Security dashboard: the cybersecurity KPIs worth tracking

Strategic, management and operational indicators, the ANSSI method, cybersecurity KPI examples and tips for presenting a security dashboard to the board.

· 10 min read
Illustration: a glass gauge with an orange needle above three bars

A security dashboard brings together the indicators used to steer and report on information security. A good one does not show everything: it shows each audience what it needs to decide, from the technical team to the board.

This guide draws on the method published by ANSSI, France's national cybersecurity agency, and on the work of Clusif, a French information security association, to explain how to choose indicators, separate management from operational ones, document each cybersecurity KPI and present the whole to management.

01

Security dashboard: definition and purpose

ANSSI's platform describes the security dashboard as a summary and visualisation tool to track all security actions, check that the security policy is applied both at management level and in the field, and make sure useful information reaches decision-makers.

It meets three needs. Steering: knowing whether the objectives set by the security policy are being met. Alerting: spotting drift before it becomes an incident. Reporting: justifying resources and obtaining decisions. In an ISMS, it feeds the monitoring and measurement required by ISO 27001, which ISO/IEC 27004 details as guidance.

02

ANSSI's method for building a security dashboard

The TDBSSI guide was written by DCSSI, ANSSI's predecessor, in a version dated 5 February 2004. ANSSI still offers it and considers it relevant. It defines an indicator as data combining the measurement of one or more key points, compared with history, a target or a threshold. Its approach has five steps:

  1. Prerequisites: identify recipients, define use and frequency, have security objectives, know the system and data sources, secure budget and resources.
  2. Project set-up: involve the stakeholders and form working groups.
  3. Design: formalise measurable objectives, choose what to measure, build indicators and dashboards, write data feeding procedures, get approval.
  4. Operation: produce and distribute the dashboards.
  5. Evolution: track their use and adapt them when context or objectives change.

The guide also sets qualities for each indicator: no duplication, proven usefulness against objectives, known causes of variation so you can act, and calculable at any time, simply and at reasonable cost. These criteria are often enough to remove half the indicators initially proposed.

03

Management or operational indicators: three levels

ANSSI's method distinguishes three dashboard levels. The strategic level gives a summary view to steer security policy, with six indicators at most. The management level tracks objectives by domain, with about twelve indicators. The operational level measures basic components and often acts as an alarm, with up to about twenty indicators. Clusif's 2018 guide adds a temporary dashboard, set up for the duration of a crisis or major vulnerability.

What matters is the link between levels: each strategic indicator should be explained by management indicators, themselves calculated from operational measurements. Choose a strategic indicator to see the chain behind it.

Consolidation From the field to the board
  • Coverage of major risks, fed by: Progress of the risk treatment plan, Overdue measures by department (management); Actions closed in the period, Overdue open actions (operational).
  • Exposure to critical vulnerabilities, fed by: Mean time to fix critical vulnerabilities, Share of assets covered by scans (management); Workstations and servers fully patched, Open vulnerabilities by severity (operational).
  • Security awareness level, fed by: Training rate by department, Click rate in phishing exercises (management); People trained in the period, Phishing reports received (operational).
  • Compliance with frameworks, fed by: NIS 2 or ISO 27001 compliance rate by site, Open audit findings (management); Requirements assessed, Missing evidence (operational).
Example indicators inspired by ANSSI and Clusif guidance; the volumes per level follow the TDBSSI method's recommendations.
04

Cybersecurity KPI examples by level

There is no universal list: good indicators follow from your objectives and risks. Here is a starting point, inspired by Clusif's examples and ANSSI's method.

Example security dashboard indicators by level
DomainStrategicManagementOperational
RiskMajor risks covered or not coveredTreatment plan progressOverdue open actions
VulnerabilitiesExposure to critical vulnerabilitiesMean time to fixWorkstations and servers fully patched
AccessPrivileged accounts under controlPrivileged access review rateAccounts without multi-factor authentication
PeopleShare of staff trainedClick rate in phishing exercisesReports received
IncidentsSignificant incidents and their impactIncidents by category and handling timeQualified alerts
ComplianceCompliance level with applicable frameworksOpen audit findingsMissing evidence
Third partiesCritical suppliers assessedAssessment progressPending questionnaires

Risk indicators read best alongside the risk matrix and risk map behind them; compliance indicators presuppose clearly identified frameworks; third-party indicators rely on your vendor risk management programme. Indicators specific to compliance tracking are covered in our article on compliance management.

