Most security teams measure activity.
How many firewall changes were processed. How many tickets were closed. How many compliance checks passed.But those are operational statistics, not security outcomes.
The harder question is this: Is the organization actually becoming more secure over time?
That question has become increasingly difficult to...