Proving It

Working Security · Chapter 11

The ultimate test isn’t passing an audit. It’s answering “are we secure enough?” at any moment, with reasonable confidence.

Your board asks: “Are we secure?”

You know the answer is complicated. You know that “secure” isn’t a binary state, that risk is contextual, that compliance isn’t the same as security, and that the programme has strengths in some areas and gaps in others. You know all of this, and you have about 10 minutes of the board’s attention.

So you show a dashboard. Green, amber, red. Mostly green. A few ambers. The board nods. “Looks good.” Next agenda item.

You’ve just wasted an opportunity. Not because the dashboard was wrong — it probably wasn’t. But because “mostly green” doesn’t answer the question the board was actually asking. They weren’t asking for a status report. They were asking: should I be worried? And your answer was a traffic light.

This chapter is about proving that your programme works — not to the auditor, though that matters, but to the people who need to trust your judgement: your board, your management team, your customers, and yourself. Each audience needs a true story told in different terms. The evidence is the same. The framing changes.

Same substance, three stories

Once you’ve been running the cadence from Chapter 7 — evidence as a byproduct, generated by the work itself — then you have the raw material. Completed reviews, risk assessments, policy approvals, incident records, task completions. The material is the same. What changes is how you tell the story with it, and that depends on who’s asking.

The auditor wants traceability. Show me that Control A.5.18 was reviewed quarterly. Show me the evidence for each review. Show me the trail from requirement to control to evidence. This is the most structured audience — they’re working from a checklist, and your job is to make the chain from requirement to proof as short and clear as possible.

The board wants confidence. They don’t care about A.5.18. They want to know: is access management under control? Is the audit going to go well? Where are we exposed? The same access review evidence that satisfies the auditor gets reframed as: “access management is current across all critical systems, with 91% evidence completeness, up from 78% six months ago.”

The customer wants trust — and this is increasingly where the pressure lives. Enterprise buyers send security questionnaires before signing contracts. They ask for evidence of your controls, your certifications, your incident history. The speed and quality of your response is a competitive differentiator. Deals stall for weeks because the security team needs four days to assemble answers that should have taken an hour. Deals close faster than the competitor’s because the response was specific, evidenced, and returned the same day. Your programme’s ability to prove itself to customers isn’t a compliance function — it’s a sales function.

Many programmes only think about evidence when one of these audiences asks for it. Then they scramble. When evidence is a byproduct of operations, the scramble disappears. What remains is the framing — knowing which story to tell, using which subset of evidence you’ve already collected.

Internal audit as a health check

Internal audit, in many organisations, is a dress rehearsal for the external audit. You audit yourself to check whether you’ll pass, find the gaps the external auditor would find, and patch them before the real thing. It’s defensive. It’s stressful. And it reinforces the idea that the audit is the point.

Internal audit should be a health check. You audit yourself to find out how the programme is actually performing — not to prepare for someone else’s assessment, but to improve your own understanding. The questions change: not whether the auditor will accept the evidence, but whether the control is actually working; not whether the documentation exists, but whether it reflects what’s happening; not whether you can pass, but where you’re weakest and what to fix next.

This reframing changes the output. A dress-rehearsal audit produces a list of gaps to paper over before the external auditor arrives. A health-check audit produces a prioritised list of genuine improvements. The first makes you look better. The second makes you be better.

Run internal audits on a rolling schedule — one area per quarter, not the entire programme at once. The area you audit in Q1 gets fixed in Q2, and the evidence of the fix is there by the time the external auditor arrives. No scramble, no papering over — just continuous improvement that happens to produce good audit results as a side effect.

The uncomfortable corollary: the health check will find things you don’t like. Controls that aren’t working. Evidence that’s missing. Processes that have drifted from what the policy describes. This is the point. A health check that finds nothing wrong is either dishonest or auditing the wrong things. The programme gets stronger every time you find and fix a real problem. It stays fragile every time you look away from one.

External audit as validation

If you’ve been running the programme continuously, with internal health checks, then the external audit becomes a fundamentally different experience.

I don’t mean it becomes easy. Audits are always work. The auditor asks questions you didn’t anticipate. They sample evidence you haven’t looked at recently. They interpret requirements differently than you expected. There’s always some friction.

But the nature of the friction changes. In a programme that scrambles before audits, the friction is existential: do we have enough? Is the evidence real? Will they find the gap we know about but couldn’t fix in time? You’re hoping to survive.

In a programme that runs continuously, the friction is conversational: the auditor asks about a control, you show the evidence trail, they ask a follow-up, you explain the rationale. There might be a minor non-conformity — a review that was a week late, a policy that could be more specific. These are real findings, but they’re manageable. You know about them already because your health checks found them first.

The psychological difference is enormous. You’re not defending a position. You’re walking someone through a programme you understand and trust. The auditor isn’t policing you — they’re a second opinion confirming what you already know. That’s a different conversation, and it produces a different outcome. Not because the auditor is easier on you, but because you already know what they’ll find.

One practical note: auditors appreciate narrative. They audit hundreds of organisations, many of which present evidence as a disconnected pile of screenshots and spreadsheets. When you can walk them through the logic — “here’s the risk, here’s the control that treats it, here’s the evidence it’s operating, here’s the requirement it satisfies, and here is what we want to improve” — you’re making their job easier. Auditors who find their job easier tend to be more collegial.

Metrics that mean something

Much security reporting is activity counting: tasks completed, vulnerabilities found, training sessions delivered, policies reviewed. These numbers go up over time, which makes them feel like progress, but they answer the wrong question.

“287 tasks completed this quarter” tells you people were busy. It doesn’t tell you whether the programme is healthy. Were those the right 287 tasks? Did they address the highest risks? Are the remaining open tasks critical or trivial?

Activity metrics are easy to produce and comforting to present, which is why they dominate so many dashboards. But they’re vanity metrics — they make you feel good without informing decisions.

Outcome metrics are harder to produce and more uncomfortable to present, but they tell you what’s actually happening. And they work best when you read them together, not in isolation.

Start with two metrics that together tell you whether the programme is healthy: risk trend and evidence completeness. Risk trend tells you whether your treated risks are growing or shrinking — if you treated 14 critical risks last quarter and you’re treating 16 now, that’s progress. If your residual exposure grew because three new risks appeared and only one was treated, that’s a problem, regardless of how many tasks were completed. Evidence completeness tells you what percentage of your controls have current, valid evidence — not “do we have evidence” but “is it current?” A control with evidence from eight months ago is technically evidenced and practically stale. Together, these two numbers answer: are we covering the right risks, and can we prove it?

Next: gap closure rate, which tells you whether the programme is improving. When you find a gap — through internal audit, risk assessment, or external finding — how quickly does it close? A programme that finds gaps quickly but closes them slowly has bottlenecks. One that closes quickly but finds slowly has a visibility problem. Gap closure is the metric that tells you whether your health checks are producing action or just producing lists.

The lagging indicator that confirms the whole system is working: time to audit-ready. How long from “we need to show evidence” to “here’s the package”? If the answer is weeks, evidence isn’t really a byproduct — it’s still being assembled retrospectively. If it’s hours, the cadence is doing what it was designed to do.

No single number captures a programme’s health. But these four, read together, tell you whether things are getting better or worse and point to where the problems are. Activity metrics tell you people are busy. Outcome metrics tell you whether the work is producing results.

The board conversation

Let me come back to where this chapter started. The board asks: “Are we secure enough?”

Here’s what that conversation looks like when you can actually answer it.

“Our programme currently treats 16 critical risks and 23 moderate risks across all our assets in scope. Three risks are consciously accepted — here’s the rationale for each. Our compliance posture is 94% across ISO 27001 and 89% across SOC 2 — the SOC 2 gap is in the logging area, which we’re addressing this quarter. Evidence completeness is at 91%, up from 78% six months ago. The surveillance audit is in November and I expect no major non-conformities based on our last internal health check. Our biggest exposure is third-party risk — two tier-1 vendors are overdue for reassessment and I’ve escalated that.”

