Security teams have learned to measure activity. The harder task is turning those measurements into signals directors can use to govern risk.