TLDR
Most organizations report security health using metrics that measure activity rather than attacker opportunity. Vulnerability counts, patch rates, and completed audits tell leadership how busy the security team is; they don’t reveal how far an attacker could get or how long they’d go undetected. Two of the most consequential breaches of 2024 happened inside organizations that had active security programs, ran third-party audits, and reported metrics upward. The problem wasn’t that they weren’t measuring anything. The problem was what they were measuring.
Security teams generally report what’s easy to count. Vulnerabilities patched. Findings closed. Percentage of endpoints covered. Training completions. Audit results. These are legible, they populate dashboards cleanly, and they give the appearance of a program moving forward. Boards receive them, nod, and move on.
The problem is that none of those numbers answer the question an attacker would care about: how long can I be inside before anyone notices, and how far can I move in that time?
Compliance frameworks didn’t intend to create this gap. HIPAA, PCI-DSS, SOC 2, and their counterparts were designed to establish floors, not to characterize actual risk posture. But over time, the audit requirements those frameworks created shaped what gets measured and reported upward. Organizations built their security reporting around what auditors asked for. Auditors ask for activity. Boards started believing that sufficient activity meant sufficient security. It often doesn’t.
What Two Breaches Actually Show Us
The argument isn’t theoretical. Two of the most significant incidents of the past two years demonstrate exactly what happens when activity metrics are healthy and attacker-opportunity metrics are invisible.
Change Healthcare, February 2024. Attackers affiliated with the ALPHV/BlackCat ransomware group accessed a Citrix remote access portal using stolen employee credentials. The portal had no multi-factor authentication enabled. From there, they spent nine days moving laterally through the network, exfiltrating data, and staging a ransomware deployment before anyone detected them. The final cost exceeded $1.5 billion. More than 190 million Americans had their health information compromised.
What makes this case relevant to the metrics conversation is a detail that emerged during congressional testimony: UnitedHealth Group confirmed that third-party auditors had been regularly hired to review Change Healthcare’s technology infrastructure. The audits were running. The reviews were completing. The findings were presumably being tracked. And a critical internet-facing portal sat without MFA, undetected by any of those processes, until an attacker found it first. The activity metrics didn’t measure the exposure because the exposure wasn’t what the metrics were designed to find.
Microsoft / Midnight Blizzard, November 2023 through January 2024. A Russian state-sponsored threat group gained access to Microsoft’s corporate email systems, including accounts belonging to senior leadership and the cybersecurity team, by compromising a legacy test account that lacked MFA. The intrusion began in November 2023. Microsoft detected it on January 12, 2024, roughly two months later.
The technical detail worth understanding here is how the attackers stayed invisible for that long. They deliberately kept their password spraying attempts at a low volume, specifically to evade detection thresholds that flag suspicious login activity based on failure rate. The detection mechanism Microsoft was using had a known threshold. The attacker stayed under it. This is what it looks like when an adversary understands your metrics better than you do. The measurement itself became the blind spot.
Both incidents involved organizations with mature security teams, documented programs, and active oversight. The gap wasn’t negligence in the conventional sense. It was a measurement problem.
The Metrics That Reflect Attacker Opportunity
Shifting from activity metrics to attacker-opportunity metrics doesn’t require abandoning compliance reporting. It requires adding a second lens.
Mean Time to Detect (MTTD)
According to Mandiant’s M-Trends 2025 report, the global median dwell time in 2024 was 11 days. When organizations discovered breaches through internal detection, the median was 10 days. When external parties had to notify them, it was 26 days. That 16-day gap is a direct measurement of detection program quality, and it’s one most organizations don’t track at all. If your team can’t answer what your current MTTD is, that’s worth knowing.
Lateral movement opportunity
Once inside with a standard user account, how far can an attacker move? The answer is determined by network segmentation, privilege boundaries, and credential hygiene across the environment. In the Change Healthcare incident, nine days of undetected lateral movement preceded the ransomware deployment. The perimeter had been crossed; what extended the damage was the absence of internal boundaries that would have contained it. This is something an offensive assessment can measure directly. A vulnerability scan cannot.
Detection coverage gaps
Most organizations assume their monitoring covers their environment. Offensive assessments routinely reveal that significant portions of the environment generate no logs that anyone is watching. The assumption of coverage and the reality of coverage are frequently different. The gap is what attackers move through.
Privilege escalation paths to crown jewels
Not how many privileged accounts exist, but how many routes lead from a compromised standard user to the assets that would be catastrophic to lose. Attackers don’t need to find the most direct path. They need to find one path. If your security program isn’t mapping those paths, you don’t know what you’re defending.
These metrics are harder to produce than a patch count, which is exactly why they don’t appear on most dashboards. Generating them typically requires someone to think like an attacker, not like an auditor.
What Leadership Actually Needs
Boards and executives are not disengaged from security. They’re receiving metrics that don’t translate into decisions.
“We patched 94% of critical vulnerabilities this quarter” does not tell a CEO whether operations would survive a targeted attack. “If an attacker compromised a standard employee account today, our detection would flag it in approximately this many days, and here is what they could reach before that” is a statement that maps directly to business continuity and liability. Those are different conversations, and they drive different investment decisions.
The governance dimension matters here. The SEC’s cybersecurity disclosure rules now require public companies to report material incidents promptly and to describe their cybersecurity risk management programs annually. Following the Change Healthcare breach, a CEO testified before Congress. Following the Microsoft breach, the company disclosed to regulators and the public. These are no longer incidents that stay inside the security team. They become board-level events with legal, regulatory, and reputational consequences. The question of whether the board understood the actual risk posture before the incident is one that regulators, shareholders, and counsel will ask.
If a board cannot answer “how long would an attacker go undetected in our environment,” that’s not a gap in the dashboard. It’s a governance gap, and it carries exposure.
One Thing to Do This Week
Pull your last security report to leadership. Count how many metrics measure defender activity (patches closed, audits completed, training completions, findings resolved) and how many measure attacker opportunity (time to detect, coverage gaps, lateral movement boundaries, escalation paths).
If the ratio is weighted almost entirely toward activity, that’s the starting point for a different conversation. Bring one question to your security team: “If an attacker compromised a standard employee account today, what is the first alert that would fire, and when?” If the answer is immediate and specific, you have a baseline. If the answer requires a meeting to figure out, you have a priority.
This isn’t an indictment of the security team. Most practitioners know this gap exists. The structure of security reporting doesn’t create space to surface it. A single honest conversation about what the program can and cannot see is often where the real work begins.
The Measurement Problem Is the Security Problem
Compliance programs exist for a reason. Audit requirements serve real purposes. None of that is the issue. The issue is that organizations have quietly allowed compliance reporting to substitute for risk characterization, and the two are not the same thing.
The organizations behind the most damaging recent breaches weren’t skipping their audits. They were measuring the wrong things and trusting the results. Building a security program that leadership can actually act on requires measuring what attackers care about: how long they’d have, how far they’d get, and what they’d reach. Everything else is paperwork.

