Feature Compliance Strategy
Cybersecurity KRIs: 8 Metrics That Show Whether Your Security Program Is Actually Working
Compliance checkboxes tell you whether controls exist. Cybersecurity KRIs tell you whether they're functioning. Here are the 8 metrics NYDFS Part 500, the FFIEC IT Examination Handbook, and security-mature financial institutions actually track — with Green/Amber/Red thresholds and calibration guidance.
Table of Contents
TL;DR:
- Cybersecurity KRIs measure whether your controls are reducing exposure — not just whether they exist. NYDFS enforcement has handed out over $144 million in fines since 2021, and the gap between “we have controls” and “they’re functioning” is exactly what examiners and adversaries exploit.
- The 8 KRIs here cover the four domains that produce the most enforcement findings: patch management, authentication, phishing resilience, and access governance.
- Green/Amber/Red thresholds need to be calibrated to your risk appetite — not industry averages — and revisited annually as the threat environment changes.
- Regulators (NYDFS, FFIEC, FTC) don’t mandate specific KRI formats, but they do expect evidence of ongoing monitoring. Metric documentation is evidence. Silence is not.
The Gap Between “Controls Exist” and “Controls Work”
In January 2025, NYDFS fined PayPal $2 million for a 2022 data incident. The company’s engineering team made changes to data flows that exposed unmasked personal data — including Social Security numbers — without adequate training or testing controls in place. Not a sophisticated attack. A process gap that metrics would have caught: someone making a material configuration change without going through a change management process that had security review in the loop.
In August 2025, NYDFS fined Healthplex $2 million for a 2021 phishing incident. A threat actor compromised an employee’s Office 365 account and gained complete access to their email — because MFA was not enabled for Outlook Web Access. Not a zero-day exploit. An MFA coverage gap on one application.
Both enforcement actions resulted from the same basic failure: the organization had security policies and security tools, but no one was tracking whether those tools were covering what they were supposed to cover. There was no KRI showing that MFA coverage on email was 94% (not 100%). There was no KRI showing that a critical system was being modified by personnel who hadn’t received security training.
Over $144 million in NYDFS Part 500 enforcement penalties since 2021. Twenty-seven enforcement actions. The pattern across almost all of them: controls were described in policy but not measured in practice.
That’s the gap cybersecurity KRIs exist to close.
KRIs vs. Controls: What the Difference Actually Means
A cybersecurity control is a protective mechanism — a technical or process implementation. MFA on your VPN is a control. A patch management process is a control. Quarterly access reviews are a control.
A cybersecurity KRI is the metric that tells you whether the control is functioning as designed — and whether your residual exposure is within acceptable bounds.
The distinction matters for three reasons:
Controls are binary. KRIs are continuous. Your policy either says “we do access reviews” or it doesn’t. But the KRI — percentage of privileged accounts reviewed in the last 90 days — gives you a health reading. A program that reviews 94% of privileged accounts in 90 days is meaningfully different from one that reviews 73%, even if both can check the “we have access reviews” box.
Controls describe inputs. KRIs describe outcomes. A control says “we patch critical vulnerabilities.” The KRI says “average days to remediate critical vulnerabilities is 22 — up from 16 last quarter.” One is a policy commitment; the other is a risk signal.
Examiners and adversaries both look at outcomes, not inputs. Your NYDFS examiner will ask what your patch compliance rate is. A ransomware operator scans for systems with unpatched critical vulnerabilities. Both are asking the same question: is your exposure actually under control?
The 8 Cybersecurity KRIs to Track
These eight metrics cover the domains most commonly cited in NYDFS enforcement actions, FFIEC IT examination findings, and FTC Safeguards Rule enforcement. They’re organized by domain.
Domain 1: Vulnerability Management (2 KRIs)
KRI 1: Critical vulnerability remediation time
What it measures: Average days from detection to remediation for critical-severity vulnerabilities.
Why it matters: Unpatched critical vulnerabilities are the single most common initial access vector in financial services breaches. CSBS Cyber Hygiene Fundamentals set 15 days for critical vulnerabilities. NYDFS examination findings consistently flag institutions with average remediation times above 30 days.
| Status | Threshold |
|---|---|
| Green | Average ≤20 days; no critical vulnerability open >30 days |
| Amber | Average 21–30 days; 1–3 criticals open >30 days |
| Red | Average >30 days; 4+ criticals open >30 days |
Escalation: Red triggers CISO review within 24 hours, written remediation plan within 5 business days.
KRI 2: Patch compliance rate (critical and high)
What it measures: Percentage of systems with critical/high-severity patches applied within the target window (typically 30 days for critical, 60 days for high).
