Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security flywheels and momentum metrics: what should teams measure?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security programs that rely on maturity tiers, compliance scores, and lagging operational metrics can miss whether risk reduction is compounding or stalling, according to Abstract Security’s interview with Jess Jimenez of Dropbox. The stronger model is to measure momentum, friction, and reinforcement loops so security investment can be tied to business impact rather than static posture.

NHIMG editorial — based on content published by Abstract Security: C2 Corner with Jess Jimenez on measuring security momentum

Questions worth separating out

Q: How should security teams measure whether security controls are creating momentum?

A: Measure momentum by pairing a leading indicator with a lagging outcome for each major control loop.

Q: Why do maturity scores often miss the real state of a security programme?

A: Maturity scores show whether a capability exists, but they rarely show whether it is reinforcing other controls or creating operational friction.

Q: What do security teams get wrong about appsec metrics?

A: They often measure the number of vulnerabilities found instead of the speed and consistency of remediation.

Practitioner guidance

  • Map one control loop end to end Pick a high-value loop such as detection to response or access review to remediation.
  • Replace isolated metrics with paired measures For every major security control, track one leading signal and one outcome signal.
  • Identify and remove the biggest drag point first Look for manual steps, false-positive-heavy workflows, and evidence-gathering overhead that slow the loop.

What's in the full article

Abstract Security's full article covers the operational detail this post intentionally leaves for the source:

  • The specific flywheel examples Jess Jimenez uses to connect detection, response, and confidence in practice.
  • The way leading indicators and lagging indicators are paired to show whether security investment is compounding.
  • The discussion of accelerants and drag points that helps teams decide where automation or process redesign will matter most.
  • The leadership guidance on presenting momentum-based measures to boards and executives.

👉 Read Abstract Security's interview on security flywheels and momentum measurement →

Security flywheels and momentum metrics: what should teams measure?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Security momentum is now a governance problem, not just a measurement problem. Static maturity models can prove that controls exist, but they do not show whether those controls are compounding risk reduction across the programme. That matters in identity-heavy environments where access decisions, evidence collection, and response workflows influence each other. Practitioners should treat momentum as a governance signal, not a reporting flourish.

A question worth separating out:

Q: How do teams know if IAM lifecycle controls are working?

A: They should be able to prove that accounts are provisioned and removed on schedule, that access changes are logged, and that stale entitlements are rare. If deprovisioning is incomplete or audit evidence is fragmented, lifecycle control is failing even when the front-end access experience looks smooth.

👉 Read our full editorial: Security momentum needs flywheels, not static maturity scores



   
ReplyQuote
Share: