Hotline: Cybersecurity and Privacy | September 2026

This Month: Performance Measures and Hacking Back

min read


"Hotline: Cybersecurity and Privacy" tackles the philosophical, moral, strategic, and organizational quandaries related to higher education cybersecurity, privacy, and data. This month, Mike answers your questions about measuring meaningful reductions in cybersecurity risk and the risks and ethical implications of government-authorized "hack back" programs.

Stacked tiles with various icons: key, lock, shield, etc. The top on is a phone in use.
Credit: HowLettery / Shutterstock.com © 2026

Busy, Not Better: The KPI Performance Art Project

Dear Hotline: My board wants a dashboard with security KPIs, so I give them phishing click rates, patch percentages, and mean time to detect. But none of these numbers tell us whether we're actually safer than we were last year; they just tell us whether we're busy. Are security KPIs really measuring risk reduction, or are they just giving nervous executives something green to look at?

And, once I have the KPIs figured out, I have another problem: as soon as I put a number on something, my team optimizes for the number. Phishing click rates go down because people stop reporting suspicious emails, not because they got smarter. Patch compliance hits 98 percent because we stopped patching the hard, high-risk systems that would tank the score.

Is every security KPI eventually just Goodhart's Law waiting to happen?

KPI (Keeps Piling It On)

Dear KPI: Bless you for mentioning Goodhart's Law, though now all the cool kids will start citing it. The rizz is gone. Looking over past Hotline columns, I see I've tackled questions about metrics a few times, so I'll avoid retreading those waters.Footnote1

I remember sitting in a room with the campus executives who handled risk, including the CFO and leaders from the auditing and legal teams, and listening to a colleague wax poetic about unpatched Java installations. They're like moles: everyone has them, but sometimes they go bad. His concern was well founded—those unpatched installations were everywhere and introduced a ton of risk. But you could feel the pain radiating off the executives as they sat stoically through this recitation of doom about software they'd probably never heard of. The issue isn't that the risk isn't real; it's that the language makes it unintelligible.

I'm recalling this story because it illustrates a serious operational challenge for technology and security leaders: we can count many things that introduce risk to our environments, but explaining those risks in ways that leadership cares about and understands is difficult. You've hit the nail on the head: most of these aren't really about resilience; they're activity metrics. Sadly, I've seen many institutions where CISOs and executives treat such metrics as indicators of resilience.

They're attractive precisely because they are easy, legible, and comforting. They're always simple percentages or at best a trend line showing change over time. They're quite valuable to the security team as a measure of operational effectiveness, but that's about all.

The fact that your board wants a "dashboard" is also a tell. I think of a dashboard as something with real-time metrics—like the dashboard of your car showing your speed and RPM. But the risk posture of your institution doesn't change in real time; it moves at an evolutionary pace. Moving it requires strategic investment and initiatives that, by definition, have longer time horizons.

Remember, your board governs primarily through two levers of control: resources and policy. By asking for a metric like "percentage of networked hosts running our official anti-malware software," they're really asking about compliance with your policy requiring its use. In other words, they are asking, "Are people listening to us, and if not, why?"

I believe we're endlessly stuck relying on these sorts of metrics as KPIs because we haven't done the hard work of educating our leadership on what constitutes valuable, risk-based alternatives. Frankly, I think IT leaders too often underestimate campus leaders' capacity to absorb cyber nuance. I've had many CIOs tell me, "Reduce your slide to a table of metrics, or it'll be ignored." Your campus executives are awash in risk discussions—everything from natural disasters to student drinking to the vagaries of donor politics. With the same intentionality, cyber risk should be just as manageable.

Most common KPIs like the ones you mentioned, assume the institution is trying to be accurate and that its answers map to reality. In practice, institutions drift into self-deception, and risk is hidden in misalignment, latency, and incentives. I think it's worth unpacking the term misalignment, since it leads directly to effective KPIs. By "misalignment," I mean the difference between what we claim (policy), what we observe (telemetry), and what we actually make real (allocation and enforcement).

Steer the conversation with your executives toward strategic issues. If you want metrics that matter, they should answer three questions. First, "Where do our words, our data, and our spending diverge in what they reveal about our security posture?" This is the question that aligns statements with truth and raises questions about funding. Next, recall that executives intuitively understand time and consequence. So perhaps, "From initial compromise, how long do we have before an incident becomes irreversible or publicly consequential?" The answer to this question tells executives if you'd survive when controls fail anyway and opens the door to a discussion of resilience. Finally, you want to expose whether your technical and security programs work without heroics. Ask, "In our current environment, does the default path for a new project produce a secure system or an insecure one that requires intervention?" This distinguishes architectural security from performative security. If insecurity is the default, nothing else scales.

