Most board cyber reports still look the same: a heat map, a list of projects, and a row of green traffic lights. Directors read them, ask a question or two, and move on. Then an incident happens, and it emerges that multi-factor authentication was missing on remote access, privileged accounts were never reviewed, and the incident response plan had not been tested in years.
That is not a hypothetical. It is close to the list of failures behind the $2.5 million penalty the Federal Court imposed on FIIG Securities in February 2026. This article sets out what regulators and director bodies across Australia, New Zealand, the Gulf and Malaysia now expect boards to see, and the twelve key risk indicators we recommend reporting every quarter.
Why the traffic-light report stopped working
The AICD and CSCRC Cyber Security Governance Principles, updated in November 2024, are direct about it. Board reporting should go beyond single data points and traffic lights, trend data gives particular insight, and results should be assessed against the board’s risk appetite using both lead and lag measures. The Principles also caution that a zero cyber risk appetite is unlikely to be appropriate or achievable.
A traffic light tells a director whether management is comfortable. A well-designed key risk indicator tells a director whether the organisation is moving towards a risk it has said it will not accept, early enough to act.
What regulators now expect boards to see
- ASIC and the courts. In ASIC’s action against FIIG Securities, the Federal Court imposed civil penalties for cyber failures under the general licence obligations for the first time. The failures ASIC listed read like a list of missing indicators: no multi-factor authentication for remote access, weak control of privileged accounts, no regular vulnerability scanning or penetration testing, no structured patching, and no incident response plan tested at least annually.
- APRA. In June 2025, APRA wrote to the chairs of every superannuation trustee requiring a self-assessment of authentication controls, multi-factor authentication for all high-risk activities and privileged access, and a named accountable person for CPS 234, with a deadline of 31 August 2025. Under CPS 230, boards also oversee critical operations and their tolerance levels.
- New Zealand. The Institute of Directors publishes a guide on reporting cyber security to boards, and the Government’s proposed critical infrastructure regime would make directors responsible for compliance through attestations.
- Saudi Arabia. The NCA’s Essential Cybersecurity Controls require a cybersecurity supervisory committee, and require audit and review results, including corrective actions, to be reported to that committee and the authorised official.
- Malaysia. Bank Negara Malaysia’s Risk Management in Technology policy, revised in November 2025, places technology risk appetite with the board.
KPIs, KRIs and thresholds
A key performance indicator looks back and asks whether an objective was met. A key risk indicator looks forward and asks whether risk is trending towards a level the organisation has said it will not accept. Boards need both, but the KRIs are the ones that change decisions.
Gartner’s approach is useful here. It describes outcome-driven metrics, which show how well the organisation is protected rather than how busy the security team is, and protection-level agreements, which turn risk appetite into a measurable target at a known cost. In practice, every KRI a board sees should have three things: a target, an amber threshold that triggers management action, and a red threshold that triggers a board conversation.
The 12 KRIs to report every quarter

The thresholds below are starting points we use with clients. Each board should calibrate them to its own risk appetite and regulatory position.
