
Security Metrics for the Board: KPIs, KRIs and Ten Measures Worth Reporting
Most board security dashboards report activity, not risk. The difference between activity metrics, KPIs and KRIs, ten measures worth reporting, the ones to leave out, and how to present them so they lead to decisions.
Executive Advisory
Most security dashboards that reach a board report activity: alerts processed, patches applied, emails blocked, people trained. They show that the team is busy. They do not answer the question directors are actually asking, which is whether the organisation is getting safer and where it is still exposed. Here is how to tell the difference between activity metrics, KPIs and KRIs, ten measures worth putting in front of a board, and how to present them so they lead to decisions.
In short. Report a small number of measures, each tied to a risk the board cares about, each with a threshold the board has agreed, each shown as a trend. Prefer measures of exposure and capability, such as how long critical internet-facing flaws stay open or how much of the estate the SOC can see, over measures of effort. Baseline for a quarter before setting targets. And end every report with the decisions you need, because a metric that never changes a decision is decoration.
Why boards are asking now
Board oversight of cyber risk has moved from good practice to an expectation written into frameworks and rules.
- NIST Cybersecurity Framework 2.0, released on 26 February 2024, added a sixth function, Govern, covering how the organisation should "establish and monitor the organization's cybersecurity risk management strategy, expectations, and policy". Monitoring implies measures.
- NIST SP 800-55, the measurement guide for information security, was reissued in December 2024 as two volumes: one on identifying and selecting measures, one on running a measurement programme.
- In the United States, the SEC's 2023 rules require listed companies to describe the board's oversight of cyber risk in annual reports and to disclose material incidents on Form 8-K within four business days of determining they are material.
- In India, RBI's 2026 Cybersecurity Directions require commercial banks to maintain cyber security metrics, and NBFCs to define metrics and a scorecard to measure IT performance and maturity.
Activity metrics, KPIs and KRIs
The three kinds of measure answer different questions. Board reports go wrong when they are filled with the first kind.
| Kind | Question it answers | Example | Belongs with |
|---|---|---|---|
| Activity metric | How busy is the team? | Alerts triaged this month; phishing emails blocked | The security team |
| Key performance indicator (KPI) | Is a control or process performing as intended? | Share of critical vulnerabilities fixed within the policy deadline | Management and the board |
| Key risk indicator (KRI) | Is our exposure to a specific risk rising or falling? | Number of internet-facing systems with a known exploited vulnerability open beyond deadline | The board, against its risk appetite |
"Emails blocked" is a classic activity metric that looks like an outcome. A higher number may mean more attacks, a better filter, or a change in how the vendor counts. It cannot be compared with a threshold or tell a director what to do, so it belongs in the team's operational reporting, not the board pack.
What makes a measure board-worthy
- It is tied to a named risk. Ransomware, a data breach, a regulatory failure, an outage of a critical service. If you cannot say which risk a measure tracks, it does not belong.
- It has a threshold the board agreed. Green, amber and red mean something only if the board set the boundaries as an expression of its risk appetite.
- It is shown as a trend. A single number invites the question "is that good?". A line over four quarters answers it.
- It has an owner and a data source. Someone is accountable for it, and it can be reproduced from the same data next quarter.
- It can change a decision. If it went red, there is something the board could approve, fund or accept.
Ten measures worth reporting
No organisation needs all ten, and the right thresholds depend on your risk appetite. Pick the ones that track your most important risks, define them precisely, and baseline them before agreeing targets.
| Measure | Kind | Why the board should care |
|---|---|---|
| 1. Critical internet-facing vulnerabilities open beyond deadline | KRI | Exposed systems with known critical flaws are a leading way in; see our article on edge-device zero-days |
| 2. Time to remediate critical findings against policy | KPI | Shows whether the remediation process works, not only whether scans run |
| 3. Phishing-resistant MFA coverage for privileged and remote access | KPI | Stolen credentials remain one of the most common starting points of a breach |
| 4. Standing privileged accounts | KRI | Each permanent administrator is a target; the trend shows whether privilege is being reduced |
| 5. Share of critical assets the SOC can see | KPI | Monitoring only protects what sends it data |
| 6. Validated detection coverage of priority techniques | KPI | Whether detections were proven to work recently; see detection engineering |
| 7. Time to detect and contain confirmed incidents | KPI | The speed of response decides the size of the damage. Report with care when the number of incidents is small |
| 8. Critical systems with a tested restore within their recovery objective | KRI | Answers "could we recover from ransomware?"; see business impact analysis |
| 9. Critical suppliers assessed, and those with open high-risk findings | KRI | Supplier compromise is a growing route into organisations |
| 10. Risk acceptances past their review date | KRI | Shows whether accepted risks are being revisited or have quietly become permanent |
A useful eleventh, for organisations that test regularly, is the share of penetration test findings that recur from the previous test. It measures whether fixes are addressing causes or only symptoms, and is one of the clearest signals a board can get about the maturity of an engineering organisation.
Measures to keep out of the board pack
- Raw counts of attacks or blocked threats. They rise and fall for reasons unrelated to your risk, and cannot be given a meaningful threshold.
- Total vulnerabilities found. Better scanning finds more. Report how long the important ones stay open instead.
