How do security professionals measure their success and how do they communicate this to others in their organizations?
The way I see it, if no security incidents occur then either the security team is doing a good job, there was no threat to begin with, or it's only a matter of time before an incident does occur. If a security incident occurs, then clearly the security team has failed.
It seems like workers in security are in a lose-lose situation: having to justify their existence when times are good or explaining why they performed their jobs to a reasonable standard when things go wrong. Is this really how it is?