Research · 3 min read

Detection count is a vanity metric. Ask your vendor for these three instead.

Every brand-protection report leads with threats detected. It is the easiest number to inflate and the least connected to any outcome. Three questions that are harder to dodge.

Open any brand-protection report and the first number is detections. It is the wrong number, and the reason is structural: detection count rewards being wrong.

A vendor who loosens their scoring reports more threats. Their number goes up, their dashboard looks busier, and the extra findings are false positives the customer now has to triage. Nothing in the metric penalises that. We produced this exact failure ourselves — a scoring flaw that reported seven high-confidence threats for one brand, three of which were an unrelated legitimate company.

Three questions instead

What is your median time to removal? From approval to the content being verified gone. If they measure from "notice sent" rather than "content removed", they are measuring their own outbox.

What is your verified removal rate, over resolved cases? Insist on the denominator. Rate over *all* cases flatters early and punishes later; rate over resolved cases is the honest one.

What proportion of findings do customers reject? This is the false-positive rate under another name, and it is the question vendors like least. A high rejection rate means their detections are costing you review time.

Why we publish the failures

Our own dashboard reports cases that were exhausted after every escalation, alongside the ones that worked. It makes the numbers look worse. It is also the only version that lets a customer tell whether the service is working, which is the entire point of giving them a number at all.