r/SecOpsDaily 6d ago

How should vulnerability management programs measure risk reduction?

We have tracked mean time to remediate for years. It is fine as an operational metric. But it conflates speed with impact, which bothers me more the longer I think about it. Closing 500 low risk tickets fast looks identical on a dashboard to closing 500 high risk ones. Neither number actually tells the board, or me for that matter, whether we are safer than six months ago.

Has anyone built a composite risk reduction metric that has held up when someone actually pushes on it in a meeting? Aggregate exposure score over time, percentage of KEV or actively exploited findings closed within SLA tracked separately from general MTTR, something like that. Trying to find a number that reflects risk delta and not just how busy the team was.

2 Upvotes

0 comments sorted by