The Risk to Register section opens with a risk you can tweak and copy right into your own risk register, and Mitigation Monday will give you something related to help address the risk. The body of each issue will explore one of the topics under the four pillars to help you map it into your own business. This week’s issue is free to all subscribers!
A lack of regular reporting of Key Risk Indicators (KRI) or Key Performance Indicators (KPI) can lead to lapses in control effectiveness.
Today’s risk is loaded with IT governance, risk, and compliance jargon, but it does not diminish the importance once you unpack it. There is a saying “measure what matters” (and also the title of a book), meaning you have to understand what progress is being made to know whether you are doing the right things. The easiest analogy is our own personal health data. Assuming you go at least annually to the doctor, you are getting your weight, blood pressure, cholesterol, and many other numbers measured each year. Why those numbers? Because they matter to long term health.
If you are actively working on improving your health, then you may measure some of them more frequently, quarterly, monthly, or even daily. The changes to the measurements over time become important to knowing if what you are doing is working. These become your personal health KRIs and KPIs. High cholesterol is a KRI predicting future health problems. The miles run per day is your KPI. Are you getting more resilient and faster and meeting your performance expectations? Tying back to last week’s issue on controls, for health, your controls are choosing what you eat, getting regular exercise, and even taking your measurements on the right schedule.
When you do not take those measurements, and as a result, do not know if your performance is improving or risks getting worse, it means you also do not know if your “controls” are working. Is that diet helping? Are you active enough? This is the measurement of control effectiveness. Are the things you are doing designed to meet your goals, or missing the mark? IT risk management is very similar to managing our own health. There are things we need to do regularly (e.g. exercise your disaster recovery plan) and plenty we have to measure.
To help ensure we are doing it, we have to report on it regularly. Every organization will have its own reporting schedule, but a safe minimum is an executive report at least quarterly of the top risks and performance measurements. When we do not have a reporting schedule, it can lead to lapses in taking the measurements, and that can lead to lapses in running the underlying controls we need to make sure things are improving, not getting worse.
At ComplianceXO, the comparison was often made between your business’s health and a person’s own health. We use a lot of overlapping terminology, such as stress testing or resilience. When it comes to understanding your IT risk, compliance, and security program, it should be thought of as a fitness program. The right combination of diet (your systems) and exercise (your operations) should lead to a long, healthy lifetime for your IT investments. Lapses in either can quickly lead to vulnerabilities, incidents, and even outages. The other thing in common between our own health and IT health is the need to always improve our efforts.
Your IT program will never reach a finish line. The main reason? The risks are constantly changing. Is that warehouse management system you installed 20 years ago still working flawlessly? That is amazing, but could you hire a new person who knows how to maintain it? If the hardware it is running on fails, could you buy replacements? Or perhaps you just built a brand-new application, it should be good for a while, right? All software has vulnerabilities, and those are getting discovered, exploited, or patched on an ongoing basis. To keep it up and running, you are going to have to continue to update it. Add to these examples the changing customer demands, competitors, and even new opportunities to run your business more efficiently. The old saying, “the only constant is change,” means your IT will be changing, continuously.
A stagnant governance program is one which will eventually fail.
You likely will not be able to build a perfect governance program from the start. It will have to be a long-term plan, working toward an agreed goal. From the beginning, you will be working on improving your efforts every day. Between the world changing and your internal goals, compliance standards assume and expect you to have a plan for continuous improvement. A stagnant governance program is one which will eventually fail. The antidote is to define what continuous improvement means to your business and make it part of the program. This begins with defining your reporting cadence and your Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs). Then you will need to connect those to the underlying data and analytics available or create new sources where they are missing.
Most compliance standards require some level of regular reporting to key stakeholders. This could be to a board of directors or the executive leadership team. Sometimes it could be to key customers as well. It is important for you to know what is expected for your industry and compliance goals. Absent any strict requirement, you should plan for at least quarterly reporting on more critical items, and then an annual report on the entire program (with appropriate levels of executive summaries). The recipient of the report should be the board (if you have one) or key executives such as the CEO, CFO, and head of legal, or their equivalents in your company. And even if you are a one-person company, do not think you can skip the formality of a reporting cadence just because you already know the results. The habit and exercise will be a benefit to you, especially if you later grow larger.
As for choosing your KPIs and KRIs, this too depends on your business and your compliance obligations. In the world of IT risk, KPIs would focus on numbers you want to grow, such as number of customers served by hosting cost. Or number of tickets closed by a particular service level time period. The KRIs are numbers you want to decrease. These include number of cyber incidents detected, number of trouble tickets opened, vulnerabilities in software, and more. Keep in mind you will have plenty of performance and risk indicators. It is up to you which ones are key to your business. Ultimately you will need to track and report all of these metrics. But they might roll up to a unified KPI or KRI which makes it to your quarterly report.
Once you are measuring and reporting your KPIs and KRIs, you have begun building your continuous improvement program. The second half is understanding the trends of those measurements and taking action to improve the numbers. If your KPIs are getting better, that is great. Can you find ways to create new efficiencies or make things even more reliable? If they are slipping, do you know why and do you take action to correct it? The same questions apply to KRIs as well. Since new risks are always being discovered, are you being proactive at mitigating both the new ones and old ones, so that your KRIs also are improving over time? Continuous improvement is a two-fold exercise. First, measure. Second, correct. And then you repeat the process forever.
Since building a health IT program is a journey, you have to plan for long term growth and the unknown challenges of the future. The most effective way to do so is to have the process in place to know where you are performing today and where you would like to be in the near future. Your continuous improvement exercises help you make those decisions. Measuring what matters to your business and watching the trends gives you insight into whether you are doing the right things the right way or need to make changes. The end result is you will have a healthier, more resilient business, ready to face those future challenges and opportunities.
And that is an improvement we should all be happy to make.
If you do not have an executive IT Risk and Opportunity meeting on the calendar, go schedule it now. It is okay to schedule it for next quarter, so you have some time to build the report, but to start building the habit of regular reporting, you have to start with the first one. In the effort of scheduling the meeting, you will also be deciding who should attend, which is another important aspect to document. Once you have the when and the who, you will now have some time to decide what to report.
If you have not done an IT Risk Assessment before, you may need this as a starting point. It gives you a baseline of your current strengths and weaknesses and opportunities for improvement. You can use this to help decide what KPIs and KRIs are important to your business. Then, between now and the meeting you scheduled, you can spend the time finding out how to measure how things are working for those KPIs and KRIs. Sometimes you will find you have the data, but no summary. Other times, you will have to start logging the information. Both are good discoveries to make and correct, and you should count them as part of your continuous improvement.
The end result of this mitigation is you should have a plan on how frequently you’ll report to leadership the overall health and risk of your IT program, who should be involved, and not only what you’ll measure, but how you will too. This effort will tie right back into your continuous improvement goals, and your overall IT risk, compliance, and security goals.
Happy mitigating!
Thanks for reading The Risk Register by ComplianceXO! This post is public so feel free to share it.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.