Key risk indicators that predict, not describe
Leading indicators for eleven common security risks, each with the source of the number, the threshold, the role that acts, and where the indicator misleads.
Risk5 Sept 202613 min read
On this page
How to read this
A key risk indicator is tied to a named risk and moves before it materialises. A key performance indicator says how well a control runs. A number with no threshold is neither.
Every entry names its risk, the source of the number, the threshold and the role that acts. None states an industry norm. Thresholds are written as method, set from the organisation's own baseline and tolerance, because a borrowed number is indefensible.
The three disciplines meet in each entry. Risk work names the exposure and picks the indicator leading it. Governance sets the threshold, the owner and the escalation. Compliance reuses the same numbers as evidence, under ISO/IEC 27001:2022 clause 9.1, Monitoring, measurement, analysis and evaluation 1. One loop, not three reporting lines.
The split between control measures and activity measures is settled in Board reporting for security and assumed here.
The catalogue
Each entry serves a row of the register, whose method is in The risk register people trust.
Credential compromise
Risk. An account is used by someone other than its holder, and the use passes for normal.
Leading indicators. Accounts still exempt from multi-factor authentication; time from a leaver's last working day to access removal; identities with no review this cycle.
Source of the number. The identity directory and the leaver record. ISO/IEC 27002:2022 control 5.16 asks that the full life cycle of identities be managed 2. Control 5.17 puts authentication information under a management process 3.
Threshold and escalation. Each exemption is a dated exception with a named owner. The removal time the access policy commits to is the threshold; a breach goes to the identity owner.
Where it misleads. It counts what the directory knows. Local, service and machine identities outside it are what it cannot see.
Unpatched exposure
Risk. A known vulnerability stays reachable long enough to be used.
Leading indicators. Age of the oldest unremediated finding on an externally reachable asset; high-risk systems past the organisation's reaction time.
Source of the number. Vulnerability records joined to the asset register. ISO/IEC 27002:2022 control 8.8 asks for a defined timeline to react to vulnerability notifications, and high-risk systems first 4. CSF 2.0 keeps the record under ID.RA-01, vulnerabilities in assets identified, validated and recorded 5.
Threshold and escalation. The timeline the organisation defined is the threshold. Anything past it the platform owner remediates to a date, or the risk owner accepts in writing.
Where it misleads. A falling count can mean fewer assets were scanned. Read it beside scan coverage, or it reports the scanner's reach as the estate's health.
Supplier failure
Risk. A supplier's security position moves, and the change reaches the service before the register.
Leading indicators. Critical suppliers whose assurance evidence is past the agreed interval; unassessed sub-supplier changes; missing service reports.
Source of the number. The supplier register and the reports the agreements require. ISO/IEC 27002:2022 control 5.22 asks that supplier security practices and service delivery be monitored, reviewed, evaluated and managed for change 6. CSF 2.0 has DE.CM-06 monitor external service provider activities and services to find potentially adverse events 7.
Threshold and escalation. The interval set for each criticality band is the threshold. Overdue evidence on a critical supplier goes to the service owner, then the risk owner.
Where it misleads. It measures the paperwork cycle. A supplier can be current on evidence and losing the people behind it.
Ransomware readiness
Risk. Recovery is assumed rather than demonstrated, and the assumption is tested during the incident.
Leading indicators. Time since the last successful restore test per critical service; services with no tested recovery inside their stated objective.
Source of the number. Restore-test and continuity exercise records. ISO/IEC 27002:2022 control 5.30 asks that ICT readiness be planned, implemented, maintained and tested against business continuity objectives 8.
Threshold and escalation. The stated recovery objective is the threshold, and a test either met it or did not. A miss goes to the service owner with a remediation date.
Where it misleads. Backup success is not restore success. An indicator built on job completion measures the backup, not the recovery.
Change failure
Risk. Security is lost during a change nobody assessed as one.
Leading indicators. Changes made outside the change process; emergency changes as a share of the period; changes followed by an incident.
Source of the number. Change records joined to incident records. ISO/IEC 27002:2022 control 8.32 puts changes to information processing facilities and systems under change management procedures 9. CSF 2.0 has ID.RA-07 manage, assess for risk impact, record and track changes and exceptions 10.
Threshold and escalation. Set the band from the organisation's own recent history, then treat movement outside it as the signal. The change authority owns the threshold.
Where it misleads. It rewards under-recording. A falling count of out-of-process changes is good news only if recording coverage held.
