Back to Blog
Board Reporting October 6, 2026 •5 min read

The Numbers Have to Travel. Security's Don't.

Finance settled measurement with GAAP. Operations with OEE and cycle time. Those numbers travel between places, years, and teams. Security's don't — and that is a category gap, not a tooling one.

By Metric Maestro

TL;DR

Every other function in the enterprise agreed on how to count years ago. Finance settled it with GAAP, sales with pipeline stages, operations with OEE and cycle time. Those numbers travel. A gross margin figure means the same thing in Dallas as in Dublin, and the same thing in 2016 as in 2026. Security has nothing like this. Every CISO is still building the measurement layer from scratch, in a spreadsheet, the week before the board meeting. The gap is roughly a decade. The tooling market in security is mature, but what never shipped alongside it was a shared definition of what the numbers on those dashboards actually mean. Two companies running the same vendor report MTTR differently. The same company running two tools reports vulnerability counts differently. The same team, year over year, restates its own numbers because the underlying definition drifted. This is not a tooling gap. It is a category gap. Finance did not solve measurement by shipping better accounting software — it solved measurement by agreeing, as a profession, on what counted as revenue and how the books closed. Security did the reverse. The software arrived first, and the discipline of measurement was left to whoever happened to be running the program. The result: numbers that do not travel between companies, between years, or between tools. A category has to exist before the numbers can travel. Security measurement, as its own discipline, has to be named and defended before any tool can carry it.

Every other function in the enterprise agreed on how to count years ago. Finance settled it with GAAP. Sales settled it with pipeline stages. Operations settled it with OEE and cycle time. These numbers travel. A gross margin figure means the same thing in Dallas as it does in Dublin, and the same thing in 2016 as it does in 2026. An operations leader can walk into any plant on the planet and read the board. A finance leader can hand a prior-year number to an analyst who has never met them, and the analyst can use it. Security has nothing like this. Every CISO is still building the measurement layer from scratch, in a spreadsheet, the week before the board meeting.

The Gap Is Roughly a Decade

The gap is not small. It is roughly a decade, by our count, and in some dimensions longer. The tooling market in security is mature. There are detection platforms, posture platforms, identity platforms, risk platforms, and GRC platforms, each with dashboards and each with a reporting view. What never shipped alongside them was a shared definition of what the numbers on those dashboards actually mean. Two companies running the same vendor will report mean time to remediate differently. The same company running two tools will report vulnerability counts differently. The same team, year over year, will restate its own numbers because the underlying definition drifted when a tool was swapped, a team reorganized, or a framework was adopted mid-cycle.

This Is a Category Gap, Not a Tooling Gap

This is not a tooling gap. It is a category gap. Finance did not solve measurement by shipping better accounting software. Finance solved measurement by agreeing, as a profession, on what counted as revenue, what counted as a liability, and how the books closed. The software came after the discipline. Security has done the reverse. The software arrived first, in waves, and the discipline of measurement was left to whoever happened to be running the program at the time. The result is that every CISO is reinventing the vocabulary, and because the vocabulary is private, the numbers do not compound. They do not travel between companies, which breaks benchmarking. They do not travel between years, which breaks trending. They do not travel between tools, which breaks continuity through every migration and acquisition the program will ever go through.

The Board Feels It First

The board feels this before anyone else does. A board that has read a hundred finance decks and a hundred operations decks is being handed a security deck that reads like a different language every quarter. The questions they ask — is this better than last year, is this better than our peers, is this money well spent — are questions the current measurement layer cannot answer with any confidence. The deck gets rebuilt. The definitions shift again. The cycle repeats. Over time, the function loses credibility not because the work is poor but because the numbers describing the work refuse to hold still.

A Category Has to Exist Before the Numbers Can Travel

A category has to exist before the numbers can travel. Security measurement, as its own discipline, has to be named, defined, and defended before any tool can carry it. That means a shared vocabulary, a shared method for closing the books on a quarter, and a shared standard for what a metric has to survive to count as a metric at all — a company change, a year change, a tool change, a board question. That is the work we are doing at Metric Maestro, and the work the category has been missing. If your security numbers have to be rebuilt every time something around them moves, we would like to talk. Follow us for the full breakdown of what the category looks like when it finally arrives.