Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Cybersecurity KRIs: 8 Metrics That Show Whether Your Security Program Is Actually Working

Compliance checkboxes tell you whether controls exist. Cybersecurity KRIs tell you whether they're functioning. Here are the 8 metrics NYDFS Part 500, the FFIEC IT Examination Handbook, and security-mature financial institutions actually track — with Green/Amber/Red thresholds and calibration guidance.

By Rebecca Leung · June 5, 2026 ·
Table of Contents

TL;DR:

  • Cybersecurity KRIs measure whether your controls are reducing exposure — not just whether they exist. NYDFS enforcement has handed out over $144 million in fines since 2021, and the gap between “we have controls” and “they’re functioning” is exactly what examiners and adversaries exploit.
  • The 8 KRIs here cover the four domains that produce the most enforcement findings: patch management, authentication, phishing resilience, and access governance.
  • Green/Amber/Red thresholds need to be calibrated to your risk appetite — not industry averages — and revisited annually as the threat environment changes.
  • Regulators (NYDFS, FFIEC, FTC) don’t mandate specific KRI formats, but they do expect evidence of ongoing monitoring. Metric documentation is evidence. Silence is not.

The Gap Between “Controls Exist” and “Controls Work”

In January 2025, NYDFS fined PayPal $2 million for a 2022 data incident. The company’s engineering team made changes to data flows that exposed unmasked personal data — including Social Security numbers — without adequate training or testing controls in place. Not a sophisticated attack. A process gap that metrics would have caught: someone making a material configuration change without going through a change management process that had security review in the loop.

In August 2025, NYDFS fined Healthplex $2 million for a 2021 phishing incident. A threat actor compromised an employee’s Office 365 account and gained complete access to their email — because MFA was not enabled for Outlook Web Access. Not a zero-day exploit. An MFA coverage gap on one application.

Both enforcement actions resulted from the same basic failure: the organization had security policies and security tools, but no one was tracking whether those tools were covering what they were supposed to cover. There was no KRI showing that MFA coverage on email was 94% (not 100%). There was no KRI showing that a critical system was being modified by personnel who hadn’t received security training.

Over $144 million in NYDFS Part 500 enforcement penalties since 2021. Twenty-seven enforcement actions. The pattern across almost all of them: controls were described in policy but not measured in practice.

That’s the gap cybersecurity KRIs exist to close.

KRIs vs. Controls: What the Difference Actually Means

A cybersecurity control is a protective mechanism — a technical or process implementation. MFA on your VPN is a control. A patch management process is a control. Quarterly access reviews are a control.

A cybersecurity KRI is the metric that tells you whether the control is functioning as designed — and whether your residual exposure is within acceptable bounds.

The distinction matters for three reasons:

Controls are binary. KRIs are continuous. Your policy either says “we do access reviews” or it doesn’t. But the KRI — percentage of privileged accounts reviewed in the last 90 days — gives you a health reading. A program that reviews 94% of privileged accounts in 90 days is meaningfully different from one that reviews 73%, even if both can check the “we have access reviews” box.

Controls describe inputs. KRIs describe outcomes. A control says “we patch critical vulnerabilities.” The KRI says “average days to remediate critical vulnerabilities is 22 — up from 16 last quarter.” One is a policy commitment; the other is a risk signal.

Examiners and adversaries both look at outcomes, not inputs. Your NYDFS examiner will ask what your patch compliance rate is. A ransomware operator scans for systems with unpatched critical vulnerabilities. Both are asking the same question: is your exposure actually under control?

The 8 Cybersecurity KRIs to Track

These eight metrics cover the domains most commonly cited in NYDFS enforcement actions, FFIEC IT examination findings, and FTC Safeguards Rule enforcement. They’re organized by domain.

Domain 1: Vulnerability Management (2 KRIs)

KRI 1: Critical vulnerability remediation time

What it measures: Average days from detection to remediation for critical-severity vulnerabilities.

Why it matters: Unpatched critical vulnerabilities are the single most common initial access vector in financial services breaches. CSBS Cyber Hygiene Fundamentals set 15 days for critical vulnerabilities. NYDFS examination findings consistently flag institutions with average remediation times above 30 days.

