Glossary
GLOSSARY Measurement fundamentals

Security Metrics

Last updated 27 Jul 2026

Security metrics are the quantitative measures an organization uses to understand how its security operation is performing. The category is broad enough to be almost useless as a phrase, which is part of the problem. A count of blocked emails and a protection level agreed with the board are both security metrics, and they serve entirely different purposes.

The half nobody measures

Security has more tools than any other function in the enterprise. Each one exports numbers, and those numbers are where most metric programs start and stop.

But a large part of what a security function does never appears in a security tool. Training and awareness programmes. Tabletop and recovery exercises. Audit findings and their closure. Third-party assessments. Headcount and skills coverage. Budget commitments and what they bought. Policy exceptions granted and expired.

These live in spreadsheets, ticket queues, HR platforms, ERP systems and people’s heads. A metric set built only from tool exports describes the tooling, not the programme.

Five properties of a usable metric

It has a written definition, including the exact population it covers.

It has an owner who is accountable for the definition, and a separate owner accountable for moving the value.

It is computed the same way every period, so the trend means something.

It can be traced back to the records that produced it, because it will be challenged.

Someone acts on it. A metric that has never changed a decision is a reporting artifact.

Structuring a set

Work down rather than up. Start from the outcomes leadership cares about, derive the outcome-driven metrics that express them, then derive the operational metrics that feed those. Building upward from whatever the tools happen to export produces a large set that answers no particular question.

Keep the executive layer small. Six numbers that carry agreed targets beat thirty that carry none.

Pair leading and lagging indicators explicitly, so a degrading outcome can be traced to the signal that should have warned first.

Measuring the whole operation with Metric Maestro

Metric Maestro measures the security operation as a whole, whether the data comes from a tool, a spreadsheet, or a person. Manual entries carry supporting evidence alongside the value, so a number typed in by a human is as traceable as one pulled from an API.

Each metric is computed from a fixed definition with the source records retained behind it. Same formula every period, full history across tool swaps, every value traceable to source.