What separates a KRI from a metric
A metric becomes a KRI when three things are true: it is tied to a named risk in the register, it has a threshold that means something (amber, red) rather than a trend nobody interprets, and someone owns the response when the threshold is crossed. A dashboard with forty security metrics and no thresholds is reporting; six KRIs with thresholds and owners are governance. The number of indicators matters less than the fact that each one changes a decision.
Examples that hold up
Median time to patch critical vulnerabilities on internet-facing assets, against a threshold in days. Percentage of critical suppliers without a valid assessment. Number of security exceptions past their expiry. Share of controls whose evidence is older than its cadence. Incidents open beyond the reporting deadline of the applicable regulation. Each is computable from data the organization already holds, which is the difference between a KRI that is measured monthly and one that is estimated in a meeting.
From the KRI to the board
The board does not read forty indicators either. The board pack carries the handful of KRIs tied to the top risks, each with its threshold, its trend and the decision pending when it breached. Presented that way, the indicator is not a technical curiosity but the answer to the question directors are now asked under NIS2 and DORA: did you know the risk was moving, and what did you decide?