Effective risk management depends on clear, consistent reporting to keep stakeholders informed about identified risks, mitigation plans, and outcomes. This content covers the key phases of risk reporting, common audiences, delivery methods, and the role of KPIs, KRIs, and trend analysis in communicating organizational risk health.
Risk Reporting
One of the key elements to success is communication. There's going to be a lot of people that are going to want to know what you're doing, what risks you're finding, and what you're doing about them, and one of the ways we can do that is through reporting.
Reporting can happen pretty much any time within this process. However, I do find that there's a few key parts where we probably want to do some reporting, or are required to do some reporting.
For one, when we go through the identification and analysis phase, we're going to end up with a report. A lot of that comes in with something like a risk assessment: when we do a risk assessment, we're going to end up with a report. We're going to want to communicate that report so people understand what our risks are and what we're doing about them, or what we're going to do about them, or at least prep them with the fact that we're going to have to do something about them.
Then we're going to go through the prioritization and planning phase. We're going to start prioritizing and planning these solutions to mitigate these risks, and once again there's going to be others that are probably going to want to know what's going on — specifically because now we're going to get some cost involved in this, and probably have to get some permission to be able to put some resources towards mitigating some of these risks.
Then another thing we'll see is mitigation and monitoring, where we're going to actually put our controls into place and then monitor to see how effective they were. Then we're going to want to report on what we accomplished, and assess what we accomplished, and make sure that we were doing everything to really mitigate these issues — or do we need to go back and start doing other things to mitigate these issues?
Then the question might come up: who are these reports for, who is going to be seeing these reports? I can tell you there are a lot of people within the company that might have an interest in these reports. I was always kind of amazed, when I sent out these types of reports, who would want to be a part of that. So it really could be anybody in the company, but for a large degree it could be things like the board of directors, maybe even the owners and shareholders of the company. Certainly I try to include those who are in higher levels of leadership within the company. Or maybe you have a security team and you're reporting it to the security team. And then sometimes, like I say, it could be other areas of the company as well.
But it doesn't have to be just inside the company — it could be to entities outside the company. I've had a lot of clients that ask for specific reports around risk, and I've had to give them risk reports. I've also had partners and vendors that have asked for it. Maybe not quite as many vendors; really we're probably going to be asking those vendors for some reports before we do business with them. But certainly I've also asked for reports, and also have been asked for reports from partners.
There's various delivery methods that can happen as well. I've had delivery methods where I've actually created documents and turned over documents. For instance, the risk assessment I've always turned into a document, so that way we could hand it out to lots of different types of people in different forms. For instance, maybe I'll send it to them through email. Or I've had emails where I've had to compile, on a weekly basis, risk reports and other types of reports, and put it into an email and send it off.
There's also things like dashboards. A dashboard is a single pane where you can go in — a lot of times it's electronic — where you can go in there and see what's happening on all of your systems, and you'll be able to track and monitor all your systems. We can do that from a risk perspective as well.
One question is, how often do these happen? For instance, the risk assessment, I would do those once a year, so then I would compile a report from that perspective. So there is the actual report, and then there's also things like I would have to assemble what they called dashboards, and I put dashboards and copied and pasted a bunch of information in emails and sent that out, and that was on a weekly basis. So it was on a recurring basis. And then also occasionally they would do an ad hoc, where they'd request it.
Now, dashboards are typically done on a computer and are live, so that's ongoing. This is a good example of a dashboard: a typical dashboard, where you have all sorts of charts and graphs and information that's being displayed, and then you can go and view this at any point in time. So dashboards are great to track things live. They just called it a dashboard when I sent it through email, but it wasn't, I would say, a typical dashboard.
Things that we might want to include in these types of reports are risks, risk assessments, key performance indicators or KPIs, key risk indicators or KRIs, risk trend analysis, and risk event reports. So these are some of the things we would include.
One thing that can be really handy is tracking things like KPIs or KRIs and trend analysis. Trend analysis takes all of the data points that you have and creates trends off of those. Now, some trends are great, like uptime — we want uptime to go up — or customer satisfaction, we want that to go up. But if our downtime is going up, or if there are other key risk indicators that are going up, then this is a concern. So these are great ways to identify the health and what's going on with the company, and with our infrastructure, and with risk.
Key performance indicators are different numbered values. There's some sort of value that we can measure that we track over time, and it lets us know the health of things. It allows us to see these trend lines. So key performance indicators are things that we're going to choose, and a great example of this might be something like uptime, or ticket completion, or customer satisfaction, or NPS scores — different things that we want to see improve over a period of time. So the KPI is going to track, once again, the health of our systems and of our company.
A very similar idea is these key risk indicators, or KRIs. Same type of thing: we want to track the health of the company, but we do it from a perspective of risk. So we identify different measurements that might indicate the risk is going up — things like maybe the incident count, or project delay percentage, or downtime, or compliance, or disaster preparedness, maybe a credit score or loan delinquencies.
Ultimately, a lot of the details around reports — what they look like and who they're going to — really depends on the situation. You're going to have to analyze when and where and how and why and who is all going to get access to these different reports. So really it's going to be highly adapted to your environment.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →