Proving it works: five numbers and a quarterly review

You deployed the vital few (part 2) on a 90-day plan (part 3). Now the uncomfortable truth underneath all of it: coverage decays. New hires arrive outside the MFA policy. A vendor re-adds its admin account. A backup job silently stops including the new server. The restore test gets skipped one busy quarter, then two. Controls don't fail loudly at small organizations — they erode, invisibly, because nothing looks different.

The answer isn't more dashboards. It's the Pareto principle applied one last time — this time to measurement. Five numbers, collectible in under an hour, each one attached to a vital-few control and a decision. If a metric can't change a decision, it's decoration.

Activity is not coverage

Most security metrics that get reported are activity metrics: attacks blocked this month, alerts triaged, training videos completed, patches applied. They share two fatal flaws. First, they're numerators without denominators — "12,000 attacks blocked" says nothing about the one that wasn't, and the number goes up when things get worse. Second, no decision follows from them: nobody does anything different because the blocked-attack counter read higher this month.

Coverage metrics invert this. They ask: of everything that should be protected, how much actually is? The denominator comes from your two inventories — which is why the inventories came first in this series, and why they have to stay current for any of this to mean anything. An activity metric tells you the control did something. A coverage metric tells you whether the control still covers what it's supposed to. Only the second one detects erosion.

The five numbers

#MetricWhere it comes fromGreenInvestigate
1MFA coverage — % of active human accounts under enforcement, plus exception countIdentity admin portal vs. HR roster100%, exceptions ≤ 5, none expiredAny gap between roster and enforcement; any exception past its expiry
2Legacy auth sign-ins — successful, last 30 daysSign-in logs, one saved filter0Any nonzero — something re-enabled it or something new bypasses it
3Privileged accounts — humans with top-tier admin, and daily-use accounts holding standing adminRole membership export2–4 named humans; zero daily-use admin accountsAny name you can't justify in one sentence; any vendor back in the list
4Days since last successful restore testThe restore test log< 90> 90, or the last test failed and wasn't re-run
5Oldest unpatched critical on the edge — and anything internet-facing out of supportEdge inventory sheet< 7 days; nothing end-of-lifeAnything older than the SLA; any device that can no longer be patched at all

Three properties make these five worth collecting and almost everything else skippable. Each has a denominator — they're measured against the inventory, so drift shows up as a number moving, not as silence. Each is cheap — the five together are under an hour with saved queries, which means they'll actually get collected, which is the metric property that matters most. Each triggers a known conversation — a red number maps to a specific playbook section and a specific owner, so there's never a "huh, interesting" result. Interesting is for dashboards; these are for decisions.

Notice what's not here: phishing click rates, alert volumes, vulnerability scan totals across all internal machines. Some of those earn a place later. None of them belong in the first year, because none of them measure whether the doors that the breach data cares about are still locked.

The numbers decay in predictable ways

Metric 1 erodes through onboarding — the new-hire flow that quietly skips the enforcement group — and through "temporary" exceptions that outlive their reason. Metric 2 goes nonzero when someone re-enables a protocol to fix a printer at 6 p.m. Metric 3 erodes through vendors and through privilege granted for a project that ended. Metric 4 is pure calendar discipline, which is why the quarterly test goes on a recurring calendar slot like any other compliance control. Metric 5 erodes when the advisory emails start getting archived unread. None of this is hypothetical; it's the standard decay path of every small-org security program, and the entire point of measuring is to catch it while it's a number and not an incident.

The one-hour quarterly review

Once a quarter, one hour, three steps:

  1. Collect the five numbers (20 minutes with saved queries) and write them next to last quarter's. The trend matters more than the snapshot — a metric moving the wrong way two quarters running is a process problem, not a glitch.
  2. Re-ask the Pareto question (20 minutes): has the 20% moved? New SaaS, new vendor with access, new contract with security clauses, new office, new product surface — anything that changes where most of your risk concentrates. This is also when the exception list gets re-read and expired entries get closed, and when one or two risks in the register get re-scored if reality changed.
  3. Report one slide (20 minutes to make): the five numbers with green/red status, one trend worth a sentence, and at most one decision you need. Drop it into the leadership briefing. Five numbers a non-technical executive can read in thirty seconds beat any dashboard — and a red number with a named fix builds more trust than a wall of green ever will.

Resist the urge to grow this. The review's power is that it's one hour and it always happens. The version with fifteen metrics and a slide deck is the version that gets skipped in a busy quarter — and skipped reviews are how erosion wins. If a sixth number wants in, a current number has to leave.

When to graduate beyond the vital few

The vital few are a starting posture, not a finish line — but "when do we do more?" has a measurable answer instead of a vibes-based one: when all five numbers have been green for two consecutive quarters, the evidence folder is real, and the register is operating with named owners. That's the signal that the first 20% is genuinely locked, not just deployed.

Then graduation is a Pareto exercise, not a shopping trip: run the gap assessment against CIS IG1 to find the next vital few for your situation — for one organization it's vendor access, for another it's the CUI enclave or the DPDP clock, which is what the situation pages are for. Pick the framework conversation by who's asking (the framework maze), add the next two or three controls, give each a number, and fold them into the same one-hour review. The program grows; the discipline doesn't change.

The 80/20 security program

  1. 1. Start here: the argument and the vital few
  2. 2. The playbooks: deploying the five controls
  3. 3. The first 90 days: an execution plan for teams
  4. 4. Proving it works: five numbers and a quarterly review You are here