Back to Blog
Board Reporting August 19, 2026 5 min read

Every Function Got Its Measurement Layer. Security Got Tools.

Finance got ERP. Sales got CRM. Engineering got observability. Security got sixty tools and a spreadsheet. The measurement layer every function built has never materialized for security — and the gap is about to close.

By Metric Maestro

TL;DR

Every enterprise function built its measurement layer in sequence — ERP for finance, CRM for sales, BI for operations, observability for engineering. Security got hundreds of tools and no connective tissue. Every CISO rebuilds the reporting infrastructure from scratch, every quarter, in every company. That is a category problem, not a maturity problem. The measurement layer for security has never been built. It is about to be.

Every other function in the enterprise learned to measure itself. Finance did it first, then sales, then operations, then engineering. Security got more tools than any of them — and still improvises the monthly board deck in a spreadsheet. That contradiction is the most revealing fact about our discipline right now, and it has almost nothing to do with the difficulty of the work.

The Functions That Built Their Layer First

Consider the timeline. Finance got its measurement layer in the 1970s when ERP systems turned the general ledger into something a CFO could interrogate on demand. Sales got CRM in the 1990s and, with it, a pipeline that could be forecast, sliced, and defended in front of a board. Operations got BI dashboards in the 2000s that turned throughput, quality, and cost into a shared vocabulary across the org chart. Engineering got observability in the 2010s — the moment when uptime stopped being a story and became a number with a decimal point. Each of these functions moved from craft to accountability the same way: someone built the infrastructure that made measurement routine.

What Security Got Instead

Security never got that layer. What it got instead was tools — hundreds of them. The average enterprise security program runs somewhere between sixty and eighty distinct products, each generating its own telemetry, its own severity scale, its own definition of what a “finding” means. None of them were built to answer the questions a board actually asks. How exposed are we compared to last quarter. Where is control coverage weakest. What is the trend on mean time to remediate a critical. Is the program getting better or worse against the threats we said we cared about. These are simple questions. The infrastructure to answer them consistently, month over month, does not exist off the shelf.

The Ritual Nobody Names

So every CISO improvises. They pull exports from the vulnerability scanner, the EDR, the SIEM, the GRC platform, the ticketing system. They stitch them together in a shadow spreadsheet the week before the board meeting. They pick metrics that look defensible and hope no one asks how the denominator was calculated. We have watched this ritual play out in Fortune 500s and Series B startups with equal frequency. It is not a discipline problem. It is not a maturity problem. It is a category problem: the measurement layer for security has never been built, so every leader rebuilds it from scratch, every reporting cycle, in every company.

A Pattern That Has Played Out Before

The pattern is familiar to anyone who has watched a category form. Before Salesforce, sales operations was a spreadsheet job too. Before Datadog, engineering leaders described system health in adjectives. In each case, the underlying work was not new — what changed was that someone built the infrastructure that turned improvisation into instrumentation. Security is at that exact inflection point now. The raw signal is already there, buried across those sixty-plus tools. What is missing is the connective tissue: a system of record for security performance that produces the same number twice, defends the definition when challenged, and shows the trend without a human assembling it by hand.

The Standard Every Function Already Meets

We think this gap is about to close, and quickly. The leaders who adopt early will not be the ones with the loudest dashboards. They will be the ones whose numbers survive the next board question — the ones who can point to a methodology, a definition, and a trend line, and stand behind all three without a caveat. That is the standard every other function in the enterprise already meets. It is the standard security is about to be held to, whether the tooling catches up in time or not.

Metric Maestro exists to build that layer. If your monthly board deck still lives in a spreadsheet, follow us for the frameworks, benchmarks, and receipts as this category takes shape — or reach out directly if you’re ready to stop rebuilding it from scratch every quarter.