The Power of Key Risk Indicators in Technology Risk Management
CybersecurityOctober 17, 2022

The Power of Key Risk Indicators in Technology Risk Management

Prince Adu

Culture eats strategy for breakfast, so is the absence of Key Risk Indicators (KRIs). Learn how to demystify metrics for effective risk management.

Culture eats strategy for breakfast, so is the absence of Key Risk Indicators (KRIs).

Cybersecurity encompasses people, process and technology that needs to be safeguarded against cyberattacks while ensuring confidentiality, integrity and availability of organizational assets and data. The objective is to ensure secure access to information and information systems, prevent illegitimate access of adversaries to systems whilst meeting business objectives. Some of these risks include the theft of information, fraud through alteration of systems or data, and the subversion access of IT systems through ransomware for example. Notwithstanding, the adoption of the cloud with its numerous benefits comes with its own cybersecurity risks as most organizations are adopting the hybrid model of IT operations.

There are several frameworks such as ISO 27001, ISO 31000, NIST framework, PCI DSS etc. that management have invested and adopted. How can executive management ensure good returns on their investment?

Today, management set Key Performance Indicators (KPIs) for CISOs and Security Departments to measure their performance. KPIs simply track whether set target goals are being met or not.

Unfortunately, these KPIs are not complemented with effective Key Risk Indicators (KRIs) for effective security risk management and oversight. According to ERM Insights by Carol, only 30% of organizations that develop KRIs are satisfied with the quality of insights they receive. The remaining 70% of organizations are either not very satisfied, not at all satisfied, or they are not using KRIs at all.

Cybersecurity Key Risk Indicators are critical to the execution of business strategies today. However, they tend to be ignored or managed in silos. Sometimes, KPIs are used interchangeably with KRIs which results in misunderstanding during cyber and information security risk management review meetings, wrong decisions based on performance instead of risk, and time wasting discussing performance-based issues instead of risk.

Key performance indicators are set by management to measure the performance of business. They measure how well projects, individuals and departments are performing in line with strategic goals.

Key risk indicators help identify and understand risks, likelihood and impact of not achieving a strategic goal in the future. KRIs identify and provide early warning signs that enable organizations to report risks, prevent crises and mitigate them in time. KRIs build meaningful metrics that embrace efficiency and change in organizational culture and maturity levels. These metrics are translated into scorecards as an indicator of security risk posture.

For example, management establishes a KPI for measuring the performance of a finance mobile app, and a complementary KRI is to track vulnerabilities to cyberattacks such as fraud. Similarly, management establishes a Human Resources KPI for staff productivity and satisfaction and compliments it with KRIs to monitor the likelihood of staff turnover or losing key staff to competitors.

Setting effective cybersecurity key risk indicators offers significant benefits. Management can gain deep insights and take more risk in a well-controlled manner than their competitors. Executive management can make fact-based decisions on how much risk to take on strategy and how much to spend on security controls. They can achieve an increased ROI on their investment in cyber and information security controls. The cybersecurity department can quantify their contribution to the business and gain deserved recognition. Compliance can be put on autopilot to improve security culture. When implemented effectively, KRIs can become a competitive advantage to the business.

Setting KPIs for Cybersecurity Departments or CISOs without corresponding KRIs can result in making costly poor decisions, reputational damage, data breaches, and revenue loss amongst others. KRI tracks the performance of a goal in real time and is proactive in managing risk. Don't be caught in the trap of a false sense of security. Adopt effective KRIs.

Written by

Prince Adu

All Insights