The share of attacks that make it all the way to their objective. Lowering this number matters more than reducing average handling time because it shows whether the security programme is preventing harm rather than merely documenting it.
Expanded Definition
Attack completion rate is a security outcome metric that tracks how often an adversary reaches the intended objective, such as data exfiltration, privilege escalation, fraud, or service disruption. It is different from volume-based measures like alert counts and from efficiency metrics like mean time to respond, because it asks whether defensive controls actually stopped harm. For NHI Management Group, the value of this metric is that it ties detection and response activity to real adversary success, which is especially important in environments where identities, secrets, and tool-bearing agents can be abused quickly.
In practice, the metric is shaped by what counts as an “attack” and what counts as “completion,” and those definitions vary across vendors and internal reporting models. Some teams score completion at first persistence, while others require confirmed business impact. That means the metric should be defined alongside kill-chain assumptions, asset scope, and evidence standards. It also benefits from mapping to attack paths documented in the MITRE ATT&CK Enterprise Matrix, because that gives analysts a consistent way to describe how intrusion steps lead to an objective. The most common misapplication is treating blocked alerts as failed attacks, which occurs when teams count detection activity as prevention without verifying whether the adversary still achieved the goal.
Examples and Use Cases
Implementing attack completion rate rigorously often introduces measurement ambiguity, requiring organisations to balance operational simplicity against evidence quality and consistent scoring rules.
- A phishing campaign that steals credentials but is stopped before mailbox access may be counted as incomplete if the objective was data access, not credential theft.
- An account takeover in which the attacker creates persistence in a cloud identity system, then fails to reach sensitive data, helps show where control gaps exist in identity and identity and access management.
- A ransomware intrusion that encrypts only a single host before containment may be considered unsuccessful if the objective was enterprise-wide disruption.
- An AI-enabled intrusion campaign tracked through the MITRE ATLAS adversarial AI threat matrix may fail at model manipulation even after initial access succeeds.
- A multi-stage intrusion documented in CISA cyber threat advisories can be benchmarked against completion rate to show whether defensive tuning is reducing real adversary success.
Why It Matters for Security Teams
Attack completion rate matters because it exposes whether a security programme is preventing impact or merely generating activity. A team can reduce noise, shorten triage queues, and still leave the organisation exposed if adversaries continue to complete their objectives. That is why this metric is more decision-useful than many surface-level operational KPIs. It also encourages better control design: segmentation, privileged access restriction, secret rotation, hardening of SaaS and cloud identities, and more resilient detection around critical business paths. For identity-heavy environments, the metric is especially revealing because stolen credentials, service tokens, and agent permissions often create a direct line from access to impact.
Security leaders often pair outcome metrics like this with control frameworks such as NIST SP 800-53 Rev 5 Security and Privacy Controls to decide which safeguards should reduce completion, not just detect activity. It is also useful when analysing AI-assisted intrusions, as shown in the Anthropic report on the first AI-orchestrated cyber espionage campaign, where success depended on chaining multiple steps through identity and tool access. Organisations typically encounter the true cost of attack completion only after a breach, at which point the metric becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RS.MA-1 | Outcome-focused response metrics align to monitoring whether incidents are contained before mission completion. |
| NIST SP 800-53 Rev 5 | CA-7 | Continuous monitoring supports measuring whether controls stop adversaries before they reach objectives. |
| OWASP Non-Human Identity Top 10 | NHI abuse often enables attack completion through stolen service identities and exposed secrets. | |
| OWASP Agentic AI Top 10 | Agentic systems can expand attack paths, making completion a key measure of tool and permission misuse. | |
| NIST AI RMF | AI RMF prioritises measuring and managing harmful outcomes, which maps directly to completion rate. |
Track whether attacks were actually contained and use completion rate to validate response effectiveness.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org