05

Documenting each indicator: the indicator sheet

An undocumented indicator does not survive the departure of the person who calculates it. Clusif recommends keeping a sheet for each one that states:

  • the label and the security objective it relates to;
  • the calculation, unambiguously (numerator, denominator, scope);
  • the data source and how it is collected;
  • the update frequency;
  • the target and alert thresholds;
  • the indicator's owner.

In the United States, NIST published in December 2024 the two volumes of its Measurement Guide for Information Security (SP 800-55), covering how to select measures and set up a measurement programme: useful further reading.

06

Presenting the security dashboard to the board

The strategic level has gained weight with the NIS 2 Directive, whose Article 20 requires management bodies to approve cybersecurity risk management measures and oversee their implementation. Oversight requires something to oversee with. The ANSSI and AMRAE guide "Controlling the digital risk" devotes its final steps to how executives steer digital risk.

A few rules make the presentation effective:

  • Few indicators, six at most, always the same from one meeting to the next so trends speak.
  • A trend rather than an isolated figure: value, target and change since the last meeting.
  • Business language: "three days of production downtime" rather than "critical vulnerability on a server".
  • The decisions expected: a strategic dashboard ends with what you are asking management for (budget, risk acceptance, priority).
  • A link to the enterprise risk map, kept by the risk manager, so cyber is compared with other risks on the same scales.

Clusif's guide also stresses an often-neglected point: whoever presents must be able to explain every figure and every change. That is usually the CISO.

07

Common mistakes

  • Measuring what is easy rather than what matters: the number of blocked emails says nothing about risk.
  • Piling up indicators: beyond the reader's attention span, nobody reads any more.
  • Figures without targets: 87% is neither good nor bad without an objective.
  • Manual collection: each update takes days, figures arrive late and input errors pile up.
  • A frozen dashboard: ANSSI's method includes an evolution step; an indicator that no longer triggers any action should go.
08

How Phinasoft helps

The hard part of a security dashboard is rarely choosing indicators: it is feeding them. Phinasoft starts from data your teams already produce in the platform, rather than re-keying it:

  • indicators are calculated automatically from compliance assessments, risk analyses and action plans;
  • indicators can be calculated by framework and by scope, at different levels of detail, and linked frameworks avoid assessing the same requirement twice;
  • you build customised dashboards and generate summaries and exportable reports for management, business units and auditors;
  • you keep an overall view of action plans, with each owner tracking their own.

These features are described on the compliance campaigns and risk analysis module pages. To see a dashboard built on your own scopes, you can request a demo.

Going further: the broader governance, risk and compliance approach explains how dashboards fit into the whole picture.

Summary

01

Three levels, three audiences

Strategic for management (six indicators at most), management level for the CISO and domain owners, operational for technical teams.

02

Indicators that roll up

Each strategic indicator should be explained by management indicators, themselves calculated from operational measurements.

03

A decision tool

In front of the board, a security dashboard is there to obtain decisions: trends, risks in business terms and the decisions expected.

Frequently asked questions about security dashboards

What is a security dashboard?

A summary tool that brings together information security indicators to track how the security policy is applied and to support decisions. It usually has three levels: strategic for management, management level for the CISO and domain owners, and operational for technical teams.

Which cybersecurity KPIs should be presented to the board?

A few consolidated indicators tied to business stakes: coverage of major risks, exposure to critical vulnerabilities, progress of the security plan, awareness level, compliance with applicable frameworks, significant incidents. ANSSI's method recommends no more than six indicators at the strategic level.

What is the difference between management and operational indicators?

An operational indicator measures the state of a component or activity close to the ground (patched workstations, open vulnerabilities) and often acts as an alarm. A management indicator tracks the achievement of security objectives by domain (mean time to fix, plan progress) and helps the CISO direct action.

Has ANSSI published a guide on security dashboards?

Yes. The TDBSSI guide, written by DCSSI, ANSSI's predecessor, in a version dated 5 February 2004, describes a five-step method and three dashboard levels. It is still available for download on ANSSI's MesServicesCyber platform, which considers it relevant despite its age.

How often should a security dashboard be updated?

It depends on the level and audience: operational indicators can be tracked continuously or weekly, management indicators monthly, and the strategic dashboard at the pace of the executive or risk committee. ANSSI's method makes the reporting frequency a prerequisite to set from the start.

Do you need a tool to build a security dashboard?

You can start with a spreadsheet, but Clusif's guide recommends automating collection and updates with a database and a visualisation tool. A GRC platform calculates indicators directly from assessments, risks and action plans.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.