Glossary
GLOSSARY Measurement fundamentals

Outcome-Driven Metric (ODM)

Last updated 27 Jul 2026

An outcome-driven metric expresses security performance as a protection level that a non-technical executive can understand, debate, and fund. The concept comes from Gartner’s outcome-driven metrics work and has since spread into how many boards frame the security conversation.

Three properties

Three properties, roughly.

It describes a result rather than an activity. “Share of endpoints restored to a known-good state within four hours” is an outcome. “Number of endpoint scans run” is an activity.

It is written in language a business executive can act on, without needing a translator.

It can be dialed. Spend more and the number moves in a predictable direction. That relationship is what turns a metric into a budget conversation rather than a status update.

The protection level conversation

The point of an ODM is not the number itself. It is that the number can carry a target set by someone outside the security team.

Security leadership presents the current level and what it costs. The business decides whether that level is enough. The agreed target becomes a protection level agreement. Responsibility for the level of risk being carried moves to where it belongs.

What ODMs demand of your data

An ODM has to be computed the same way every period, or the protection level cannot be negotiated against it. That sounds obvious and is routinely violated.

The usual pattern: the metric is assembled by hand from three exports, the analyst who built the spreadsheet moves teams, the vendor gets replaced at renewal, and the number that goes to the board in March is not the number that went in the previous September. Nobody notices, because nothing records how either was produced.

Producing ODMs with Metric Maestro

Metric Maestro computes each metric from a fixed definition against a stored set of source records. Same formula every period. Full history across tool swaps. Every value traceable back to the records behind it.

That is what makes a protection level agreement enforceable rather than aspirational. When the board asks how the number was derived, or an auditor asks whether last year’s figure was produced the same way, the answer is already there.