StatusThreshold
GreenAverage ≤20 days; no critical vulnerability open >30 days
AmberAverage 21–30 days; 1–3 criticals open >30 days
RedAverage >30 days; 4+ criticals open >30 days

Escalation: Red triggers CISO review within 24 hours, written remediation plan within 5 business days.

KRI 2: Patch compliance rate (critical and high)

What it measures: Percentage of systems with critical/high-severity patches applied within the target window (typically 30 days for critical, 60 days for high).

Why it matters: Patch coverage tells you whether your vulnerability management program is reaching the full environment or leaving pockets of exposure. A program that patches well-managed servers but misses legacy systems, OT endpoints, or recently onboarded cloud resources has a false compliance rate.

StatusThreshold
Green≥90% critical patches applied within 30 days
Amber80–89% critical patches within 30 days
Red<80% critical patches within 30 days

Calibration note: The 90% threshold is a starting floor, not a ceiling. Institutions with higher-risk environments (financial crime exposure, sensitive consumer data) should target 95%+.

Domain 2: Authentication (2 KRIs)

KRI 3: MFA coverage — privileged and remote access

What it measures: Percentage of privileged accounts and remote access pathways protected by MFA.

Why it matters: MFA is explicitly required under NYDFS Part 500 Section 500.12 (effective November 1, 2025) for any individual accessing any information systems from an external network or with privileged access. NYDFS examiners identify MFA gaps as a top enforcement priority. The Healthplex enforcement action came down to a single application missing MFA coverage.

StatusThreshold
Green≥99% privileged accounts with MFA; 100% remote access pathways
Amber96–98% privileged accounts; any remote access gap under investigation
Red<96% privileged accounts; any unresolved remote access gap >15 days

Note: For institutions subject to NYDFS Part 500, anything below 100% on remote access requires a documented exception with a compensating control and remediation timeline.

KRI 4: Privileged access review completion rate

What it measures: Percentage of privileged accounts reviewed and re-certified within the required review cycle (typically quarterly for privileged users).

Why it matters: Access review exceptions — terminated employees with active accounts, excessive privilege, accounts with no recent activity — are consistently found in examination findings. The FFIEC Information Security Booklet specifically addresses access rights reviews as a critical control. Ghost accounts and privilege creep are real vectors.

StatusThreshold
Green≥95% privileged accounts reviewed within cycle; zero terminated employee accounts active >24 hours post-offboarding
Amber88–94% reviews completed on time; 1–2 offboarding misses
Red<88% reviews completed; 3+ offboarding misses; any account active >5 business days post-termination

Domain 3: Phishing Resilience (2 KRIs)

KRI 5: Phishing simulation click rate

What it measures: Percentage of employees who click the simulated phishing link in scheduled phishing awareness exercises.

Why it matters: Phishing remains the leading initial access vector for financial services breaches. Consistent measurement of employee susceptibility — not just training completion — identifies departments, roles, or individual employees who need additional coaching before a real attack. NYDFS Part 500 requires training programs; click rate is the metric that tells you whether your training is effective.

StatusThreshold
Green<8% click rate across organization; <12% in any single department
Amber8–15% overall; 12–20% in any department
Red>15% overall; >20% in any department; no improvement over 3 consecutive tests

Calibration note: Thresholds should be tighter for roles with elevated access (finance, IT, executive assistants). A 10% click rate in your accounting team is a different risk than 10% in a business operations group.

KRI 6: Security awareness training completion rate

What it measures: Percentage of employees who completed required security awareness training within the cycle window.

Why it matters: NYDFS Part 500 Section 500.14(a) requires regular cybersecurity awareness training for all personnel. Training completion rate is the foundational metric — but it’s a leading indicator of phishing resilience, not a substitute for click rate data.

StatusThreshold
Green≥98% completion within cycle
Amber92–97% completion; gap under active remediation
Red<92% completion; or gap persisting >30 days without documented remediation

Domain 4: Incident Detection and Response (2 KRIs)

KRI 7: Mean time to detect (MTTD) — security incidents

What it measures: Average time from when a security incident begins to when it is detected by your security monitoring program.