Privileged-access abuse
Risk. Rights granted for one purpose are used for another, and the use looks routine.
Leading indicators. Privileged sessions with no linked approval; break-glass uses; privileged actions from unmanaged endpoints.
Source of the number. Session logs read against the approval record. ISO/IEC 27002:2022 control 8.2 asks that the allocation and use of privileged access rights be restricted and managed 11.
Threshold and escalation. Every break-glass use is reviewed, whatever the count. Only the unexplained fraction carries a threshold, and the platform owner owns it.
Where it misleads. A high volume of privileged sessions can be an operating model rather than a risk. Only the unlinked portion says anything.
Detection blind spots
Risk. An event happens in a part of the estate that reports nothing.
Leading indicators. In-scope asset classes with no log source reaching the monitoring platform; time since the last verified detection test; time from alert to triage.
Source of the number. The log-source inventory against the asset register, plus detection test records. ISO/IEC 27002:2022 control 8.16 asks that networks, systems and applications be monitored for anomalous behaviour 12. For financial entities, DORA has post-incident review examine the promptness of responding to security alerts 13.
Threshold and escalation. Coverage of the in-scope asset classes is a stated target, not a trend. A class with no source is an open finding for the monitoring owner.
Where it misleads. Coverage of ingested sources is not coverage of the estate. Compute it against the asset register, not the platform's own inventory.
Awareness decay
Risk. People who were trained no longer act on it, and the evidence is an incident.
Leading indicators. Time since the last assessed activity per role group; groups whose understanding was assessed rather than only attended; events reported by first-line staff.
Source of the number. Training records and the reporting channel. ISO/IEC 27002:2022 control 6.3 asks that understanding be assessed at the end of a training activity, to test knowledge transfer and programme effectiveness 14. Control 6.8 asks for a mechanism to report suspected events in a timely manner 15.
Threshold and escalation. The interval set per role group is the threshold, and that group's manager owns it. A falling reporting rate against the group's own baseline is the movement to escalate.
Where it misleads. Completion is attendance. A rising volume of reports usually means the programme works, so read direction, not level.
Cloud misconfiguration
Risk. A resource is created outside the agreed configuration and stays there because nothing checks.
Leading indicators. Accounts or subscriptions outside the configuration baseline; age of the oldest unresolved deviation; resources created outside the pipeline.
Source of the number. The platform's own description of its configuration, read against the baseline. ISO/IEC 27002:2022 control 8.9 asks that configurations of hardware, software, services and networks be established, documented, implemented, monitored and reviewed 16.
Threshold and escalation. Deviation age carries the threshold, set from the change cadence the platform already runs. The platform owner clears it or records a dated exception.
Where it misleads. It is bounded by baseline coverage. Resource types with no baseline never show as deviations, so publish that coverage beside the count.
Key-person dependency
Risk. A control runs because one person runs it, and absence is the failure mode.
Leading indicators. Controls with a single named performer and no exercised deputy; critical procedures not executed by a second person in the period.
Source of the number. The control inventory read against role assignments and execution records. Assignment sits under ISO/IEC 27001:2022 clause 5.3, Organizational roles, responsibilities and authorities 17; capability under clause 7.2, Competence 18.
Threshold and escalation. For controls called critical, one performer is the threshold, so the count is a stated target rather than a trend. It escalates to the function's owner.
Where it misleads. A named deputy is not a tested deputy. Count only deputies who performed the control, or the number measures the document.
Regulatory-clock miss
Risk. A dated obligation arrives with the work unfinished, because the clock sat outside the register.
Leading indicators. Days to the earliest binding date with an open action; obligations with no named owner; age of the oldest unmapped regulatory change.
Source of the number. The obligation register, fed by the regulatory radar. ISO/IEC 27002:2022 control 5.31 asks that legal, statutory, regulatory and contractual requirements, and the approach to meeting them, be identified, documented and current 19. NIS2 requires policies and procedures assessing the effectiveness of cybersecurity risk-management measures 20.
Threshold and escalation. The lead time the work needs, counted back from the binding date, is the threshold. Crossing it escalates to the accountable executive.
Where it misleads. It reports obligations already in the register. An unmapped change is invisible, so mapping age sits beside the countdown.
