Reporting Vulnerability Metrics to a Board That Wants Numbers

A board does not need your finding count. It needs to know whether risk is falling, how quickly serious problems get fixed, and whether anything is currently outside the tolerance the board has agreed. The NCSC’s Cyber Security Board Toolkit is built around the questions directors should ask, and most of them can be answered with four or five numbers reported consistently.
The metrics worth reporting
Time to remediate by severity is the most useful single measure, because it describes the process rather than the weather. Report the median and the worst case for critical findings, since an average hides the one that has been open for a year. Both numbers are easy to produce from any scanning platform and both are hard to argue with. Coverage comes next: the proportion of known assets actually being scanned, which tells the board whether the other numbers mean anything. Then report open findings past their agreed deadline, which is the closest thing to a risk statement your data can support. Add the count of internet-facing systems, because that number changes without anyone deciding it should.
The numbers that mislead
Raw finding counts move for reasons that have nothing to do with risk. Add a new scanner and the count doubles. Lose credentials on half the estate and it falls. Neither change reflects a change in exposure, and a board that has been trained to watch the total will read both wrongly. Average severity scores are worse, because averaging hides the single critical issue among a hundred low ones. Counting tests performed measures activity rather than outcome, and it encourages buying more tests instead of fixing more findings.
“Report the same handful of numbers every quarter, even in the quarters where they look poor. The value is in the trend and in the board learning to read it. Changing the metrics because this quarter’s story is awkward destroys the only thing that made the reporting useful, which is comparability.”
William Fieldhouse, Director, Aardwolf Security Ltd

Putting numbers into business language
Translate each metric into a consequence. Instead of reporting eleven critical findings, say that eleven systems are exposed in a way that could interrupt order processing, and that three of them have been in that state beyond the agreed window. Tie remediation delays to the reason, whether that is a supplier dependency, a change freeze or a resourcing gap, because those are decisions a board can act on. Numbers without a decision attached become background noise within two meetings, and the board stops asking about them entirely by the third.
Where independent evidence helps
Internal metrics describe your own process, and a board reasonably asks how you know the process is working. A penetration test from an independent penetration testing provider gives an outside view once or twice a year, and the number worth reporting from it is how many findings were fixed and verified rather than how many were found. Consistent vulnerability management reporting between those points shows the trend, which is what turns a set of measurements into an argument for or against more investment.
Frequently asked questions about security metrics
These questions come up when reporting to a board is being redesigned.
How many metrics should a board see?
Four or five, on one page, with a short commentary. Anything longer competes with every other item on the agenda and gets skimmed, which is worse than reporting less.
Should you benchmark against other organisations?
Sparingly. Comparable data is hard to obtain and easy to misread, and your own trend over time is a far better guide to whether the work is having an effect.



