Back to Blog
Board Reporting October 1, 2026 •5 min read

The Number Survived. The Defense of the Number Did Not.

An auditor's one-line email lands on a Tuesday afternoon asking how a figure was calculated. The figure has been in every board deck for two years. The person who built the spreadsheet left in March. The number is still there. The defense of the number is not.

By Metric Maestro

TL;DR

A polite one-line email from an auditor arrives on a Tuesday afternoon: can you walk us through how this figure was calculated? The figure has appeared in every board deck for two years. The person who built the spreadsheet left in March. The workbook is still there, still producing a value when opened — but the reasoning behind that value, the assumptions, the exclusions, the business rule that suppressed certain incidents as duplicates, all lived in one person's head. This is the quiet failure mode no risk register tracks: an undefendable number, which is worse than a wrong one, because a wrong number can be corrected and an undefendable one has to be withdrawn. The structural fix is deterministic computation — raw sources captured and versioned, transformations expressed as code, metrics produced identically on demand by anyone who can read the pipeline. The method survives the person. The number survives the turnover.

The auditor’s email landed on a Tuesday afternoon. One line, polite, routine: “Can you walk us through how this figure was calculated?” The figure in question had appeared in every quarterly board deck for the past two years. It was the kind of number nobody questioned, because it had always been there. The person who built the spreadsheet left in March. Nobody has opened the workbook since. The tabs are colored. The formulas reference cells that reference other cells across six sheets. One VLOOKUP points to a CSV on a laptop that was wiped and reissued to a new hire in April. The number is still there. The defense of the number is not.

The Failure Mode Nobody Puts on a Risk Register

This is the quiet failure mode nobody puts on a risk register. It does not show up in a pen test. It does not trigger an alert. It surfaces only when someone external asks a reasonable question, and the organization discovers that the answer departed with a two-week notice period and a farewell lunch. The spreadsheet is still there, technically functioning, producing a value every time it is opened. But the logic behind that value, the assumptions, the exclusions, the business rule that decided which incidents counted and which were suppressed as duplicates, all of it lived in one person’s head. The workbook was the artifact. The reasoning was the person.

The Same Pattern in Nearly Every Program

We see this pattern in nearly every security program we audit. A control effectiveness score built on a scoring rubric that was never written down. A mean-time-to-remediate metric that silently excludes a category of findings because someone decided, in 2022, that those findings were “noise.” A compliance coverage percentage whose denominator shifts quarter to quarter because the asset inventory feeding it is regenerated by a script nobody maintains. These numbers are not wrong in a way you can prove. They are undefendable, which is worse. A wrong number can be corrected. An undefendable number has to be withdrawn, and withdrawing a number from a board deck is the kind of event that ends careers and triggers investigations.

The Method Was Never Separated From the Person

The underlying issue is not that spreadsheets are bad, or that the person who left was negligent. The issue is that the method of computation was never separated from the individual who performed it. There was no definition that could be read independently of the workbook. There was no raw source that could be re-queried. There was no transformation step that could be re-run. There was no timestamp proving when the value was computed and against what version of the input. The number existed, but the chain of evidence that would let anyone else arrive at the same number did not. That is institutional memory failure, and it is one resignation away from happening to every metric your program reports.

Deterministic Computation Is the Structural Answer

Deterministic computation is the structural answer. The raw source is captured and versioned. The transformation is expressed as code, not as a sequence of mouse clicks across colored tabs. The metric is produced on demand, by anyone with access, and the output is identical every time the inputs are identical. When the auditor asks how it was calculated, the answer is not a person. The answer is a pipeline anyone can read, re-run, and verify. The method survives the person. The number survives the turnover.

This is what Metric Maestro was built to deliver. We help security programs replace fragile, person-dependent spreadsheets with reproducible metric pipelines that defend themselves — to auditors, to boards, to the next person who inherits your seat. Your security numbers should outlast the people who built them. Let us show you what that looks like.