Goodhart's law

Once a measure becomes a target, people optimise the measure and it stops describing the thing you cared about.

Count closed vulnerabilities and tickets get closed. Measure patch compliance and systems get excluded from scope. Nobody is cheating; they are responding rationally to what is being counted. It is why every security metric needs somebody asking what behaviour it will produce before it is put on a dashboard.

Checked against the primary source.

More on Metrics, decisions & economics