Key Risk Indicator (KRI)
Definition
A metric that measures the level or trend of a specific risk exposure. KRIs are often leading indicators: they change before a risk event occurs, giving management time to act. Example: number of critical vulnerabilities unpatched beyond 30 days.
- Indicator type
- Leading
- Measures
- Level or trend of a specific risk exposure
- Example metric
- Count of critical vulnerabilities unpatched beyond 30 days
- Domain
- Security metrics and continuous monitoring
Common questions
Why are KRIs described as leading indicators?+
They change ahead of an actual loss event, for example a rising count of unpatched critical vulnerabilities signals growing exposure before any breach occurs, giving management a window to reallocate resources or escalate remediation before the risk materialises.
How does an organisation set the threshold for a KRI?+
Thresholds are usually set from historical baselines, risk appetite statements, and regulatory or contractual obligations, with escalation triggers defined so that crossing the threshold automatically prompts a documented review rather than being noticed only in hindsight.
Related terms
- Compliance Dashboard
- An automated reporting surface that aggregates metric and control-status data and presents it in a format aligned to one or more regulatory...
- Continuous Monitoring
- An automated control framework that applies fraud indicator tests to transactions as they are processed or on a frequent scheduled basis, generating...
- Control Effectiveness
- The degree to which a security control achieves its intended objective under real operating conditions. Measured through a combination of design review...
- Key Performance Indicator (KPI)
- A metric that measures how well a specific control or process is performing against a defined target. KPIs are often lagging indicators:...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...