Checklist

Cyber Risk Metrics Checklist

Cyber risk metrics should show condition, trend, exposure, decision needs, and follow-up. A metric is weak if it looks impressive but does not help anyone decide what to do.

Purpose: Use this checklist to test whether a proposed metric helps a decision. Not every operational measure needs to become a board or risk metric.

Metric quality checklist

PurposeWhich risk, objective, or decision does the metric support?
DefinitionAre numerator, denominator, scope, exclusions, and timing documented?
OwnerWho supplies the data, interprets it, and acts on it?
ThresholdWhat value or condition requires review or escalation?
TrendCan results be compared consistently over time?
Data qualityAre completeness, delay, error, and manual adjustment understood?
ContextDoes the metric show affected services, criticality, or consequence?
ActionabilityCan a responsible owner change the result?
BalanceIs it paired with outcome, control, exposure, or decision measures as needed?
AudienceIs the level of detail appropriate for operations, executives, or the board?

Worked examples

{rows}
ExampleContext / RatingCondition / SafeguardDecision / Result

How to use this page

  1. Write the decision first, then select the measure.
  2. Test the definition on real records before publication.
  3. Show trend and commentary together.
  4. Review metrics that remain green but no longer reflect exposure.
  5. Retire measures that create reporting work without decision value.

Cautions

  • Activity volume is not automatically risk reduction.
  • Red/amber/green requires written thresholds.
  • Averages can hide a critical service or business unit.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.

Frequently asked questions

Can a small organization use this tool?

Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.

Does this replace professional advice?

No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.

How often should it be updated?

Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.