Why it matters: MTTD is a direct measure of detection effectiveness. An attacker who has been inside your network for 120 days before detection has had time to exfiltrate data, establish persistence, and escalate privileges in ways that dramatically increase breach severity. Tracking MTTD over time shows whether your threat detection investments are working. NYDFS Part 500 Section 500.6 requires continuous monitoring or periodic testing of security controls — MTTD is how you measure the result.

StatusThreshold
GreenMTTD trending ≤24 hours for high-severity alerts; ≤72 hours for medium
AmberMTTD 24–72 hours for high-severity; increasing trend over 2 quarters
RedMTTD >72 hours for high-severity; no established baseline after 6 months

Note: Establishing a MTTD baseline takes time and requires mature security event logging. If you don’t have a baseline yet, the first step is instrumenting your SIEM or log aggregation to produce alert timestamps reliably.

KRI 8: Incident notification timeliness

What it measures: Percentage of confirmed reportable security incidents where the required notification was completed within the regulatory deadline (NYDFS: 72 hours from discovery; FFIEC banking regulators: 36 hours).

Why it matters: Notification failures are a separate enforcement category from the incident itself. The FFIEC 36-hour computer security incident notification rule requires banking organizations to notify their primary federal regulator within 36 hours of determining that a computer-security incident has materially disrupted operations. NYDFS requires notification within 72 hours of becoming aware of a cybersecurity event. Missing either clock is a separate violation — and NYDFS has fined institutions specifically for late notification.

StatusThreshold
Green100% of required notifications filed within regulatory window
AmberOne late notification in trailing 12 months; post-incident process review completed
RedTwo or more late notifications in trailing 12 months; or notification process not tested in prior 12 months

Calibrating Thresholds to Your Environment

The thresholds above are starting points, not universal benchmarks. Three calibration factors matter:

Risk appetite. A community bank serving local depositors has a different risk profile than a national fintech processing high-dollar real-time payments. Tighter thresholds are warranted for institutions with higher exposure — more sensitive data, more complex environments, higher regulatory scrutiny.

Historical performance. If your patch compliance rate has been consistently at 96%, an Amber threshold at 80–89% is effectively no trigger at all. Set thresholds close enough to your baseline to actually function as early warning signals — typically, Amber starts at 80–85% of your historical baseline.

Trend direction. A KRI at 88% that’s been at 88% for three consecutive quarters is stable. A KRI at 88% that was at 94% two quarters ago is a problem worth escalating even if it hasn’t crossed the Red line. Track trend as well as absolute value.

Thresholds should be reviewed annually — at minimum after any material change to the threat environment (a new threat vector becoming prominent), your business (an acquisition, a major system change), or your regulatory requirements.

What NYDFS and FFIEC Examiners Actually Look For

NYDFS examiners conducting Part 500 examinations are looking for evidence that the CISO has visibility into security program health through ongoing metrics — not just a static risk assessment conducted once a year. When you get examination requests for cybersecurity program documentation, what satisfies the examiner isn’t a binder of policies. It’s a history of metric tracking showing that you’re monitoring whether those policies are being executed.

The FFIEC IT Examination Handbook takes the same posture. The Information Security Booklet explicitly calls for “developing and implementing metrics for evaluating progress toward strategic security goals” and “identifying, measuring, mitigating, monitoring, and reporting heightened cybersecurity risks.” That’s a KRI program description.

The common failure pattern in NYDFS enforcement actions isn’t “they had no security policies.” It’s “they had security policies but no ongoing measurement showing whether those policies were being executed at the control level.” The gap between policy and execution is where the fines live.

So What?

If you’re running a compliance or risk function at a financial institution and you can’t answer these questions today — this is where to start:

Before next board meeting: Pull your current patch compliance rate for critical vulnerabilities, your MFA coverage percentage for privileged users, and your security awareness training completion rate. These three numbers are the first ones NYDFS will ask for.

