Why performance, risk, and control need three different indicators — not one number everyone agrees to watch.

A security dashboard can be entirely green and still tell you almost nothing about risk.

Access reviews completed on time. Training finished. Vulnerabilities closed within target. Incidents resolved inside SLA. Those numbers prove the team is working. They don’t prove exposure is shrinking, or that the controls behind them still hold.

Three questions, not one

That’s why a measurement model has to answer three separate questions. Are we running the program as intended? Is our exposure moving toward the line we said we wouldn’t cross? Are the controls we depend on actually operating?

Those are the jobs of the Key Performance Indicator (KPI), the Key Risk Indicator (KRI), and the Key Control Indicator (KCI). The labels matter less than keeping the three questions apart.

Watch all three come out of one piece of work. Access reviews completed on schedule — that’s performance. A steady climb in standing privileged-access exceptions — that’s risk. Whether the review actually removes access that shouldn’t exist — that’s control. Same activity, three different truths. A program can be green on the first, quietly red on the second, and never have seriously asked the third — which is how a team ends up busy, on schedule, and accumulating risk at the same time.

The average that hid the exposure

Here’s a version of this I’ve watched play out. Make the phishing pass rate the number everyone reports, and it improves — sixty percent, then eighty-five, then ninety. A genuinely pleasant slide to present.

Then look at who’s left in the failing remainder. Often the same people every quarter, and not a random sample — the senior people, the ones with broad access, payment authority, or the mailbox an attacker would actually pick.

The pass rate wasn’t lying. As a performance number, it was telling the precise truth, which is what made it so hard to argue with. The average improved. The exposure never moved, because it was concentrated in exactly the group the average was busy diluting.

Averages make dashboards tidy. Concentration is where the risk lives.

And an indicator without a threshold agreed in advance is just a number everyone watches drift. That isn’t governance. It’s spectating.

The real test

Here’s one test, applied to the year rather than the quarter: if your dashboard stayed uniformly green through an acquisition, a cloud migration, a reorganization, two incidents, and forty percent headcount growth, the calm isn’t evidence that nothing moved. It’s evidence that nothing you were watching was capable of noticing.


Vikas Khandelwal is the Founder & Principal Consultant at Secalyx Technologies, and author of the upcoming From Risk to Trust series for CISOs and cybersecurity leaders.

Leave a Reply

Your email address will not be published. Required fields are marked *