Summary
| Risk | Leading indicator | Source | Threshold owner | Requirement served |
|---|---|---|---|---|
| Credential compromise | Authentication exemptions; removal time | Identity directory | Identity owner | ISO/IEC 27002:2022 controls 5.16, 5.17 |
| Unpatched exposure | Age of the oldest reachable finding | Vulnerability records | Platform owner | ISO/IEC 27002:2022 control 8.8; NIST CSWP 29 ID.RA-01 |
| Supplier failure | Assurance evidence past its interval | Supplier register | Service owner | ISO/IEC 27002:2022 control 5.22; NIST CSWP 29 DE.CM-06 |
| Ransomware readiness | Time since a successful restore test | Restore records | Service owner | ISO/IEC 27002:2022 control 5.30 |
| Change failure | Changes outside the process | Change and incident records | Change authority | ISO/IEC 27002:2022 control 8.32; NIST CSWP 29 ID.RA-07 |
| Privileged-access abuse | Sessions with no linked approval | Session logs | Platform owner | ISO/IEC 27002:2022 control 8.2 |
| Detection blind spots | Asset classes with no log source | Log inventory | Monitoring owner | ISO/IEC 27002:2022 control 8.16 |
| Awareness decay | Time since the last assessed activity | Training records | Group manager | ISO/IEC 27002:2022 controls 6.3, 6.8 |
| Cloud misconfiguration | Age of the oldest deviation | Configuration state | Platform owner | ISO/IEC 27002:2022 control 8.9 |
| Key-person dependency | Critical controls with one performer | Control inventory | Function owner | ISO/IEC 27001:2022 clauses 5.3, 7.2 |
| Regulatory-clock miss | Days to the earliest binding date | Obligation register | Accountable executive | ISO/IEC 27002:2022 control 5.31; Directive (EU) 2022/2555 Art. 21(2)(f) |
Designing a threshold
A threshold is a governance decision expressed as a number, and it comes from the appetite, not the indicator. ISO 31000:2018 clause 6.3.4 has the organisation specify the amount and type of risk it may or may not take, and define criteria for evaluating significance 21. Those criteria are dynamic; the method for writing them is in Risk appetite and criteria. CSF 2.0 has GV.RM-02 establish, communicate and maintain risk appetite and risk tolerance statements 22.
Baselines come before levels. ISO/IEC 27002:2022 control 8.16 asks that a baseline of normal behaviour be established, with alerting set on predefined thresholds and tuned to that baseline 23. Trend usually carries more than level: DORA asks entities to map the evolution of ICT risk over time, analysing the frequency, types and magnitude of incidents 24. Cadence is design too: ISO 31000:2018 clause 6.6 asks that monitoring and periodic review of the process be planned, with responsibilities defined 25.
The loop closes at three points. Risk work supplies the exposure and the tolerance, and clause 6.4.2 lists indicators of emerging risks among the factors in risk identification 26. Governance sets the threshold and the escalation, and reviews whether either still fits, under ISO/IEC 27001:2022 clauses 6.1.2 and 9.3 27 28. Compliance reuses the series as evidence, which is why DORA has a resilience strategy set out security objectives including key risk metrics 29.
Where indicators break down
- The indicator that measures the tool. Coverage of what a platform ingests is not coverage of the estate. Publish every such number beside its denominator, taken from the asset or supplier register.
- Gaming. An indicator whose value the reporting team controls will move toward comfort. Separate the number from its recorder, and read out-of-process counts beside recording coverage.
- The threshold nobody owns. A threshold with no named role is a preference. CSF 2.0 has GV.OV-03 evaluate and review risk management performance for adjustments needed 30.
- The lagging number dressed as leading. Incident counts describe what already happened. ISO/IEC 27002:2022 control 5.27 asks that types, volumes and costs of incidents be quantified and monitored, and recurring incidents update the risk assessment 31. That is feedback, not prediction.
- The indicator with no decision attached. If no value would change anything, the number is context. Objectives come first, under ISO/IEC 27001:2022 clause 6.2 32.
- Thresholds set where the organisation already sits. A set green every period is a warning, and a review that never moves a threshold is not one.
