Security Metrics for Banks
One Guy’s Perspective: I’m moderately new to the banking industry, but I’ve been working with KPIs, CPIs, metrics, and stats across a wide variety of industries for my entire career. When I wrote my two books on metrics, I intentionally avoided focusing on any one industry.
But to support my banking peers now that I’m on the “inside,” I thought I’d offer a Top 25 pulled from a variety of chapters in my books — metrics that are practical for the bank’s leadership, Bank Security Officer (BSO), and Information Security Officer (ISO).
If you’ve heard me speak on this topic, you know my K.I.S.S. method for a converged security program starts with simple pie charts and colors — “Red is Bad, Green is Good.” So I hope these maturity metrics challenge (and maybe scare) the Board of Directors (BoD), senior leadership, and BSO/ISO leadership.
Again, this is a perspective — far from the only or “best” set of metrics — but if you’re struggling with where to start, start here. But Rule #1: “Make sure the audience is ready for the results.”
— Jim
Top 25 Security Metrics for Banks
| # | The Metric | Best Score |
|---|---|---|
| 1 | Percentage of our organization’s technology assets that will be EOL/EOS by end of the fiscal year | 0% |
| 2 | Percentage of our organization’s buildings that have vulnerabilities that cannot be mitigated by end of the fiscal year | 0% |
| 3 | Percentage of our organization’s suppliers that have contractual non-compliance that will not be mitigated by end of the fiscal year | 0% |
| 4 | Percentage of technology assets (in-house, outsources, cloud, SaaS) that the Bank Security Officer (BSO) and Information Security Officer (ISO) has verified, meet or exceed FFIEC controls guidance | 100% |
| 5 | Percentage of security incidents, regardless of size and type, that have been reported to the IRC/DRC/BoD each quarter | 100% |
| 6 | Percentage of IRC/DRC/BoD members that have been involved in at least one TTX this year | 100% |
| 7 | Percentage of fraud (internal and customer impacting) losses, regardless of size and type, which have been reported to the IRC/DRC/BoD each quarter | 100% |
| 8 | Percentage of locations (branches, non-branch, suppliers) that has been verified by the BSO as having met the Bank Protection Act (BPA) Requirements | 100% |
| 9 | Percentage of supply chain (prime and subs), regardless of whether there is a contract, has been through a business risk, corruption, and financial due diligence within the last year. | 100% |
| 10 | Percentage of Board members that have a document explaining all the security (physical, personnel, cyber, etc.) protecting them that is managed by the Bank | 100% |
| 11 | Percentage of BoD reportable audits/exams that checked for data integrity issues | 100% |
| 12 | Percentage of technology vulnerabilities discovered in the last 90 days, that have not been mitigated | 0% |
| 13 | Percentage of major projects where the BSO and ISO are part of the regular project calls | 100% |
| 14 | Percentage of security spend that is tracked separately from other operational capital and expenses | 100% |
| 15 | Percentage of information/cyber security TTX that have engaged our cyber insurance program | 100% |
| 16 | Percentage of employees and suppliers with access to Bank data that have been through at least 4 phishing texts in the last 12 months | 100% |
| 17 | Percentage of cameras with at least 90 days of verifiable video recordings | 100% |
| 18 | Percentage of important internal systems that have had their backup restored to check for backup integrity issues, in last 12 months | 100% |
| 19 | Percentage of audit and investigations after-action findings that have an assigned owner and funding | 100% |
| 20 | Percentage of employees that have been through face-to-face robbery, bomb threat, evacuation and shelter-in-place training in the last year | 100% |
| 21 | Percentage of BoD meetings that include facility “bug sweeps” and security checks before meeting | 100% |
| 22 | Percentage of locations (not just branches) with OSHA First Aid, Stop the Bleed®, and AED capabilities | 100% |
| 23 | Percentage of locations (not just branches) that have been through an external and insider penetration test, covering converged security threats | 100% |
| 24 | Percentage of C-Suite that has reviewed the results of this year’s CRI and R-SAT assessments | 100% |
| 25 | Percentage of BoD primary employer’s security teams that have met with our organization’s security team in last 12 months | 100% |
| Extra Credit | Percentage of meeting resorts/event locations/golf courses/etc., used for external Bank sponsored meetings/retreats, that have been pre-meeting audited for security vulnerabilities and threats | 100% |
← Return to the Bank Security Resources Library
🖶 To save or print this document, use your browser’s Print function (Ctrl+P / Cmd+P) and select “Save as PDF” if needed.