- Training completion on its own. It shows that people clicked through a course, not that behaviour changed.
- Composite scores nobody can decompose. A single security score is easy to present and hard to act on. If you use one, show what drives it.
Presenting it
A good cyber section of a board pack fits on one or two pages and follows the same structure every quarter, so movement is visible at a glance.
Headline
Two or three sentences: is overall exposure better or worse than last quarter, and why.
The measures
Each with its current value, its threshold, its status against that threshold and its four-quarter trend. Red items get one line of explanation.
What changed
Significant incidents, test results, regulatory changes and threats relevant to your sector, each in plain business language.
Decisions requested
The specific approvals, investments or risk acceptances you need, with options and their cost. This is the section that makes the rest worth reading.
Where the board wants risk in financial terms, quantitative methods such as FAIR can estimate the probable loss from specific scenarios. They work best for a few significant scenarios used to compare options, not as a replacement for the measures above.
Building the programme
Step 1 — Agree the risks
With the board or its risk committee, agree the handful of cyber risks that matter most to the business.
Step 2 — Choose and define the measures
For each risk, one or two measures, each with a precise definition, a data source and an owner. NIST SP 800-55 is a good guide to doing this systematically.
Step 3 — Baseline before you target
Collect a quarter of data before setting thresholds, so targets reflect reality rather than aspiration.
Step 4 — Have the board set thresholds
The thresholds are the board's statement of risk appetite, so the board should approve them.
Step 5 — Report quarterly, review annually
The same structure every quarter, and once a year a review of whether the measures still track the risks that matter.
Frequently Asked Questions
Click any question to expand the answer.
QWhat is the difference between a KPI and a KRI in cybersecurity?
A KPI measures whether a control or process is performing as intended, such as the share of critical vulnerabilities fixed within deadline. A KRI measures whether exposure to a specific risk is rising or falling, such as the number of internet-facing systems with known exploited vulnerabilities open beyond deadline.
QHow many security metrics should a board see?
Few enough to discuss: typically a handful, each tied to a named risk with an agreed threshold and a trend. A long list of measures usually means none of them is driving decisions.
QWhy not report the number of attacks blocked?
Because it rises and falls for reasons unrelated to your risk, such as attacker activity, filter changes or how a vendor counts, and cannot be given a meaningful threshold. It is useful operational data for the security team, not a board measure.
QWho should set the thresholds?
The board, on management's recommendation. Thresholds are a statement of risk appetite, which is the board's to decide. Set them after a quarter of baseline data so they reflect reality.
QWhat does NIST CSF 2.0 say about governance?
Released on 26 February 2024, CSF 2.0 added a sixth function, Govern, covering how an organisation establishes and monitors its cybersecurity risk management strategy, expectations and policy. Board-level measures are one of the main ways that monitoring happens.
QIs there a standard for security measurement?
NIST SP 800-55, reissued in December 2024 as two volumes, is the most widely used guide: Volume 1 covers identifying and selecting measures, and Volume 2 covers developing a measurement programme.
QDo Indian regulators require security metrics?
For banks and NBFCs, yes. RBI's 2026 Cybersecurity Directions require commercial banks to maintain cyber security metrics, and NBFCs to define metrics and implement a scorecard to measure IT performance and maturity.
QShould cyber risk be reported in money terms?
Where it helps a decision. Methods such as FAIR estimate probable loss for specific scenarios and are useful for comparing investment options. They complement, rather than replace, measures of exposure and capability.
QHow often should security metrics go to the board?
Quarterly is common, in the same format each time so movement is visible, with an annual review of whether the measures still track the risks that matter. Significant incidents should reach the board as they happen, not wait for the quarter.
Related reading
For who owns this reporting when there is no full-time CISO, see do you need a virtual CISO?. For why passing an audit is not the same as being secure, compliance is not security. For making the case for SOC investment to leadership, why a SOC maturity assessment matters to executives.
About Adayptus
Adayptus Consulting Private Limited is a cybersecurity consultancy based in Noida, India. Our executive advisory work translates technical findings into the risk, cost and priorities a board decides on, and measures maturity against NIST CSF 2.0.
What we can do for you:
- A measurement framework. A security KPI and KRI framework tied to your top risks, with definitions, data sources, owners and a baseline quarter before targets are set.
- The board pack. Board reporting in a consistent one-page structure that ends with the decisions you need, and security budget optimisation to show what each investment changes.
- Ownership. A virtual CISO to own the programme and the reporting, and a cyber maturity assessment to set the starting point.
Sources
- NIST, Cybersecurity Framework 2.0, 26 February 2024.
- NIST, SP 800-55 Volume 1, Measurement Guide for Information Security: Identifying and Selecting Measures, December 2024, and Volume 2, Developing an Information Security Measurement Program.
- US Securities and Exchange Commission, SEC adopts rules on cybersecurity risk management, strategy, governance and incident disclosure by public companies, 2023.
- Reserve Bank of India, Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026.
Adayptus Consulting
Executive Advisory, Adayptus
Adayptus Consulting Private Limited is a cybersecurity consultancy based in Noida, India, translating technical findings into the risk, cost and priorities a board decides on.