| # | Key risk indicator | Suggested amber / red | Why it earns a place |
|---|---|---|---|
| 1 | Multi-factor authentication coverage for remote and privileged access | Below 100% / below 98% | Missing MFA was central to the FIIG penalty and APRA’s 2025 letter |
| 2 | Privileged accounts reviewed in the last 90 days | Below 95% / below 85% | Uncontrolled privileged access turns an intrusion into a breach |
| 3 | Critical vulnerabilities on internet-facing systems open beyond the agreed deadline | Any / more than 5 | Vulnerability exploitation is now the top initial access vector in the Verizon DBIR 2026 |
| 4 | Known exploited vulnerabilities fixed within 14 days | Below 90% / below 75% | Verizon found only 26% of such vulnerabilities fully remediated, with a median of 43 days |
| 5 | Critical assets covered by endpoint detection and central logging | Below 98% / below 90% | Gaps in coverage are where attackers dwell |
| 6 | Mean time to contain incidents | Above 30 days / above 90 days | IBM’s 2026 research found Australian breaches taking over 200 days cost about 60% more |
| 7 | Restore tests passed for critical systems this quarter | Below 100% / below 90% | A backup that has not been restored is an assumption |
| 8 | Days since the incident response plan was last exercised | Over 180 / over 365 | An annual tested plan was one of ASIC’s explicit expectations |
| 9 | Critical third parties assessed in the last 12 months | Below 90% / below 75% | Third parties were involved in close to half of breaches in the 2026 DBIR |
| 10 | Phishing report rate compared with click rate | Report rate below click rate | A leading indicator of whether people act as a control |
| 11 | Audit and regulatory findings past their due date | Any high / more than 3 high | The Saudi ECC and most regulators expect corrective actions tracked to closure |
| 12 | Sensitive data stores encrypted at rest and in transit | Below 95% / below 80% | IBM found only 32% of Australian organisations had sensitive data encrypted both ways |
Putting a number on the downside
Directors will ask what an incident would cost. The most recent public data gives a credible range:
- IBM’s Cost of a Data Breach Report 2026 put the global average at US$4.99 million, a record, and the ASEAN average at US$4.12 million. Reporting on the Australian results put the local average at AUD 4.22 million.
- The OAIC received 1,205 notifiable data breach notifications in 2025, the highest since the scheme began, with 716 caused by malicious or criminal attacks.
- ASD’s Annual Cyber Threat Report 2024-25 recorded an average self-reported cybercrime cost of $56,600 for small businesses, $97,200 for medium businesses and $202,700 for large businesses.
Figures like these make the case for a KRI threshold in the language boards use: exposure and cost, not patch counts. Our guide to notifiable data breaches in Australia covers the reporting side.
How to present KRIs so the board uses them

- One page. Twelve indicators, each with the current value, the last four quarters, the target and the thresholds.
- Exceptions first. Lead with anything amber or red, with the owner, the cause and the date it will be back within appetite.
- Plain language. One sentence per indicator on what it means for the business, not how the control works.
- Independent evidence. The Principles recommend external audits and penetration tests by rotating providers. A board that only sees self-reported figures is relying on management’s view of management.
- Link to appetite. Every threshold should trace back to a risk appetite statement the board approved, so a breach of threshold is a decision point rather than a surprise.
For how appetite itself should change as AI enters decision-making, see risk appetite in the age of AI.
Related reading
- Measuring cyber success: developing cyber performance measures
- How to conduct a cybersecurity maturity assessment
- GRC in cybersecurity: why it matters
Frequently asked questions
What is the difference between a KPI and a KRI in cyber security?
A KPI measures whether a security objective was achieved, such as training completion. A KRI signals whether risk is moving towards a level outside the organisation’s appetite, such as rising numbers of unpatched internet-facing systems.
How many cyber metrics should a board see?
Around ten to twelve, on a single page with trend and thresholds. More than that and the exceptions get lost.
What did ASIC’s FIIG case mean for directors?
It was the first time the Federal Court imposed civil penalties for cyber security failures under the general obligations of an Australian financial services licence, and the failures identified map directly to basic control indicators.
How often should cyber KRIs be reported?
Quarterly to the board or its risk committee, with monthly monitoring by management and immediate escalation when a red threshold is crossed.
How Security Solution Consultants can help
Security Solution Consultants designs board cyber reporting for organisations in Australia, New Zealand, Saudi Arabia, the UAE and Malaysia. We define the indicators, calibrate thresholds to your risk appetite and your regulators, build the evidence trail behind each number, and brief directors on what to ask when an indicator turns amber.
Our enterprise risk management and cyber maturity assessment services pair with GRCLens, which calculates the indicators from live assessment and evidence data rather than a spreadsheet. To see how the same evidence serves several frameworks at once, read continuous compliance across NCA ECC, ISO 27001 and SOC 2 on GRCLens, then talk to us about your board pack.


