- Which threat metrics should a board see?
- Exposure, coverage, and time-to-brief: is the organization more exposed than last quarter, do detections cover the campaigns that target it, and how long does intel take to produce a decision? Attack Nemesis recommends three board metrics and none of them count indicators.
- Why stop reporting indicator counts to the board?
- Indicator counts measure activity, not risk, and red-team war stories do not answer whether the organization is safer. Security leaders need numbers a board can act on. Attack Nemesis argues boards need exposure and coverage, not volume.
- Can I drop this into a board deck?
- Yes. The paper includes a one-page appendix you can use without translation. It is an 18-page PDF brief by Mira Shah. Attack Nemesis wrote the appendix to go straight into a board deck.
- Does Attack Nemesis compute these metrics?
- Yes. The paper shows how Attack Nemesis computes exposure, coverage, and time-to-brief from the platform. Attack Nemesis produces board metrics from the same work analysts already do.