The goal isn't to replace your board's dashboard. It's to prevent it from becoming a scoreboard for the wrong game. Otherwise, you're not measuring security—you're measuring how convincingly you can pretend to have it.

Legal, Not Legitimate: The Problem with Poking the Bear

Dear Hotline: I'm curious about the recent National Security Presidential Memorandum essentially establishing a "Hack Back" program "to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government." Hacking back has long been a temptation to cyber defenders, and it has happened, but rarely, due to legality and risk. Legality seems now not to be a barrier once you're enrolled in this program. The risk remains. Is this something higher education should even consider? How about in a research context?

Kurious

Dear Kurious: The current moment is genuinely discontinuous—not because "hacking back" suddenly became legal but because the boundary between state action and private capability is being deliberately blurred. Thanks for asking such a timely question; this is a tricky one because I suspect there will be a variety of opinions about this program. I'll avoid commenting too much about the program itself, or the wisdom of it, and focus on your core question: "Is this something higher education should even consider?"

If taking part in the program appeals to you, it's worth spending some time reading through the details. The program isn't just "get permission to become a cyber vigilante" and then go off and hack away. In essence, it's designed to deputize contractors to act as agents of the U.S. government. But even when deputized, every action requires written approval—thus you can't "hack back" when attacked. There are limits on what any approved action can achieve (physical harm falls under international law). You'll need to maintain a bond or escrow of at least $1 million to participate. And if you should stumble across a U.S. citizen in your efforts, you must immediately cease operations and notify the National Coordination Center.Footnote2 How all this plays out in practice is to be determined, and it'll be interesting to see what develops.

But the risk question is, I think, quite straightforward: poking the bear is never a good idea. We already struggle with attacks by state actors. Given their significantly greater capabilities and resources, I can't imagine we'd want to further paint a target on our backs. Imagine explaining this scenario to your governing board: "Well, North Korea got angry at something my team did, so they destroyed our network and deleted our medical record system. My bad."

The ethical question is more interesting. Legally, the situation is still constrained: independent hack-back by private firms remains generally prohibited under laws like the Computer Fraud and Abuse Act.Footnote3 However, what's emerging is a narrow exception: delegated authority under government supervision. But, of course, legality does not equal legitimacy.

Essentially, we need to ask, "Are we comfortable moving from a model of state-controlled cyber force to a hybrid model in which capability, decision-making, and accountability are distributed across public and private actors?" It strikes me that once you cross that line, three things happen. First, attribution becomes less important than authorization. "Did we approve this actor?" replaces "Was this the right target?" Second, cyber operations become more economically scalable. This is probably the real goal of the program because you can buy more offensive capability faster than you can build state capacity. Finally, I worry that the distinction between defense and offense collapses. The disruption you engage in becomes a "defensive" act.

We have a declarative signal ("We are defending against criminals"), a behavioral signal (private entities conducting offensive operations), and an allocative signal (funding and contracting mechanisms for disruption capabilities), but ethical risk emerges when those signals drift apart. When "defense" is declared but offense is funded and executed, the system becomes ambiguous—and ambiguity is where escalation lives. We cannot claim to be stewards of open academic inquiry while operating delegated cyber weapons. If we want to protect our institutions, we should focus on building resilient defaults, not renting offensive capability.

Have a cybersecurity or privacy dilemma you'd like Mike to unpack? Submit your question through our anonymous form.

Notes

  1. For related discussions, see Michael Corn, "Hotline: Cybersecurity and Privacy | June 2025," EDUCAUSE Review, June 19, 2025; "Hotline: Cybersecurity and Privacy | April 2026," EDUCAUSE Review, April 22, 2026; "Hotline: Cybersecurity and Privacy | June 2026," EDUCAUSE Review, June 17, 2026; and "Hotline: Cybersecurity and Privacy | August 2026," EDUCAUSE Review, August 27, 2026. Jump back to footnote 1 in the text.
  2. "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," White House, August 12, 2026. Jump back to footnote 2 in the text.
  3. Peter G. Berris, Cybercrime and the Law: Computer Fraud and Abuse Act (CFAA) and the 116th Congress, (Congressional Research Service, September 2020), 3. Jump back to footnote 3 in the text.

Michael Corn is an Executive Strategic Consultant at Vantage Technology Consulting Group.

© 2026 Michael Corn. The content of this work is licensed under a Creative Commons BY-NC-SA 4.0 International License.