What To Measure When We Can't Measure "Secure"

1 min read | Last Updated: 16 Jun, 2026
Security leaders are under constant pressure to prove their organizations are secure. But most of the metrics they rely on, vulnerability counts, patch rates, audit scores, measure activity, not outcomes.
In his expert insight published on ET CIO, Kaarthick Subramanian, Chief Customer Officer at Atlas Systems, breaks down why this distinction matters, and what it looks like when security teams start anchoring their strategies to business outcomes instead.
He covers everything from how to calculate liability impact, to why third-party concentration risk often flies under the radar, to how CISOs can change the conversation with leadership.