Why it matters: Patch coverage tells you whether your vulnerability management program is reaching the full environment or leaving pockets of exposure. A program that patches well-managed servers but misses legacy systems, OT endpoints, or recently onboarded cloud resources has a false compliance rate.
| Status | Threshold |
|---|---|
| Green | ≥90% critical patches applied within 30 days |
| Amber | 80–89% critical patches within 30 days |
| Red | <80% critical patches within 30 days |
Calibration note: The 90% threshold is a starting floor, not a ceiling. Institutions with higher-risk environments (financial crime exposure, sensitive consumer data) should target 95%+.
Domain 2: Authentication (2 KRIs)
KRI 3: MFA coverage — privileged and remote access
What it measures: Percentage of privileged accounts and remote access pathways protected by MFA.
Why it matters: MFA is explicitly required under NYDFS Part 500 Section 500.12 (effective November 1, 2025) for any individual accessing any information systems from an external network or with privileged access. NYDFS examiners identify MFA gaps as a top enforcement priority. The Healthplex enforcement action came down to a single application missing MFA coverage.
| Status | Threshold |
|---|---|
| Green | ≥99% privileged accounts with MFA; 100% remote access pathways |
| Amber | 96–98% privileged accounts; any remote access gap under investigation |
| Red | <96% privileged accounts; any unresolved remote access gap >15 days |
Note: For institutions subject to NYDFS Part 500, anything below 100% on remote access requires a documented exception with a compensating control and remediation timeline.
KRI 4: Privileged access review completion rate
What it measures: Percentage of privileged accounts reviewed and re-certified within the required review cycle (typically quarterly for privileged users).
Why it matters: Access review exceptions — terminated employees with active accounts, excessive privilege, accounts with no recent activity — are consistently found in examination findings. The FFIEC Information Security Booklet specifically addresses access rights reviews as a critical control. Ghost accounts and privilege creep are real vectors.
| Status | Threshold |
|---|---|
| Green | ≥95% privileged accounts reviewed within cycle; zero terminated employee accounts active >24 hours post-offboarding |
| Amber | 88–94% reviews completed on time; 1–2 offboarding misses |
| Red | <88% reviews completed; 3+ offboarding misses; any account active >5 business days post-termination |
Domain 3: Phishing Resilience (2 KRIs)
KRI 5: Phishing simulation click rate
What it measures: Percentage of employees who click the simulated phishing link in scheduled phishing awareness exercises.
Why it matters: Phishing remains the leading initial access vector for financial services breaches. Consistent measurement of employee susceptibility — not just training completion — identifies departments, roles, or individual employees who need additional coaching before a real attack. NYDFS Part 500 requires training programs; click rate is the metric that tells you whether your training is effective.
| Status | Threshold |
|---|---|
| Green | <8% click rate across organization; <12% in any single department |
| Amber | 8–15% overall; 12–20% in any department |
| Red | >15% overall; >20% in any department; no improvement over 3 consecutive tests |
Calibration note: Thresholds should be tighter for roles with elevated access (finance, IT, executive assistants). A 10% click rate in your accounting team is a different risk than 10% in a business operations group.
KRI 6: Security awareness training completion rate
What it measures: Percentage of employees who completed required security awareness training within the cycle window.
Why it matters: NYDFS Part 500 Section 500.14(a) requires regular cybersecurity awareness training for all personnel. Training completion rate is the foundational metric — but it’s a leading indicator of phishing resilience, not a substitute for click rate data.
| Status | Threshold |
|---|---|
| Green | ≥98% completion within cycle |
| Amber | 92–97% completion; gap under active remediation |
| Red | <92% completion; or gap persisting >30 days without documented remediation |
Domain 4: Incident Detection and Response (2 KRIs)
KRI 7: Mean time to detect (MTTD) — security incidents
What it measures: Average time from when a security incident begins to when it is detected by your security monitoring program.
Why it matters: MTTD is a direct measure of detection effectiveness. An attacker who has been inside your network for 120 days before detection has had time to exfiltrate data, establish persistence, and escalate privileges in ways that dramatically increase breach severity. Tracking MTTD over time shows whether your threat detection investments are working. NYDFS Part 500 Section 500.6 requires continuous monitoring or periodic testing of security controls — MTTD is how you measure the result.
| Status | Threshold |
|---|---|
| Green | MTTD trending ≤24 hours for high-severity alerts; ≤72 hours for medium |
| Amber | MTTD 24–72 hours for high-severity; increasing trend over 2 quarters |
| Red | MTTD >72 hours for high-severity; no established baseline after 6 months |
Note: Establishing a MTTD baseline takes time and requires mature security event logging. If you don’t have a baseline yet, the first step is instrumenting your SIEM or log aggregation to produce alert timestamps reliably.