Glossary
| Term | Definition | Source |
|---|---|---|
| Baseline | The record of normal behaviour a threshold is set against, fixed before alerting | ISO/IEC 27002:2022 control 8.16 12 |
| Key performance indicator | How well a control or process performs against its target | GRCIDE working definition |
| Key risk indicator | A measure tied to a named risk that moves before it materialises, with a threshold and a role that acts | GRCIDE working definition, anchored to risk as the effect of uncertainty on objectives 33 |
| Lagging indicator | A measure of an outcome already occurred, used as feedback not warning | GRCIDE working definition |
| Leading indicator | A measure of a condition preceding the outcome, chosen because it moves first | GRCIDE working definition |
| Metric | A number with a definition and a source but no threshold or owner | GRCIDE working definition |
| Threshold | The agreed value at which an indicator forces a named decision | GRCIDE working definition, anchored to clause 6.3.4 21 |
| Tolerance | The amount of a risk the organisation will carry, stated so a threshold follows | GRCIDE working definition, anchored to ISO 31000:2018 clause 6.3.4 22 |
Change log
| Date | Change |
|---|---|
| 2026-09-05 | First publication. Every clause, control and Subcategory read from the primary or licensed text. |
References
- ISO. ISO/IEC 27001:2022, clauses 5.3, 6.1.2, 6.2, 7.2, 9.1, 9.3. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 1
- ISO. ISO 31000:2018 — Risk management — Guidelines, clauses 3.1, 6.3.4, 6.4.2, 6.6, licensed copy. https://www.iso.org/standard/65694.html 25
- ISO. ISO/IEC 27002:2022, controls 5.16, 5.17, 5.22, 5.27, 5.30, 5.31, 6.3, 6.8, 8.2, 8.8, 8.9, 8.16, 8.32, licensed copy. https://www.iso.org/standard/75652.html 12
- NIST. The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 2024-02-26, Subcategories GV.RM-02, GV.OV-03, ID.RA-01, ID.RA-07, DE.CM-06. https://doi.org/10.6028/NIST.CSWP.29 22
- European Parliament and Council. Regulation (EU) 2022/2554, Articles 6(8) and 13. CELEX 32022R2554. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng 29
- European Parliament and Council. Directive (EU) 2022/2555, Article 21(2)(f). CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 20
Sources
- 1ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27002:2022 control 5.16, licensed copy · verified 2026-09-05
- 3ISO/IEC 27002:2022 control 5.17, licensed copy · verified 2026-09-05
- 4ISO/IEC 27002:2022 control 8.8, licensed copy · verified 2026-09-05
- 5NIST CSWP 29 Appendix A ID.RA-01, nvlpubs.nist.gov · verified 2026-09-05
- 6ISO/IEC 27002:2022 control 5.22, licensed copy · verified 2026-09-05
- 7NIST CSWP 29 Appendix A DE.CM-06, nvlpubs.nist.gov · verified 2026-09-05
- 8ISO/IEC 27002:2022 control 5.30, licensed copy · verified 2026-09-05
- 9ISO/IEC 27002:2022 control 8.32, licensed copy · verified 2026-09-05
- 10NIST CSWP 29 Appendix A ID.RA-07, nvlpubs.nist.gov · verified 2026-09-05
- 11ISO/IEC 27002:2022 control 8.2, licensed copy · verified 2026-09-05
- 12ISO/IEC 27002:2022 control 8.16, licensed copy · verified 2026-09-05
- 13EU Publications Office CELEX 32022R2554 Art. 13(2) · verified 2026-09-05
- 14ISO/IEC 27002:2022 control 6.3, licensed copy · verified 2026-09-05
- 15ISO/IEC 27002:2022 control 6.8, licensed copy · verified 2026-09-05
- 16ISO/IEC 27002:2022 control 8.9, licensed copy · verified 2026-09-05
- 17ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 18ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
- 19ISO/IEC 27002:2022 control 5.31, licensed copy · verified 2026-09-05
- 20EU Publications Office CELEX 32022L2555 Art. 21(2)(f) · verified 2026-09-05
- 21ISO 31000:2018 clause 6.3.4, licensed copy · verified 2026-09-05
- 22NIST CSWP 29 Appendix A GV.RM-02, nvlpubs.nist.gov · verified 2026-09-05
- 23ISO/IEC 27002:2022 control 8.16 guidance, licensed copy · verified 2026-09-05
- 24EU Publications Office CELEX 32022R2554 Art. 13(4) · verified 2026-09-05
- 25ISO 31000:2018 clause 6.6, licensed copy · verified 2026-09-05
- 26ISO 31000:2018 clause 6.4.2, licensed copy · verified 2026-09-05
- 27ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
- 28ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
- 29EU Publications Office CELEX 32022R2554 Art. 6(8) · verified 2026-09-05
- 30NIST CSWP 29 Appendix A GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05
- 31ISO/IEC 27002:2022 control 5.27, licensed copy · verified 2026-09-05
- 32ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
- 33ISO 31000:2018 clause 3.1, licensed copy · verified 2026-09-05