A counter-metric is a second measurement chosen specifically because it would degrade if the first one were being improved the wrong way. It is the cheapest defence against Goodhart’s Law and one of the least used.
Pick the metric you intend to put a target on. Ask how a competent team under pressure could move it without improving the underlying condition. Then measure that.
Time to close alerts pairs with reopened case rate. Closing faster by closing carelessly shows up in reopens.
Phishing click rate pairs with report rate. If clicks fall and reports fall too, people learned to ignore the simulation rather than to recognise the threat.
Open critical findings pairs with severity downgrade volume. A falling count with a rising reclassification rate is not remediation.
Patch deployment speed pairs with change-induced incident rate. Speed bought by skipping testing is visible on the other side.
Mean time to respond pairs with incident recurrence. Fast containment that leaves the root cause in place produces repeats.
The pair usually reveals a real tradeoff rather than bad faith. Speed and thoroughness genuinely trade off. Making that visible turns an argument about whether someone is cutting corners into a conversation about where the balance should sit.
That is the more valuable use. Teams under a single-metric target often know they are making a trade and have no way to say so. The counter-metric gives them the language.
The counter-metric does not need a target. It needs to be visible next to the primary metric and reviewed at the same time.
Two is usually enough. A metric with four counter-metrics has become a scorecard, and the primary target loses its force.
Choose the pair when you set the target, not after the number starts looking suspicious.
From the blog