This could include the number of vulnerabilities development groups are introducing into your websites every month, the speed at which issues that do slip through QA are fixed or how many days of the year a particular system is exposed to something serious.