The attacker already made a decision.
Your organization is still scheduling the meeting.
For years, security programs have measured the presence and performance of controls. We count vulnerabilities, patching percentages, phishing failures, endpoint coverage, open findings, audit exceptions, and incident response times.
These metrics can be useful.
They can also create the illusion that security outcomes are primarily determined by control quality.
In many consequential events, the organization does not fail because it lacks information or technology.
It fails because it cannot make a confident decision quickly enough.