KRI 8: Incident notification timeliness
What it measures: Percentage of confirmed reportable security incidents where the required notification was completed within the regulatory deadline (NYDFS: 72 hours from discovery; FFIEC banking regulators: 36 hours).
Why it matters: Notification failures are a separate enforcement category from the incident itself. The FFIEC 36-hour computer security incident notification rule requires banking organizations to notify their primary federal regulator within 36 hours of determining that a computer-security incident has materially disrupted operations. NYDFS requires notification within 72 hours of becoming aware of a cybersecurity event. Missing either clock is a separate violation — and NYDFS has fined institutions specifically for late notification.
| Status | Threshold |
|---|---|
| Green | 100% of required notifications filed within regulatory window |
| Amber | One late notification in trailing 12 months; post-incident process review completed |
| Red | Two or more late notifications in trailing 12 months; or notification process not tested in prior 12 months |
Calibrating Thresholds to Your Environment
The thresholds above are starting points, not universal benchmarks. Three calibration factors matter:
Risk appetite. A community bank serving local depositors has a different risk profile than a national fintech processing high-dollar real-time payments. Tighter thresholds are warranted for institutions with higher exposure — more sensitive data, more complex environments, higher regulatory scrutiny.
Historical performance. If your patch compliance rate has been consistently at 96%, an Amber threshold at 80–89% is effectively no trigger at all. Set thresholds close enough to your baseline to actually function as early warning signals — typically, Amber starts at 80–85% of your historical baseline.
Trend direction. A KRI at 88% that’s been at 88% for three consecutive quarters is stable. A KRI at 88% that was at 94% two quarters ago is a problem worth escalating even if it hasn’t crossed the Red line. Track trend as well as absolute value.
Thresholds should be reviewed annually — at minimum after any material change to the threat environment (a new threat vector becoming prominent), your business (an acquisition, a major system change), or your regulatory requirements.
What NYDFS and FFIEC Examiners Actually Look For
NYDFS examiners conducting Part 500 examinations are looking for evidence that the CISO has visibility into security program health through ongoing metrics — not just a static risk assessment conducted once a year. When you get examination requests for cybersecurity program documentation, what satisfies the examiner isn’t a binder of policies. It’s a history of metric tracking showing that you’re monitoring whether those policies are being executed.
The FFIEC IT Examination Handbook takes the same posture. The Information Security Booklet explicitly calls for “developing and implementing metrics for evaluating progress toward strategic security goals” and “identifying, measuring, mitigating, monitoring, and reporting heightened cybersecurity risks.” That’s a KRI program description.
The common failure pattern in NYDFS enforcement actions isn’t “they had no security policies.” It’s “they had security policies but no ongoing measurement showing whether those policies were being executed at the control level.” The gap between policy and execution is where the fines live.
So What?
If you’re running a compliance or risk function at a financial institution and you can’t answer these questions today — this is where to start:
Before next board meeting: Pull your current patch compliance rate for critical vulnerabilities, your MFA coverage percentage for privileged users, and your security awareness training completion rate. These three numbers are the first ones NYDFS will ask for.
Within 90 days: Establish Green/Amber/Red thresholds for all 8 KRIs above, document the calibration rationale, and wire them into your risk reporting cadence.
Annually: Recalibrate thresholds based on the prior year’s actuals and the current threat environment. A threshold that was appropriate in 2024 may be too lenient in 2026 — the AI-assisted phishing environment has materially changed what “acceptable” click rates look like.
The KRI Library includes pre-built cybersecurity KRIs alongside 132 total KRIs across compliance, operational, financial, vendor, and BSA/AML domains — each with calibrated thresholds, data source fields, and escalation trigger definitions. If you’re building a KRI program from scratch or need a defensible starting set to bring to your risk committee, it’s designed for exactly that.
Your CISO has the controls. The KRIs tell you whether they’re working.
Sources: NYDFS 23 NYCRR Part 500; FFIEC Information Security Booklet; NIST Cybersecurity Framework 2.0; NYDFS enforcement actions against PayPal (January 2025) and Healthplex (August 2025); CSBS Cyber Hygiene Fundamentals.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What's the difference between a cybersecurity KRI and a cybersecurity KPI?
What does NYDFS Part 500 require for cybersecurity metrics?
What is a good patch compliance rate benchmark for financial institutions?
How often should cybersecurity KRIs be reported to the board?
What do NYDFS Part 500 examiners look for during cybersecurity examinations?
Do fintechs need cybersecurity KRIs even if they're not directly regulated by NYDFS?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026