TL;DR: SOC metrics still centred on volume can cause teams to optimise activity rather than risk reduction, creating noise, mis-prioritisation, and inefficient remediation, according to Hadrian. The underlying governance issue is that operational reporting can reward throughput while obscuring whether detection and exposure management are actually improving.
At a glance
What this is: This is a brief opinion-led security post arguing that SOC metrics designed around volume can push teams toward the wrong work.
Why it matters: It matters to IAM, NHI, and broader security programmes because measurement shapes control behaviour, and volume-led reporting can hide real access, exposure, and remediation gaps.
👉 Read Hadrian's post on why SOC metrics should measure outcomes, not volume
Context
SOC metrics should measure whether security work reduces exposure, not how much activity a team produces. In practice, volume-based reporting can reward alerts closed, scans run, or findings generated while leaving the highest-risk paths untouched. For identity-heavy environments, that creates blind spots around privileged access, service accounts, and other non-human identities.
The governance problem is not unique to offensive security. Any programme that measures motion instead of risk can drift away from effective control design, especially where identity, access, and remediation are spread across multiple teams. That makes the post relevant to IAM and PAM leaders as well as SOC and GRC practitioners.
Key questions
Q: How should security teams measure whether exposure management is actually reducing risk?
A: Measure whether validated attack paths, privileged access paths, and high-risk exposures are being removed, then confirm those fixes with retesting. Counts of alerts or scans only show activity. A useful metric changes when the control state changes, especially for identity-related risk.
Q: Why do volume-based SOC metrics create security blind spots?
A: Because they reward outputs that are easy to count, not outcomes that reduce attack surface. Teams can generate more alerts, tests, or findings while the same privilege, identity, or exposure weaknesses remain in place. That is measurement without governance.
Q: What do security teams get wrong about offensive testing metrics?
A: They often treat the number of tests or findings as proof of maturity. In reality, the important question is whether the testing changed remediation priority, closed exploitable paths, and improved control coverage. If not, the testing output is just noise.
Q: How can organisations tell if their reporting model is driving the wrong behaviour?
A: Look for incentives that increase activity without decreasing exposure, such as more scans with the same unresolved findings or more detections with no faster remediation. When metrics reward visibility over risk reduction, the programme is optimising appearances instead of security.
Technical breakdown
Why volume-based SOC metrics create false confidence
Volume metrics are easy to collect, but they often measure effort rather than control effectiveness. Counts of tests, alerts, or findings do not tell you whether the organisation reduced attack paths, removed privilege sprawl, or improved detection quality. In offensive security and exposure management, this creates a classic governance failure: teams can appear busy while the same weaknesses persist. The right metric has to connect activity to a change in risk state, not just a larger output stream.
Practical implication: replace raw output counts with metrics tied to reduced exposure, fewer exploitable paths, or faster remediation of the highest-risk findings.
How identity and privilege assumptions distort operational reporting
Identity is often where measurement breaks down first, because access is dynamic and distributed across human and non-human identities. A SOC can report on detections or scans while missing whether privileged accounts, service accounts, API keys, or tokens still provide durable paths to compromise. That is especially dangerous in environments using automation, because non-human identities can expand faster than review cycles can keep pace. Metrics need to show whether access is being reduced, scoped, and retired, not just whether it was observed.
Practical implication: add identity-scoped measures such as standing privilege count, stale secrets, and time-to-revoke for high-risk accounts.
What better security metrics should measure instead
Better metrics link offensive testing, exposure validation, and remediation into a single risk-reduction loop. That means tracking whether critical assets are being found, whether exploitable conditions are being confirmed, and whether fixes are closing the specific exposure that was validated. In governance terms, this is closer to outcome-based measurement than activity-based reporting. For readers using adversarial exposure validation or agentic testing, the goal is to prove that risk declined, not just that more tests were run.
Practical implication: build scorecards around validated exposure reduction, remediation closure quality, and repeat-test failure rates rather than activity totals.
NHI Mgmt Group analysis
Volume metrics create governance theatre when they are not tied to exposure reduction. Security teams can optimise for visible output while the real risk remains unchanged. That is particularly damaging in offensive security, where the point is to expose what matters, not to generate a higher count of activity. Practitioners should treat any metric that cannot be linked to a change in attack surface as incomplete.
