Explaining the WHY of good Key Risk Indicators: Do you know what yours are?

Explaining the WHY of good Key Risk Indicators: Do you know what yours are?

Not all risks are threats. Some are opportunities! In Cyber Security, the mission is Risk Mitigation. By knowing and understanding what your Key Risk Indicators (KRIs) are, you can properly prioritize your resources and time allocations. If you have somehow ended up with 1000 KRIs, all you really have is a whole lot of metrics to sort through! At that point, you’re not measuring anything (although you think you are). 

KRIs are extremely valuable. They get you to think about the potential of things that could happen under certain circumstances or as a result of an unfortunate event. You otherwise might not have had the chance to think about those things before. KRIs show you what you need to pay close attention to and what you can confidently send to the "back burner". Good KRIs allow you to make the most of your newly-found opportunities and get ahead of risks! What gets better than that? Well, KRIs help you get a good head start on a data-driven budget allocation plan to address those pesky ever-changing security priorities!

Some organizations struggle to understand that the security controls they have in-place may not provide the adequate level protection needed against advanced cyber-attacks (or even the less advanced cyber-attacks). The latest high-profile enterprise breaches are a clear example that Cyber-Risk Management needs a reasonable amount of attention and will soon be at the center stage. By far, KRIs are the perfect way to communicate with Senior Executives, Business Units and a diverse workforce full of tekkies and non-tekkies about the importance of paying attention to Key risks. At the same time you’re increasing your organization’s Cyber Security Awareness level! Now, off you go to develop your KRIs, report on them and modify them accordingly. Continuous Improvement is just around the corner!

Robert Whittemore

4Site Strategy Finance & Leadership

7 年

Not all #risks are #threats. Some are #opportunities! In #CyberSecurity, the mission is Risk #Mitigation. By knowing and understanding what your Key Risk Indicators ( #KRI 's ) are, you can properly #prioritize #resources & time #allocations #CyberIntel #CyberAgility #CyberAwareness

要查看或添加评论,请登录

Diana Candela, MD.PhD.JD的更多文章

  • Living to Work: The 99.9% Up-Time Doctrine

    Living to Work: The 99.9% Up-Time Doctrine

    The entire World is being rebooted by a Virus. A submicroscopic infectious agent, extremely complex, nonliving…

    4 条评论
  • TOP 5 TIPS: For Women Looking to Enter the Cybersecurity Field

    TOP 5 TIPS: For Women Looking to Enter the Cybersecurity Field

    #1 Find your path! Spend some time doing a bit of research into all the different areas and focus on the one that fits…

    18 条评论
  • Artificial Intelligence (AI) in 5 Bullets

    Artificial Intelligence (AI) in 5 Bullets

    It’s a computer simulation of intelligent human-like behavior, where the system(s) imitate humans as opposed to humans…

    19 条评论
  • Cryptocurrency (Crypto) in 5 bullets

    Cryptocurrency (Crypto) in 5 bullets

    ? It’s a digital version of money (cash, moola, chavos, dinero, dough, shillings, coin, etc) ? It’s kind of like DC vs…

    8 条评论
  • Blockchain explained in 5 bullets

    Blockchain explained in 5 bullets

    It’s the Tech that allows digital info/data to be distributed but not copied. It’s kind of like The Borg in the sense…

    4 条评论
  • DPA Triggers

    DPA Triggers

    I was having a very interesting conversation with a colleague Gates Marshall as to what could trigger the DPA. I…

    2 条评论
  • 3 Things You Need To Know About GDPR Compliance

    3 Things You Need To Know About GDPR Compliance

    Cyber-Risk is the new sexy trendy buzzword du jour going around and lucky for me, there’s not stopping it! The word on…

  • Establishing a Risk-Centered Program in the Age of GDPR

    Establishing a Risk-Centered Program in the Age of GDPR

    I'm very excited to speak at the next ISACA Atlanta Chapter meeting on Friday, February 16! As companies all over are…

社区洞察

其他会员也浏览了