FAIR Institute Blog

FAIRCON18 Video: How to Identify Key Risk Indicators (KRIs) for Cybersecurity

[fa icon="calendar"] Dec 20, 2018, 7:30:00 AM / by Jeff B. Copeland

FAIRCON18 Presentation by Marta Palanques and Steve Reznik of ADP on Key Risk Indicators for CybersecurityIn this video from the 2018 FAIR Conference, Steve Reznik, Director, Operational Risk Management and Marta Palanques, Director, Enterprise Risk Management at ADP, one of the most advanced quantitative cyber risk management shops, show how to identify and track key risk indicators (KRIs) over time to judge the real success of your inforisk management efforts.  


Watch the video Key Risk Indicators: A Quantitative Approach now. A FAIR Institute membership is required – join now (it's free). 


As Marta says, “You can’t be running simulations every day. That’s not practical or useful…KRIs should be helping you figure out if anything has significantly changed since the last time you made a decision, for good and for bad.”

Don’t confuse KRIs with other cybersecurity metrics like unpatched servers, audited vendors or NIST CSF efficacy level, Steve and Marta warn. These indicators should be directly tied to your loss exposure and by adjusting the factors up or down in the FAIR model, you should be able to see potential loss exposure change. 

ADP uses the RiskLens Cyber Risk Quantification Platform for FAIR analysis and demonstrated a case study using the Sensitivity Analysis function of the platform to tweak the factors to see the effect on a baseline loss exposure. For instance, a decrease of one percent in vulnerability would reduce loss exposure by the same amount as by responding to an incident 10% faster.

“Sometimes this is eye opening in what is the best strategy to reduce a particular risk,” says Marta. “At the end of the day, the question is which of these risk factors could put you above your tolerance line and those are the ones you want to report on” – your cybersecurity KRIs.

Marta and Steve will be presenting on using FAIR to uncover KRIs at the upcoming RSA Conference. 


Watch the video Key Risk Indicators: A Quantitative Approach now. A FAIR Institute membership is required – join now (it's free). 


Topics: Risk Management, FAIR Conference 2018

Jeff B. Copeland

Written by Jeff B. Copeland

Jeff is the Content Marketing Manager for RiskLens.

Become A Member

Subscribe to Email Updates

417NjDVYgtL._SX404_BO1204203200_.jpg
Learn How FAIR Can Help You
Make Better Business Decisions

Recent Posts