That’s a three-minute answer. It answers the question. It’s specific enough to be credible and concise enough to hold attention. It includes what’s working, what isn’t, and what you’re doing about the gaps. And notice what it demonstrates: proportionality. Three risks consciously accepted, not treated to zero. A SOC 2 gap acknowledged and scheduled, not panic-fixed. Investment scaled to actual risk, not maximised across the board.

Compare that to: “We completed 287 security tasks this quarter. Here’s a dashboard. Mostly green.”

The difference isn’t polish or presentation skill. It’s that the first answer comes from a programme where the data is connected, the evidence is current, and the person presenting it can see the whole picture. The second comes from a programme where the data is scattered and the presenter is summarising activity because they can’t summarise outcomes.

The board conversation is the downstream test of everything this book has been building. If you can answer “are we secure enough?” with specifics — treated risks, accepted risks, compliance posture, evidence completeness, known gaps and their remediation plan — then the programme is working. If you can only answer with activity counts and traffic lights, something structural is missing. The answer to the board tells you more about your programme’s health than the audit does.

When the story doesn’t go well

Sometimes you prove it, and the answer is uncomfortable.

Your evidence completeness is at 60%. Your risk trend is flat because new risks are appearing as fast as old ones are treated. Your gap closure rate is measured in months, not weeks. Your internal health check found that three controls you thought were operational aren’t.

This is not failure. This is a programme that’s honest about where it stands, which is the point. It is better than a programme that looks good on paper.

The temptation is to hide the uncomfortable numbers. Show the board the green dashboard. Tell the auditor about the working controls, not the broken ones. Present the activity metrics that look healthy and bury the outcome metrics that don’t.

Resist this. Not because honesty is virtuous — though it is — but because it’s strategically stronger.

The honest version has a plan. “We’re at 60% evidence completeness. Here’s why: we transitioned three areas to the new cadence this quarter and haven’t finished the remaining two. By Q3, we’ll be at 80%. Here’s the specific plan.” That’s a person in command of their programme. The board can evaluate the plan, challenge it, resource it. There’s something to work with.

The dishonest version has a secret. “Mostly green.” The board nods. But the 60% is still 60%. The gaps are still gaps. And now you’re carrying the additional burden of maintaining the performance — knowing that any unexpected question could expose the reality behind the dashboard. That’s not a stronger position. It’s a more fragile one.

Auditors know this too. An auditor who finds a gap you’ve already identified, documented, and planned a remediation for will typically treat it differently than a gap you’ve been hiding. Same gap, different story — and the story matters for the outcome.

The people who need to trust your judgement — the board, the auditor, your customers — trust honesty more than perfection. Nobody expects a flawless programme. They expect one that knows itself. That’s what proving it actually means.

What to do Monday morning

  1. Prepare a 3-minute board answer and say it out loud. Not a deck, not a dashboard — a spoken debrief. Treated risks, accepted risks, compliance posture, biggest exposure, plan for the gaps. If you can’t get through it in three minutes with specifics, you don’t know your programme well enough yet. The gaps in your answer are the gaps in your visibility.

  2. Replace one activity metric with an outcome metric. If your next management report says “X tasks completed,” replace it with evidence completeness, gap closure rate, or risk trend. Activity counts make people nod. Outcome metrics make people ask questions — and the questions are the point.

  3. Run a one-hour health check on one narrow slice — today, unscheduled. Not the whole programme, not even a domain — one slice: access to your production database, or your five most critical vendors’ review dates. Pull the real data and check it against what the programme claims. Fix the first thing you find, and write down what the hour taught you about the rest. An honest hour that finds two problems is worth more than a clean external audit where the problems stayed hidden.


← People First

The Compound Effect →

From Working Security. Not washing it.