What good looks like, measured
> Quantitative targets
EXEC & BOARD LEVEL
Across cloud environments. Detection coverage ≥95% for known assets; telemetry proves impact by demonstrating attacks that fail from preventative work.
Vulnerability dwell time under 30 days for p90.
CIS Level 1 Benchmark compliance across cloud control and data planes.
Security questionnaire response under 3 business days for p90, under 7 days for p99.
Controls-testing automation above 60% (depending on baseline).
SOC 2 Type II and ISO 27001 maintained without findings; ISO 42001 readiness complete and certification underway.
All LLM interactions logged and auditable in production; tool-call authorization controls in place for all production agent deployments.
> Qualitative indicators
THE SIGNALS THAT NUMBERS MISS
Security is not named as a blocker in any competitive win/loss review — excluding compliance frameworks we've decided not to pursue.
Engineering teams experience security as helpful rather than obstructive, as measured through internal pulse surveys.
Zero security incidents requiring customer notice from preventable causes — misconfiguration, credential hygiene, unpatched known vulnerabilities.
AI-specific security controls are in place and defensible in enterprise security reviews: our answers are sufficient on first review most of the time.
Zero regrettable attrition from the security team.