Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics episode artwork

EPISODE · Jul 22, 2025 · 40 MIN

Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor, explains why vulnerability totals and unexamined CVSS scores often measure activity instead of security outcomes. He introduces the Goal Question Metric framework as a way to begin with an organizational goal, ask what must be understood, and choose measurements that answer those questions. Aram and the hosts distinguish precision, reliability, and accuracy, examine how metrics shape behavior, and identify overlooked indicators that show whether a program is actually moving. They also discuss redesigning executive dashboards and testing a long-standing metric from Chris. The takeaway: a useful metric must support a decision, reflect context, and make its limitations visible.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Aram Hovsepyan:→ Aram Hovsepyan on LinkedIn→ CodificMentioned in this episode:→ Goal Question Metric framework→ LINDDUN→ Codific→ OWASP SAMM→ Kim Wuyts→ Security Compass→ ToreonFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Why your security dashboard may be lying01:25 Meet Aram Hovsepyan02:43 From privacy research to AppSec06:30 The inspiration behind the talk09:44 How common security metrics fail11:35 If every metric is green, are you secure?13:23 Metrics drive human behavior16:48 Introducing Goal Question Metric18:38 Precision, reliability, and accuracy22:05 Good numbers can answer the wrong question26:43 Why total vulnerability counts mislead28:30 The metrics teams overlook31:52 Measuring movement, not perfection33:13 Redesigning a security dashboard35:04 Testing Chris's long-standing metric38:22 What a useful metric must reveal40:09 Closing thoughts

Episode metadata supplied by the publisher feed · Published Jul 22, 2025

Embed this episode

A dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor, explains why vulnerability totals and unexamined CVSS scores often measure activity instead of security outcomes. He introduces the Goal Question Metric framework as a way to begin with an organizational goal, ask what must be understood, and choose measurements that answer those questions. Aram and the hosts distinguish precision, reliabi...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

0:00 40:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 40 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 22, 2025.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!