Excess alerting and testing can hide NHI governance debt: when service accounts, tokens, and API keys remain outside the measurement model, teams miss the access paths that matter most. This is a recurring failure mode in modern environments because non-human identities scale faster than manual review. The governance conclusion is simple: if identity is not in the metric, identity risk is not really being measured.
Outcome-based measurement is becoming the more credible control model for exposure management. That means measuring whether specific risks were confirmed, contained, and removed, not whether more work was produced. For teams operating under NIST-CSF and NIST-800-53, the practical shift is toward evidence that controls reduced exposure, not just evidence that activity occurred.
Named concept: metric misalignment debt. This is the gap between what a team records and what the organisation actually needs to know about risk. Once that gap exists, dashboards can look healthy while control coverage weakens. Practitioners should assume the measurement model itself can become a security liability.
Identity-aware validation is the missing layer in many operational scorecards. If offensive testing does not feed back into IAM, PAM, and NHI remediation, the programme learns too slowly. The field should treat identity-linked exposure as a first-class measurement category, not a side effect of broader SOC activity.
What this signals
Volume-led reporting is becoming less defensible as identity risk, agentic behaviour, and exposure validation converge. Programmes that cannot show a direct link between testing activity and reduced attack surface will struggle to justify their control model to both executives and auditors. The practical response is to move from output dashboards to evidence of risk closure.
Metric misalignment debt: once measurement rewards activity over reduction, the programme accumulates hidden risk in privileged access, non-human identities, and remediation backlog. That debt is hardest to see in environments where teams count work but do not track whether the work changed the security state. The answer is to connect offensive findings to IAM, PAM, and exposure-management closure criteria.
For identity-heavy environments, the next reporting step is to treat access scope, secret age, and privilege persistence as board-level indicators, not specialist telemetry. That makes reporting more useful for Ultimate Guide to NHIs-style governance conversations and closer to how exposure actually accumulates.
For practitioners
- Redesign SOC scorecards around exposure reduction Track whether validated attack paths were removed, not how many alerts, scans, or tests were produced. Tie each scorecard item to a remediated condition and a measurable decrease in exploitable access.
- Add identity-specific risk measures Include standing privilege counts, stale secrets, and time-to-revoke for privileged accounts, service accounts, API keys, and tokens. These figures show whether identity risk is shrinking or just being reported more often.
- Close the loop between testing and remediation Require every high-risk finding from offensive validation to map to an owner, a fix date, and a retest result. Without that loop, the programme measures discovery instead of control improvement.
- Use outcome evidence in executive reporting Report on reduced exposure, failed re-test rates, and removed privilege pathways rather than raw output volumes. That keeps leadership focused on risk change instead of operational noise.
Key takeaways
- Volume-based SOC metrics can create the appearance of progress while leaving exposure unchanged.
- Identity and non-human access need to be part of the measurement model if teams want to see real risk.
- The strongest reporting models tie offensive testing to remediation closure, retesting, and reduced attack surface.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Outcome-based monitoring is relevant to the article's critique of volume metrics. |
| NIST SP 800-53 Rev 5 | SI-4 | System monitoring should evidence effective detection, not just higher telemetry volume. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Logging is useful only if it supports actionable detection and investigation outcomes. |
| NIST AI RMF | MEASURE | The article is fundamentally about measuring whether security work changes risk. |
Define metrics that demonstrate risk reduction, governance quality, and control effectiveness.
Key terms
- Metric Misalignment Debt: The accumulated risk created when a security programme measures activity more easily than it measures exposure reduction. It appears as healthy dashboards, busy teams, and unresolved attack paths that stay hidden because the wrong signals are being tracked.
- Exposure Reduction: Exposure reduction is the measurable decline in unprotected or overly accessible sensitive data over time. It is the most practical indicator that discovery, access control, and remediation are working together, because it tracks whether the programme is shrinking risk rather than just identifying it.
- Outcome-Based Reporting: A reporting approach that explains controls by the business result they create, not only by the work completed. For IAM, PAM, and NHI programmes, it makes invisible governance visible by tying access decisions to measurable risk and operational impact.
What's in the full article
Hadrian's full blog post covers the operational detail this post intentionally leaves for the source:
- How Hadrian frames the metrics problem in offensive security and why volume can distort priorities
- The practical implications of agentic-powered testing for teams comparing manual and automated approaches
- How the source article connects measurement quality to remediation outcomes and SOC effectiveness
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners align control design with real operational risk.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org