Within 90 days: Establish Green/Amber/Red thresholds for all 8 KRIs above, document the calibration rationale, and wire them into your risk reporting cadence.

Annually: Recalibrate thresholds based on the prior year’s actuals and the current threat environment. A threshold that was appropriate in 2024 may be too lenient in 2026 — the AI-assisted phishing environment has materially changed what “acceptable” click rates look like.

The KRI Library includes pre-built cybersecurity KRIs alongside 132 total KRIs across compliance, operational, financial, vendor, and BSA/AML domains — each with calibrated thresholds, data source fields, and escalation trigger definitions. If you’re building a KRI program from scratch or need a defensible starting set to bring to your risk committee, it’s designed for exactly that.

Your CISO has the controls. The KRIs tell you whether they’re working.


Sources: NYDFS 23 NYCRR Part 500; FFIEC Information Security Booklet; NIST Cybersecurity Framework 2.0; NYDFS enforcement actions against PayPal (January 2025) and Healthplex (August 2025); CSBS Cyber Hygiene Fundamentals.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What's the difference between a cybersecurity KRI and a cybersecurity KPI?
KPIs (Key Performance Indicators) measure activity — how many patches were applied, how many phishing simulations ran, how many vulnerabilities were scanned. KRIs (Key Risk Indicators) measure exposure — whether the activity is actually reducing the likelihood of a significant security event. A KPI might show your team closed 500 vulnerability tickets last month. A KRI shows how many critical vulnerabilities remain open past 30 days. One measures throughput; the other measures residual risk. Your board and regulators care about the KRI.
What does NYDFS Part 500 require for cybersecurity metrics?
NYDFS Part 500 (23 NYCRR 500) does not mandate specific KRIs by name, but requires covered entities to conduct periodic risk assessments, maintain an ongoing cybersecurity monitoring program, and provide the CISO with sufficient authority and resources to manage cybersecurity risk. Section 500.4(b) requires the CISO to provide an annual written report to the board covering the cybersecurity program, material cybersecurity risks, and remediation progress. In practice, that report needs metrics — and NYDFS examiners expect to see evidence of ongoing monitoring, not just a point-in-time assessment.
What is a good patch compliance rate benchmark for financial institutions?
The CSBS Cyber Hygiene Fundamentals recommend remediating critical vulnerabilities within 15 calendar days and high-severity vulnerabilities within 30 days. Most security-mature financial institutions target 90% or more of critical vulnerabilities remediated within 30 days as a baseline Green threshold. Anything below 80% compliance warrants investigation. What matters as much as the threshold is the trend — if your patch rate is declining quarter over quarter, that's a signal regardless of whether you're technically above the Red line.
How often should cybersecurity KRIs be reported to the board?
Critical cybersecurity KRIs (MFA coverage, open critical vulnerabilities) should be reviewed by the CISO or security leadership at least monthly. Board-level reporting typically occurs quarterly, with Red KRIs escalated immediately to the CISO and within the next scheduled reporting cycle to the board. NYDFS Part 500 requires an annual written board report. Most examinations will ask to see evidence that the board received regular updates — not just the annual report.
What do NYDFS Part 500 examiners look for during cybersecurity examinations?
NYDFS examiners consistently focus on MFA coverage (especially for privileged access and remote access), vulnerability management processes and aging, incident notification timeliness, third-party service provider security programs, and access privilege management. The enforcement actions against PayPal ($2M, January 2025) and Healthplex ($2M, August 2025) both involved MFA gaps and inadequate monitoring — the same issues that appear in NYDFS examination findings across the industry.
Do fintechs need cybersecurity KRIs even if they're not directly regulated by NYDFS?
Yes. Bank partners increasingly require evidence of cybersecurity program health as part of ongoing oversight. The FFIEC IT Examination Handbook and OCC guidance apply to any bank partner conducting due diligence on a fintech. FTC Safeguards Rule requirements apply broadly to non-bank financial institutions. And practical reality: a security breach that affects a fintech's bank partner will trigger the bank's incident reporting obligations, making the fintech's security posture a bank-level compliance issue.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.