Cyber risk register, KRIs and board reporting

A cyber risk register is the list of cyber risks your organization carries, each with an owner, a rating and a decision. We build or rebuild that register and define the key risk indicators (KRIs) that show when a risk is moving. Both feed a one-page view your board can read in five minutes.

What you receive

DeliverableWhat it is for
Cyber risk registerEach risk written as cause, event and impact, with an owner, inherent and residual ratings, controls, treatment and a due date
KRI definitionsFor each indicator: what is measured, the thresholds, the data source and who reports it
Board one-page viewTop risks against appetite, KRI trends, and the decisions the board is being asked to make

Why most risk registers stop being used

Most registers were written once, for an insurer questionnaire or a framework exercise, and then left alone. The top risk is “cyber attack”, the owner is “IT”, and the ratings have not moved in eighteen months.

The fix is rarely more columns. It is sharper risk statements, real owners and a review date someone keeps, as set out in what a cyber risk register should contain.

How we build a register your organization owns

We start with the people who run the business, not with a threat catalogue. Ten minutes with the head of finance about a vendor with admin access to payroll beats any generic list.

Each risk is rated against your cyber risk appetite statement, drafted alongside if you have none. Anything outside appetite gets a recorded decision: reduce, transfer, avoid, or accept with a named executive and a review date.

What a good cyber KRI looks like

A key risk indicator is a measure that moves before the loss does. “Phishing emails blocked this month” is an activity count. “Internet-facing systems with a critical vulnerability open longer than 14 days” tells you whether a specific risk is growing.

Every KRI we define has a threshold tied to appetite, a data source and a person who reports it.

Board and executive cyber reporting

The board view fits on one page: the handful of risks outside or near appetite, the KRI trend for each, and the decisions needed. Every colour has a number behind it.

For a federally regulated financial institution working to OSFI Guideline B-13, or a firm answering to a provincial regulator, it gives board oversight something concrete to read. See cyber KRIs the board will read.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Do we need GRC software to run a risk register?

No. A well-structured spreadsheet serves most organizations for the first year. Move to a platform once owners review their risks on schedule and the spreadsheet has become the bottleneck. See GRC platform selection.

How many risks should a cyber risk register hold?

Usually between 15 and 40 at the level executives see. Far fewer suggests risks have been merged into vague headings; far more suggests findings and missing controls have been logged as risks.

What is the difference between a KRI and a KPI?

A KPI measures how well an activity is performing. A KRI measures whether exposure to a specific risk is rising, and carries a threshold tied to your risk appetite that tells someone to act.

Who maintains the register once the engagement ends?

A named person inside your organization, usually the security or risk lead, runs the review cycle we set up with you. Each risk stays owned by the executive accountable for the process it would damage.

Start with the register you have

Send the current register, however out of date, and tell us who reads it. The reply says what a rebuild would change. This work is part of cyber risk management and governance.

Discuss a scope