Tech

Reporting Vulnerability Metrics to a Board That Wants Numbers

A board does not need your finding count. It needs to know whether risk is falling, how quickly serious problems get fixed, and whether anything is currently outside the tolerance the board has agreed. The NCSC’s Cyber Security Board Toolkit is built around the questions directors should ask, and most of them can be answered with four or five numbers reported consistently.

The metrics worth reporting

Time to remediate by severity is the most useful single measure, because it describes the process rather than the weather. Report the median and the worst case for critical findings, since an average hides the one that has been open for a year. Both numbers are easy to produce from any scanning platform and both are hard to argue with. Coverage comes next: the proportion of known assets actually being scanned, which tells the board whether the other numbers mean anything. Then report open findings past their agreed deadline, which is the closest thing to a risk statement your data can support. Add the count of internet-facing systems, because that number changes without anyone deciding it should.

The numbers that mislead

Raw finding counts move for reasons that have nothing to do with risk. Add a new scanner and the count doubles. Lose credentials on half the estate and it falls. Neither change reflects a change in exposure, and a board that has been trained to watch the total will read both wrongly. Average severity scores are worse, because averaging hides the single critical issue among a hundred low ones. Counting tests performed measures activity rather than outcome, and it encourages buying more tests instead of fixing more findings.

READ ALSO  Ultimate List of Gift Card Rate in 2025: Which Cards Pay the Highest Value?

“Report the same handful of numbers every quarter, even in the quarters where they look poor. The value is in the trend and in the board learning to read it. Changing the metrics because this quarter’s story is awkward destroys the only thing that made the reporting useful, which is comparability.”

William Fieldhouse, Director, Aardwolf Security Ltd

Diagram of authentication and access controls representing the controls behind board reporting

Putting numbers into business language

Translate each metric into a consequence. Instead of reporting eleven critical findings, say that eleven systems are exposed in a way that could interrupt order processing, and that three of them have been in that state beyond the agreed window. Tie remediation delays to the reason, whether that is a supplier dependency, a change freeze or a resourcing gap, because those are decisions a board can act on. Numbers without a decision attached become background noise within two meetings, and the board stops asking about them entirely by the third.

Where independent evidence helps

Internal metrics describe your own process, and a board reasonably asks how you know the process is working. A penetration test from an independent penetration testing provider gives an outside view once or twice a year, and the number worth reporting from it is how many findings were fixed and verified rather than how many were found. Consistent vulnerability management reporting between those points shows the trend, which is what turns a set of measurements into an argument for or against more investment.

Frequently asked questions about security metrics

These questions come up when reporting to a board is being redesigned.

How many metrics should a board see?

Four or five, on one page, with a short commentary. Anything longer competes with every other item on the agenda and gets skimmed, which is worse than reporting less.

READ ALSO  The Role of Data and Analytics in Japan’s Digital Transformation

Should you benchmark against other organisations?

Sparingly. Comparable data is hard to obtain and easy to misread, and your own trend over time is a far better guide to whether the work is having an effect.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button