The scoreboard, honestly: the hard targets, how often each one is actually looked at,
and the quiet human signals that never make it onto a dashboard.
Control Test Accuracy
The percentage of automated security and compliance tests that run without a hitch and give us valid, usable evidence.
Target · 99.5% success rate for all scheduled automated control tests.If you've got 200 automated checks running each week, we'd expect no more than one or two to fail or produce dodgy results. If your S3 bucket permission check fails, that's a problem.
Ticket Resolution Time (Risk & Compliance)
The average time it takes you to resolve assigned security or compliance-related tickets, from initial report to full fix.
Target · Resolve 90% of P3 (medium priority) tickets within 48 hours, and 100% of P2 (high priority) tickets within 24 hours.A developer raises a ticket because their new service needs a specific IAM role. You'd be expected to get that sorted, securely, within a day. Or an auditor asks for evidence on a control, and you get it to them quickly.
Automated Evidence Collection Coverage
The proportion of our required audit evidence that's automatically collected and organised, reducing manual effort.
Target · Increase automated evidence collection by 15% across your owned systems each quarter.If we currently manually pull 10 pieces of evidence for our SOC 2 audit, you'd aim to automate at least 1-2 of those each quarter, maybe by scripting a daily report from our GRC platform.
Security Configuration Drift Detection
How quickly and accurately your systems spot when a critical security configuration (like a firewall rule or S3 bucket policy) deviates from its approved baseline.
Target · Detect 100% of critical configuration drifts within 60 minutes of occurrence.Someone accidentally makes an S3 bucket public. Your system should flag that straight away, not hours later when it's already a problem.
Proactive Problem Identification
You're not just fixing what's broken; you're spotting potential issues before they become real problems for the business.
- You'll be bringing ideas to your manager about how to improve security posture, not just waiting for tasks. You'll spot a trend in failed control tests and suggest a fix. You're the one saying, 'I think we need to look at X before it blows up.' Managers will mention your initiative in performance reviews.
Clarity of Technical Explanations
How well you can explain complex technical risk issues to non-technical folks, like auditors or product managers, so they actually understand the problem and the solution.
- Auditors will comment on how easy you are to work with. Product managers won't look completely bewildered when you talk about IAM policies. You'll get fewer follow-up questions because your initial explanation was clear. Your documentation is easy to read and makes sense to someone who isn't a tech expert.
Reliability and Ownership of Systems
You take full responsibility for the systems you own, ensuring they're running smoothly and you're the first to know if something goes wrong.
- Your systems rarely have unexpected downtime or errors. If they do, you're already on it, investigating and communicating. You're the person others go to for questions about that specific system. You don't need constant reminders about maintenance or updates.
Contribution to Team Knowledge
You're actively sharing what you learn, helping to lift the entire team's capability, especially for new joiners.
- You'll be contributing to our internal wiki, running short 'lunch and learn' sessions, or doing code reviews that genuinely teach. Junior team members will naturally gravitate to you for advice. You're not hoarding knowledge
- you're spreading it.