Cybatar Security Hub
Security Metrics / Exposure & remediation metrics
Security-measurement guide

Exposure & Remediation Metrics: Backlog, Risk, Exceptions & Validation

How should vulnerability remediation performance be measured?

Direct answer

Measure the material unresolved exposure, not just tickets closed: affected critical services, known-exploited vulnerabilities in scope, age by priority, accountable ownership, approved exceptions, treatment progress, validation results and reopened conditions. Closure rate alone can improve while material residual exposure remains unchanged.

External reference

National Institute of Standards and Technology — NIST SP 800-55 Vol. 1 — Identifying and Selecting Measures

NIST measurement principles are applied to Cybatar exposure and remediation evidence. Priority and closure should remain connected to the risk context documented in the exposure-management layer.

Primary source →

Measures to retain

Material unresolved exposure

Count and age unresolved items by critical business service, internet exposure, exploitation evidence and treatment priority.

Known exploitation in scope

Track applicable KEV or other observed-exploitation evidence separately so a large low-risk backlog does not hide urgent items.

Ownership and ageing

Measure how long material findings remain without an accountable owner, approved treatment or review.

Exception debt

Track accepted/deferred findings, expiry dates, compensating controls and overdue re-approval.

Validation and reopen rate

Report whether remediation changed the underlying condition and whether apparently closed issues later reappear.

Operating method

Step 1

Segment by consequence

Keep business service, exposure and exploitation context attached to backlog measures.

Step 2

Separate treatment states

Distinguish new, owned, in progress, accepted, blocked, remediated and validated conditions.

Step 3

Measure evidence quality

A closure record should point to implementation and validation evidence.

Step 4

Report residual exposure

Show material items remaining after treatment and exceptions, not just throughput.

Measurement anti-patterns

Tickets closed as the primary success measureCVSS-only dashboardsIgnoring exceptions after approvalTreating vulnerability count as asset risk

Relevant Cybatar sources

Claim boundary

Remediation metrics do not prove every vulnerability or asset is known, that residual risk is acceptable, or that a closed record changed the environment. Validation scope and evidence should remain explicit.

Cybatar publishes measurement and reporting guidance as a first-party operating model. Examples are not universal benchmarks, regulatory thresholds, promises of security outcomes or evidence that a particular deployment is effective.

Related resources