Test driven development of security improvements

Without a mandate for measuring and reporting actual improvements in security (decision making), attempts at improving security makes absolutely no sense.