A vanity metric is a number that looks impressive and cannot change a decision. It is usually large, usually rising, and usually reported because it is available rather than because anyone needs it.
Threats blocked this month. Large number, always goes up, tells you nothing about whether you are safer. It largely measures how much untargeted noise the internet sent you.
Alerts processed. Measures volume, not effectiveness. A team drowning in false positives scores well.
Training hours delivered. Effort, not effect.
Patches deployed. Says nothing about which systems still carry exploitable exposure.
Percentage of controls implemented. Implementation is not operation. See KCI.
One question sorts most of them: if this number doubled next quarter, or halved, what would you do differently?
If the honest answer is nothing, the metric is not carrying weight. It may still be worth collecting as context, but it does not belong in a set someone is expected to act on.
A second, harsher test: could a competent adversary improve this number for you? Threats blocked goes up when you are being scanned more heavily. That is not progress.
Nobody defends a vanity metric on the merits. They survive because they are easy to produce, they make the function look busy, and removing one invites the question of what replaces it.
That question is the actual work. Cutting a metric is easy; the difficulty is that the good replacement usually needs data from outside the security tools, which is harder to get.
Threats blocked becomes share of successful intrusions detected before impact.
Alerts processed becomes alert-to-incident ratio, paired with reopened case rate.
Training hours becomes behaviour change measured against a control that depends on it.
Controls implemented becomes controls operating, evidenced, across the full population.
Each replacement is harder to produce. That is the trade, and it is worth making.
From the blog