The IT department of a financial institution usually monitors threat indicators from many different systems. It is best practice to provide reporting of the most important metrics from this monitoring to senior management and to the board.
Deciding which of the many metrics to report can be the difficult part. It is critical to communicate important events and to demonstrate the effectiveness of the security program without overwhelming your audience that might not be technical-minded.
This week, we wanted to share a list of metrics that we commonly see reported to senior management and to the board of financial institutions. These metrics do a good job of balancing communicating important information without losing or overwhelming your audience. The metrics are as follows:
If your institution needs assistance in creating meaningful cybersecurity management reporting we have a couple CySPOTâ„¢ modules that might be a good fit.
With our Governance module we work with you to create a strategic plan and build out your information security program annual tasklist and calendar. But we also lead the monthly information security meetings, create the agenda, and keep the minutes. This allows you to be certain you're reviewing the right reports and covering all the items from month to month that you should be. Giving your team a clear picture of your program.
The other module that provides a great reporting from month to month is our Monitoring and Oversight module. With it you get what we call a "Key Risk Indicator" Dashboard, aka a high-level snapshot of your risk position. Your vCISO Specialist will work with your institution to identify and regularly receive the most useful reports for monitoring key controls. They will then review reports and provide a monthly summary of statistics to management as a KRI dashboard.
If you'd like more information on either of these modules, shoot us an email at support@bedelsecurity.com.