Your question is Track Endpoint Hardening Effectiveness. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You are responsible for endpoint security on a growing B2B software platform. Controls like disk encryption, EDR, OS patching, local admin restrictions, and MDM policies are already in place, but the harder problem is knowing whether they stay effective as the fleet, employee workflows, and exceptions change over time.
What metrics do you track to keep endpoint hardening controls effective over time?