Back to Blog
Board Reporting September 8, 2026 5 min read

Finance Built the Close. Security Still Hasn't.

Every other enterprise function has a reporting layer that separates the system of record from the system of measurement. Security is the last one still assembling the numbers by hand the week before the board meeting.

By Metric Maestro

TL;DR

Every enterprise function built its measurement layer — finance has the close, operations has throughput reporting, marketing has attribution. Security is still assembling its numbers by hand the week before the board meeting. Twenty years of detection budget filled the tool stack and left the operating layer empty. The result: MTTR means ten different things across ten CISOs, and every board answer is defensible in the room but unreproducible the following month. The fix is not another console. It is the reporting layer every other function separated from its systems of record decades ago — the layer security never built.

Every enterprise function figured out how to measure itself. Finance closes the books on a calendar the whole company plans around. Operations reports throughput, cycle time, and defect rate without anyone asking twice. Marketing argues about attribution models, but it has attribution models. Each of these disciplines went through the same arc: they agreed on what “good” looks like, standardized the definitions, and built the pipes to report the numbers on a schedule. Security is the last major function still assembling its numbers by hand the week before the board meeting.

Where the Money Went

The reason is not a lack of ambition inside security teams. It is where the money went. For twenty years, the security budget was a detection budget. Every dollar that could have gone toward measuring the operation went toward another sensor, another console, another feed. The tooling stack got denser and the operating layer above it stayed empty. Security leaders inherited a category that is exceptionally good at generating events and exceptionally bad at generating a monthly number that means the same thing two quarters in a row.

What Other Functions Take for Granted

Consider what other functions take for granted. A CFO does not build the close from scratch every quarter. A COO does not manually pull throughput from four systems and paste it into a slide. There is a layer — a set of definitions, pipes, and controls — that turns operational reality into a reported number, and everyone downstream trusts it because the layer exists. Security has none of that. Ask ten CISOs how they measure mean time to remediate a critical vulnerability and you will get ten different denominators, three different clocks, and at least one answer that quietly excludes the assets nobody wants to talk about. The metric is not wrong. It is just not a metric yet. It is a story with a number attached.

The Board Question That Takes a Week

This is what makes board reporting so painful. When the audit committee asks how the program is trending, the honest answer requires a week of analyst time, a spreadsheet nobody wants to own, and a narrative stitched around a screenshot from the previous quarter. The number that shows up on the slide is defensible in the room and unreproducible the following month. That is not a reporting problem. It is the absence of a reporting layer. Every other function solved this by separating the system of record from the system of measurement, and then treating the measurement layer as its own discipline with its own tooling, its own owners, and its own definitions.

The Instinct to Buy Another Console

The instinct in our industry is to solve this by buying another console. It will not work, and the market is beginning to notice. Another dashboard on top of the existing stack inherits the same fragmented definitions, the same manual joins, and the same quarterly scramble. What is missing is not a prettier view of the tools. What is missing is the layer that sits above the tools — the one that decides what a metric is, guarantees it is computed the same way every period, and delivers it on a cadence the business can plan around. Finance built that layer decades ago and called it the close. Security has not built it yet.

That is the layer we are building at Metric Maestro. Our work is to give security leaders a set of numbers that mean the same thing in January and July, survive the board question, and free the team from the quarterly assembly job. If you are the one being asked those questions, we would like to hear what you are being asked and how you are answering it today. Follow us for the frameworks we use to turn security operations into numbers that hold up, and reach out if you want to see what the measurement layer looks like when it is finally built for security.