Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

CTEM metrics: are your security KPIs still measuring the wrong thing?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Traditional vulnerability KPIs such as open CVEs, patch rates, and backlog size measure activity rather than exposure, and CTEM should replace them with outcome-driven measures focused on validated issues, remediation effort, and continuous testing coverage, according to CYCOGNITO. The shift matters because leadership decisions improve only when reporting reflects attacker-relevant risk, not scan volume.

NHIMG editorial — based on content published by CYCOGNITO: CTEM metrics for security reporting

Questions worth separating out

Q: How should security teams measure exposure instead of just counting vulnerabilities?

A: Security teams should measure whether issues are validated, reachable, and relevant to assets that matter, then report only the subset that can realistically change risk.

Q: Why do vulnerability counts often fail to reflect actual risk?

A: Counts fail because they treat all findings as equal even when context is not equal.

Q: What breaks when remediation metrics focus only on issues closed?

A: Teams can optimise for throughput while ignoring whether the closed issues mattered.

Practitioner guidance

  • Replace activity KPIs with exposure KPIs Retire top-line metrics that only count vulnerabilities, patch throughput, or backlog size.
  • Measure urgent remediation effort directly Track engineering and operations hours spent on emergent remediation, not just the number of issues closed.
  • Define continuous testing SLAs for critical assets Set a testing cadence for each critical asset and treat any missed cadence as a coverage break.

What's in the full article

CYCOGNITO's full article covers the operational detail this post intentionally leaves for the source:

  • The full rationale for why volume-based KPIs fail executive reporting and how CTEM changes the decision model.
  • The article's breakdown of the three proposed KPIs and the exact way each one maps to exposure reduction.
  • The practical interpretation of what counts as a validated issue versus normal hygiene work.
  • The implementation framing for continuous testing coverage across a critical asset set.

👉 Read CYCOGNITO's analysis of CTEM metrics and exposure-focused security reporting →

CTEM metrics: are your security KPIs still measuring the wrong thing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

CTEM exposes a deeper measurement problem, not just a tooling problem. Security programmes have long mistaken visible activity for reduced exposure. That error is especially costly in identity and NHI governance, where scans, reviews, and rotation tasks can all happen on schedule while the highest-risk credentials remain untouched. The discipline shifts when teams measure whether action changes the attacker’s path rather than whether work was completed.

A question worth separating out:

Q: How do you know if continuous testing is actually working?

A: You should see faster conversion from raw findings to confirmed risk, fewer disputed remediation priorities, and clearer evidence that validation is happening between assessment cycles. If the programme still relies on quarterly snapshots to tell you what is exploitable, it is not continuous in operational terms.

👉 Read our full editorial: CTEM metrics shift security reporting from activity to exposure



   
ReplyQuote
Share: