An auditor asks for the working behind Q3's 87% vulnerability remediation rate. Nobody can reconstruct it — not because the team was careless, but because the number was never built to be rebuilt.
By Metric Maestro
TL;DR
An 87% vulnerability remediation rate survives a board presentation but collapses under audit — not because the number was wrong, but because no one kept the formula. Metrics built to be presented, not reproduced, become liabilities. Provenance is not a reporting nicety; it is what separates a number from evidence.
The folder opens with the confidence of a filed document. Q3 last year. Vulnerability remediation rate: 87%. It sat in a board deck, sat in a compliance packet, and now it sits in front of an auditor who wants to see it again — recomputed, reconciled, and defended. The CISO stares at the number and realizes something uncomfortable: nobody in the room can rebuild it. Not because the team is careless, but because the number was never built to be rebuilt. It was assembled, presented, and archived, and every context that made it meaningful has since drifted away.
This is the quiet crisis inside most security metrics programs. The scanner that fed the pipeline was one of three in rotation that quarter, and nobody logged which run was authoritative. The asset scope excluded a set of decommissioned hosts, but the exclusion list lived in a shared spreadsheet that has since been overwritten twice. The definition of “critical” was tightened mid-quarter after a policy revision, and the cutover date exists only in a Slack thread from an engineer who has since moved to another team. The 87% is technically accurate — for a snapshot of inputs and rules that no longer exist in any retrievable form.
Auditors are increasingly sharp about this. It is no longer enough to hand over a number; they want the lineage. Which data source. Which query. Which filter set. Which version of the taxonomy. Which point in time. When the answer to any of those questions is “we would have to reconstruct it,” the metric stops being evidence and becomes an assertion. Assertions do not survive regulatory scrutiny, and they certainly do not survive a board member who read the same figure last year and wants to understand why the trend line moved.
The deeper problem is that security programs tend to optimize for the delivery of the number, not the durability of it. Dashboards are built to render, not to reproduce. Analysts hand-craft queries under deadline pressure, paste results into slides, and move on. The moment the presentation is over, the computation dissolves. What remains is a value with no attached formula — a metric without provenance. And a metric without provenance is a story. It sounds like evidence, but under pressure it collapses into memory, and memory is not something a regulator accepts.
The fix is not more dashboards. It is deterministic computation with provenance attached at the moment the number is produced. Every metric should carry, as a first-class attribute, the formula that generated it, the sources it drew from, the filters it applied, the taxonomy version in force, and a run marker that lets anyone — this quarter, next year, three audits from now — rerun the exact same computation against the exact same inputs and get the exact same answer. When that infrastructure exists, last year’s 87% is not a mystery; it is a query you can re-execute. When it does not exist, every historical number is a liability waiting to be asked about.
Metric Maestro was built for exactly this problem. We treat provenance as the metric, not a footnote to it. Every number that leaves our platform arrives with its formula, its sources, its scope, and its run marker attached, so that a year from now — or five years from now — the answer holds. Your security numbers should survive a board question, an auditor request, and a team change without depending on anyone’s recollection. If the last year of your reporting would not survive a rerun, we should talk before the next audit cycle begins.
Whitepapers
In-Depth Comparisons
Metric Maestro vs Archer GRC
Archer is built for enterprise risk management. Metric Maestro is built for security leaders who need to prove the value of their program to the board.
Metric Maestro vs DIY Security Reporting
Most security teams start with spreadsheets. At some point, the cost of that choice becomes impossible to ignore.