Board Advisory
Cyber Risk Reporting for Boards: KRIs and KCIs That Actually Drive Decisions
How to design cyber risk reporting that Boards use: choosing key risk indicators (KRIs) and key control indicators (KCIs), setting thresholds and telling a clear story.
Most cyber risk reporting to Boards fails in one of two ways: it’s so technical that directors switch off, or so reassuring that it tells them nothing. Good cyber risk reporting sits in between — it shows directors where the organisation stands against its risk appetite, what’s changing, and what decisions they need to make.
Start with the decisions, not the data
Before choosing a single metric, ask: what decisions does the Board need to make about cyber risk? Typically:
- Is our cyber risk within appetite?
- Are we investing enough, in the right places?
- Are critical programs on track?
- Do we need to accept, treat or escalate any risk?
Every metric in the report should help answer one of these questions. If it doesn’t, it belongs in an operational dashboard, not a Board pack.
KRIs vs KCIs
Two types of indicator do most of the work:
- Key Risk Indicators (KRIs) measure exposure — how likely or impactful a risk is becoming. Example: number of critical vulnerabilities on internet-facing systems older than 14 days.
- Key Control Indicators (KCIs) measure whether controls are working. Example: percentage of privileged accounts with phishing-resistant MFA.
A strong report pairs them: the KCI shows whether the control is effective, the KRI shows whether the risk is moving.
Examples that work
| Risk | KRI | KCI |
|---|---|---|
| Ransomware | Critical vulnerabilities on exposed systems > 14 days | % of systems with tested, offline backups |
| Account compromise | Privileged account anomalies per month | % privileged access with phishing-resistant MFA |
| Supplier breach | Critical suppliers without current assurance | % critical suppliers assessed in the last 12 months |
| AI misuse | Unsanctioned AI tools detected | % AI use cases with completed impact assessment |
| Compliance | Overdue high-risk audit findings | % findings closed within agreed timeframe |
Thresholds make metrics meaningful
A number without a threshold is trivia. For each indicator, agree with management and the Board:
- Target — where we want to be.
- Tolerance — the range we can accept.
- Trigger — the point at which the Board must be told immediately.
Use simple status labels alongside colour (On track / Watch / Action required) so the message is clear in print and for colour-blind readers.
Tell a story
The best Board reports read like a briefing, not a spreadsheet:
- The headline — one paragraph on overall posture against appetite.
- What’s changed — new threats, incidents, regulatory obligations.
- Indicators — five to eight KRIs and KCIs with trends and thresholds.
- Programs — status of major uplift initiatives.
- Decisions required — clearly stated, with options.
If a director can read your report in five minutes and know what decision they’re being asked to make, the report is working.
Connect it to obligations
For many organisations, Board reporting also supports specific obligations — SOCI Act CIRMP attestation, PSPF reporting or AI governance under ISO 42001. Building one reporting model that serves all of them avoids duplicated effort and inconsistent messages.
Frequently asked questions
How many metrics should a Board cyber report include?
Usually five to eight core indicators. More than that dilutes attention. Detailed metrics can sit in an appendix or operational dashboard.
How often should Boards receive cyber risk reports?
Quarterly is common, with immediate escalation when a trigger threshold is breached. Risk or audit committees may receive more detailed reporting more often.
Can GRC platforms automate KRI and KCI reporting?
Yes. Platforms such as ServiceNow IRM can calculate indicators from operational data, track thresholds and produce consistent reports — provided the indicators are designed well first.
Want Board reporting that drives better decisions? Explore executive advisory or talk to my AI agent.