Security Metrics for Banks

Security Metrics for Banks

One Guy’s Perspective: I’m moderately new to the banking industry, but I’ve been working with KPIs, CPIs, metrics, and stats across a wide variety of industries for my entire career. When I wrote my two books on metrics, I intentionally avoided focusing on any one industry.

But to support my banking peers now that I’m on the “inside,” I thought I’d offer a Top 25 pulled from a variety of chapters in my books — metrics that are practical for the bank’s leadership, Bank Security Officer (BSO), and Information Security Officer (ISO).

If you’ve heard me speak on this topic, you know my K.I.S.S. method for a converged security program starts with simple pie charts and colors — “Red is Bad, Green is Good.” So I hope these maturity metrics challenge (and maybe scare) the Board of Directors (BoD), senior leadership, and BSO/ISO leadership.

Again, this is a perspective — far from the only or “best” set of metrics — but if you’re struggling with where to start, start here. But Rule #1: “Make sure the audience is ready for the results.”

— Jim

Top 25 Security Metrics for Banks

#The MetricBest Score
1Percentage of our organization’s technology assets that will be EOL/EOS by end of the fiscal year0%
2Percentage of our organization’s buildings that have vulnerabilities that cannot be mitigated by end of the fiscal year0%
3Percentage of our organization’s suppliers that have contractual non-compliance that will not be mitigated by end of the fiscal year0%
4Percentage of technology assets (in-house, outsources, cloud, SaaS) that the Bank Security Officer (BSO) and Information Security Officer (ISO) has verified, meet or exceed FFIEC controls guidance100%
5Percentage of security incidents, regardless of size and type, that have been reported to the IRC/DRC/BoD each quarter100%
6Percentage of IRC/DRC/BoD members that have been involved in at least one TTX this year100%
7Percentage of fraud (internal and customer impacting) losses, regardless of size and type, which have been reported to the IRC/DRC/BoD each quarter100%
8Percentage of locations (branches, non-branch, suppliers) that has been verified by the BSO as having met the Bank Protection Act (BPA) Requirements100%
9Percentage of supply chain (prime and subs), regardless of whether there is a contract, has been through a business risk, corruption, and financial due diligence within the last year.100%
10Percentage of Board members that have a document explaining all the security (physical, personnel, cyber, etc.) protecting them that is managed by the Bank100%
11Percentage of BoD reportable audits/exams that checked for data integrity issues100%
12Percentage of technology vulnerabilities discovered in the last 90 days, that have not been mitigated0%
13Percentage of major projects where the BSO and ISO are part of the regular project calls100%
14Percentage of security spend that is tracked separately from other operational capital and expenses100%
15Percentage of information/cyber security TTX that have engaged our cyber insurance program100%
16Percentage of employees and suppliers with access to Bank data that have been through at least 4 phishing texts in the last 12 months100%
17Percentage of cameras with at least 90 days of verifiable video recordings100%
18Percentage of important internal systems that have had their backup restored to check for backup integrity issues, in last 12 months100%
19Percentage of audit and investigations after-action findings that have an assigned owner and funding100%
20Percentage of employees that have been through face-to-face robbery, bomb threat, evacuation and shelter-in-place training in the last year100%
21Percentage of BoD meetings that include facility “bug sweeps” and security checks before meeting100%
22Percentage of locations (not just branches) with OSHA First Aid, Stop the Bleed®, and AED capabilities100%
23Percentage of locations (not just branches) that have been through an external and insider penetration test, covering converged security threats100%
24Percentage of C-Suite that has reviewed the results of this year’s CRI and R-SAT assessments100%
25Percentage of BoD primary employer’s security teams that have met with our organization’s security team in last 12 months100%
Extra CreditPercentage of meeting resorts/event locations/golf courses/etc., used for external Bank sponsored meetings/retreats, that have been pre-meeting audited for security vulnerabilities and threats100%

← Return to the Bank Security Resources Library


🖶 To save or print this document, use your browser’s Print function (Ctrl+P / Cmd+P) and select “Save as PDF” if needed.