About this module
Managers do not need every metric on the security dashboard. They need the few numbers that drive action. This module covers phishing click rates, patch timing, MFA coverage, incident detection speed, training completion, and repeated exceptions. Learners see that a metric is useful only if it changes what the team does next. The lesson gives managers a simple test: if the number moves, what decision will we make differently? If there is no answer, it is noise.
Key takeaways
As a manager, you don't need every security metric that exists — you need the handful that actually tell you whether your program is working. In this video, we'll cover the numbers worth watching, and exactly how often to check each one. A single statistic on its own means very little.
The real value comes from watching it change over time, and asking what that change is telling you to do differently right now. Consider four figures. How many employees click a simulated phishing email. How long it takes to patch a known vulnerability. What share of your team has multi-factor authentication turned on. And how long it takes to detect an incident once it starts.
Here's a simple test for any metric you're tracking. If the number moved this week, would you actually do something differently. If the answer is no, that metric isn't managing your risk, it's just decoration on a dashboard. Leading indicators predict future risk. Multi-factor authentication adoption, training completion, and patch cadence tell you how exposed you are before anything goes wrong.
Lagging indicators measure what already happened. Incidents, phishing click rates, and the cost of a breach tell the story after the fact. Track both, and you'll see risk coming instead of just cleaning up after it arrives. Set a rhythm for reviewing these numbers. Weekly, check open alerts and patch status. Monthly, review training completion and phishing results.
Quarterly, look at access reviews and vendor risk. And once a year, step back for a full program review. A big scary number, like the total count of alerts your systems fired this month, can feel impressive to report, but it says nothing about whether your team caught the alerts that actually mattered. Don't let a loud number distract from a meaningful one.
Pick the few metrics that change a decision, not the many that just fill a slide. That's the whole discipline of good reporting. Before you put a metric in front of leadership, run it through four quick questions. Does this number change what we do next? Is it trending in the right direction? Would my team understand it in one sentence?
And does it compare to a meaningful baseline? Here's the recap. Fewer metrics, chosen better. A mix of leading and lagging indicators. And a review cadence you actually keep, every single time. In the next video, we'll look at how to build a security-conscious team culture, because even the best metrics only work when your people already care about getting this right.



