Risk Indicators
A breach is an escalation reason in its own right
Indicators sit on any programme with thresholds and a reading history. When a reading crosses the warning or critical line, the review opens before anyone has to notice the trend.
- KRI thresholds resolve to Within Threshold, Warning Breach, Critical Breach or No Recent Data
- KPI target, variance and direction, so improvement and deterioration are unambiguous
- Owner, frequency, data source, formula and next-reading-due on every indicator
- Readings acknowledged; links to the controls and findings the indicator bears on
In the application · Assure
- Risk indicators
- Readings
- Cross-programme monitoring
- Program dashboards
- Global overview
Privileged accounts without review
KRI · monthly · owner: Security Operations
Thresholds
Indicators that know what they are attached to
An indicator is bound to the risk, objective or programme it measures. A rising indicator points at the objective it endangers, and the objective page shows the indicators that would reveal its risks materialising.
- Warning and critical thresholds per indicator
- Breach history and trend per indicator
- Indicators on enterprise, operational, IT, cyber and third-party programmes
- Metrics on objectives with baseline, target and cadence
Privileged accounts without review
KRI · monthly · owner: Security Operations
Escalation
The review opens itself
A breach is a trigger for the workflow engine: notify the owner, escalate up the ladder, mandate treatment, or open a reassessment. What happens is configured per programme in the same designer as every other flow.
- Breach → escalation reason → workflow action
- Program dashboards and a global overview across programmes
- No Recent Data surfaced as its own state, not hidden as green
- Reading history exported with the board pack
- Finding created · severity ≥ HighTrigger
- owner.department = TechnologyCondition
- Remediation plan → Head of TechnologyApproval
- No decision in 5 days → CISOEscalation
- Set state: In progress · notify assigneesAction
Versioned, simulated before publish, run by the engine with every step logged
Framework alignment
Works with your control frameworks
This module shares the platform control library. International standards, sector regulations and your own internal standard are loaded the same way and mapped to one another, wherever you operate.
Solutions by role
Built for your team
See risk indicators in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.