. They do not close the gap, because the gap is not in the review — it is in the construction. A smarter reviewer would have caught the four-point error if they had access to the same fresh query run on Wednesday. They did not, because the review happened against the document, not against the source.
The structural fix is the one that removes the variable: the same formula, pulled from the same source, on the same cadence, every single time — so that the number on Monday’s slide is provably the same number you would get if you re-ran the computation on Thursday, or the following Thursday, or in front of the auditor six months from now. Deterministic computation with attached data lineage means no one assembles the number. The number produces itself, and what the room approves is an output they could reproduce on demand rather than a slide someone built over a weekend.
Boring. Repeatable. Defensible. The metric stops being a story someone assembled and becomes a fact the organization can stand behind.
If the story at the top of this post felt uncomfortably familiar — if you can name the quarter it happened to you — you are not alone, and you are not stuck with it. Metric Maestro exists so that your board metrics come from one source, run through one formula, and survive the question that always comes forty-eight hours after the deck is approved. Talk to us before the next cycle, not after.
Whitepapers
In-Depth Comparisons
Metric Maestro vs Archer GRC
Archer is built for enterprise risk management. Metric Maestro is built for security leaders who need to prove the value of their program to the board.
Metric Maestro vs DIY Security Reporting
Most security teams start with spreadsheets. At some point, the cost of that choice becomes impossible to ignore.