Cyber KRIs a board will actually read
A key risk indicator is a number that tells the board whether a specific cyber risk is getting closer to the limit it agreed to accept. Most board packs carry activity metrics instead: emails blocked, patches applied, training completed. Six to eight real KRIs, each with a threshold, can be read in five minutes and acted on.
KRI vs metric: what is the difference?
A metric counts activity; a key risk indicator tells the board whether a named risk is moving toward, or past, the level it agreed to accept. Every KRI has an owner, a threshold and a link to a risk in the register, and a metric has none of those.
“Phishing emails blocked this quarter: 41,000” is a metric. It goes up when attackers get busier and when the filter improves, so it tells the board nothing. “Privileged accounts without phishing-resistant sign-in: 3” is a KRI. It is tied to the account-takeover risk, it has an owner, and a director can ask why it is not zero.
Eight cyber KRIs that work for most organizations
The thresholds below are starting points. Yours come from your risk appetite statement, and a regulated firm may need them tighter.
| Indicator | Green | Amber | Red |
|---|---|---|---|
| Critical internet-facing vulnerabilities open past the agreed fix time | 0 | 1 to 2 | 3 or more, or any open 30 days |
| Privileged accounts without phishing-resistant sign-in | 0 | 1 to 5 | More than 5, or any administrator of the directory |
| Days since a successful restore test of critical systems | Under 90 | 90 to 180 | Over 180, or the last test failed |
| Critical suppliers with an overdue security review | 0 | 1 to 2 | 3 or more |
| Leavers whose access was not removed within one working day | 0 | 1 to 2 | 3 or more, or any with privileged access |
| Laptops and servers missing endpoint protection or overdue patches | Under 2% | 2 to 5% | Over 5% |
| Confirmed incidents not contained within 24 hours this quarter | 0 | 1 | 2 or more |
| High-rated findings from testing or reviews past their due date | 0 | 1 to 3 | 4 or more |
Six to eight is enough for most organizations. Past ten, the board stops reading. Below five, one bad area can hide behind four quiet ones. Pick the ones that map to your top risks and drop the rest.
Who sets cyber KRI thresholds
Management proposes the thresholds and the board approves them, because the thresholds are the risk appetite written as numbers. A threshold the security team sets on its own is an operational target, not an appetite.
Write each threshold next to the risk it measures in the risk register. When a threshold changes, say so in the pack. A red that quietly becomes amber because the line moved is the fastest way to lose a board’s trust.
What to cut from a cyber board pack
- Counts of attacks blocked, emails filtered or alerts raised.
- Screenshots of tool dashboards.
- Training completion rates shown on their own.
- Colour ratings with no number behind them.
- Full lists of open findings. Give the count against threshold and keep the list in management reporting.
If a chart would not change a decision, it belongs in the operational report, not the board one.
How to show KRI trends to the board
Quarterly, with the last four quarters shown for every indicator. Anything that turns red between meetings goes to the chair or the risk committee straight away instead of waiting for the next pack.
Show each KRI on one line: current value, the four-quarter history, the threshold, and a direction arrow. Every amber or red line gets one sentence with the cause, the owner and the date it will be back in green. A director should be able to read the whole page without asking what a number means.
For a longer treatment of security measurement, NIST publishes SP 800-55, its measurement guide for information security.
Where good KRIs come from
KRIs are only as good as the risks behind them. Without a maintained register and an agreed appetite, the indicators drift back into activity counts within a few quarters. Our risk register and KRI work builds the two together, as part of wider cyber risk and governance.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
What is the difference between a metric and a KRI?
A metric counts activity; a key risk indicator tells the board whether a named risk is moving toward, or past, the level it agreed to accept. Every KRI has an owner, a threshold and a link to a risk in the register, and a metric has none of those.
How many cyber KRIs should a board see?
Six to eight is enough for most organizations. Past ten, the board stops reading. Below five, one bad area can hide behind four quiet ones.
Who sets the KRI thresholds?
Management proposes the thresholds and the board approves them, because the thresholds are the risk appetite written as numbers. A threshold the security team sets on its own is an operational target, not an appetite.
How often should KRIs go to the board?
Quarterly, with the last four quarters shown for every indicator. Anything that turns red between meetings goes to the chair or the risk committee straight away instead of waiting for the next pack.
Building a board pack that gets read
Send us your current board pack, or tell us what the board has asked for. The reply sets out which indicators to keep, which to drop and what is missing. More of our writing is indexed at writing.