
Key risk indicator
7
MENTIONS
2
EPISODES
2
PODCASTS
Search complete. 7 mentions across 2 episodes found for "Key risk indicator".
Sep 21, 2026
How to Build a Cybersecurity Program from Scratch | CISO Transformation Playbook
I
65:28Ilyas KooliyankalGUEST
Like you say, I reached 2.0, you know, this may be my risk level.
I
65:33Ilyas KooliyankalGUEST
And there's another concept which I do not want to bring it here now to avoid confusion is there is KRIs and RISC.
I
65:43Ilyas KooliyankalGUEST
key risk indicator i think i read in your some of your articles also about it but you know kris and risk is two little different items but i don't want to mix it up now but we will probably if you want to ask you can ask and then i can explain a bit more because kri or indicator is a point in time indicator and risk is a little bit of a longer one which is overall you take okay so here i'm talking about risk in total but the metrics to monitor could be the kris you know an indicator of this could be you know some of the metrics you monitor over a period of time it is just what you call uh uh opposite or uh reciprocal to kpis KPI shows the performance and KRI shows the risk indicator, which is our objective is always to bring down the risk indicator to lower level.
I
66:44Ilyas KooliyankalGUEST
Our objective is to perform better in the control.
P
69:04Prabh NairHOST
yeah
I
69:04Ilyas KooliyankalGUEST
because you you do you don't do more than what the business wants you know business saying i'm ready to accept the risk if something goes down no problem i lose 2 million i don't mind you know i want to go fast then you go and say no no no you should not go fast you know so so it doesn't make sense you know because we are here security is there for business and that is a uh what you call um uh revelation what i had and then i thought you know i need to change the way i'm thinking on security and i need to make sure that i support the business and find ways solutions you know innovative ideas and how to communicate to the board and top management how to put it into their language how to connect security to the business services objective and what risk is to bother them from security so that i can tell that okay this risk can lead to your loss of business lots of revenue you know lots of customers then i can you know justify the investment justify the effort justify the process i'm building That is how I came up with a lot of these things.
I
70:16Ilyas KooliyankalGUEST
And the very, very relevant topic, as you suggested, on KRIs and KPIs, I have very, very interesting way of coming up with some very innovative structure for that matrices and KPIs.
I
70:30Ilyas KooliyankalGUEST
And even I designed dashboards, executive management dashboard with that.
The Speed of Threat
J
10:52Jeff SchiemannGUEST
And against that compromise and report stake in the ground, you know, every three quarters having something that we would need to declare, you know, how do we measure against that? You know, what are the type of threats we're seeing? What is the type of development infrastructure we need to put off new threats evolving? And then measure and report against that in a KRI to the board.
J
11:12Jeff SchiemannGUEST
So a key risk indicator.
J
11:14Jeff SchiemannGUEST
And the KRIs are different than KPIs.
J
11:15Jeff SchiemannGUEST
KPIs are backward looking.
J
11:17Jeff SchiemannGUEST
KRIs are forward looking.
J
11:18Jeff SchiemannGUEST
They want to know what does the risk landscape look like? forward-looking, where are you prepared for that risk landscape today? And that's really important for CISOs.
J
11:27Jeff SchiemannGUEST
Most CISOs are either too technical, so they tend to come from a technical background of a head of operations or security, and they like to talk about the things that blink and spin, as I call it.
J
11:40Jeff SchiemannGUEST
And or some CISOs are very much compliancy-rated, so they're very much performance-rated, compliance checklist-rated.