Risk monitoring, reporting, and communication is the process of keeping a constant watch on all the risks an organisation faces and making sure the right people know about them in time to act. It matters for CISM because even the best risk assessment is useless if nobody ever checks whether risks have changed or if decision-makers are kept in the dark when a threat emerges.
Jump to a section
A simple way to picture Risk Monitoring, Reporting, and Communication
A home security CCTV system is a continuous loop of recording, reviewing, and alerting.
The cameras constantly monitor every room and entry point — this is risk monitoring. They don't just record passively; they are configured to detect specific events: a window breaking, a door opening at 3 AM, or a person lingering in the driveway. Each event generates a log entry and a notification — this is reporting. The system sends alerts to your phone and a central monitoring station, where a human decides if the police should be called — this is communication.
Now, what happens when you deliberately leave a window cracked open on a hot night? The system flags that open window as a "risk" — not a threat yet, but a vulnerability. Your monitoring dashboard shows a red indicator for that zone. You receive a daily summary email listing open windows and unlocked doors. This is a risk register. You discuss with your family whether the risk of burglary through that window is acceptable, or whether you should close it — that is risk treatment. The whole system helps you decide, in real time, whether your home is safe enough, and what to do if it isn't.
After an organisation identifies its risks and decides how to treat them (avoid, accept, mitigate, or transfer), the work is far from over. Risks are not static — they change over time as technology evolves, as new employees join, as regulations shift, and as the business itself grows or contracts. Risk monitoring is the ongoing process of watching those risks to detect changes and ensure that the controls put in place are still working as intended.
Risk monitoring can be done in several ways. One common method is to use automated tools that scan systems continuously for vulnerabilities, unauthorised access attempts, or configuration drifts. Another is to conduct regular manual reviews, such as quarterly audits of access logs or annual assessments of physical security. Many organisations also rely on key risk indicators, or KRIs — specific metrics that act as early warning signals. For example, a KRI might be the number of failed login attempts in a day. If that number spikes, it might indicate a brute force attack in progress.
Reporting is the activity of turning the raw data from monitoring into information that decision-makers can understand and act on. A risk report might take the form of an executive dashboard showing top risks, a monthly risk register update for the board, or an incident report following a security event. The quality of reporting matters enormously — a poorly structured report can lead to missed signals or, worse, to decision-makers ignoring genuine threats because they are buried in noise.
Communication is the final piece: ensuring that the right information reaches the right people at the right time. This includes both formal channels — such as regular risk committee meetings, board reports, and regulatory filings — and informal ones, like a quick email or a call when a critical risk emerges. Communication also involves training employees to report suspicious activity and establishing a clear escalation path so that incidents don't languish unnoticed.
The three activities — monitoring, reporting, and communication — form a loop. Monitoring produces data, which is turned into reports, which are communicated to decision-makers, who may then adjust the risk strategy, which changes what needs to be monitored next. Without this loop, an organisation is flying blind. With it, it can adapt quickly to new threats and keep its risk profile within acceptable limits.
For a CISM candidate, the key is to understand that risk monitoring is not just a technical task. It is a governance responsibility. The CISM exam focuses on the management and oversight aspects: ensuring that monitoring is aligned with business objectives, that reporting is timely and accurate, and that communication reaches the right levels of authority — especially the board of directors and senior leadership, who are ultimately responsible for risk acceptance.
Define Key Risk Indicators (KRIs)
Identify the metrics that will serve as early warning signals for the organisation's top risks. For example, if data breach is a top risk, a KRI might be the number of unpatched critical vulnerabilities. Each KRI needs a threshold that triggers an alert when exceeded.
Set Up Monitoring Tools and Processes
Deploy automated tools (like vulnerability scanners or intrusion detection systems) to collect data on KRIs continuously. Also establish manual review processes for risks that cannot be measured automatically, such as employee compliance with security policies observed during spot checks.
Collect and Analyse Data
Gather the data from monitoring tools and human observations. Compare current KRI values against their thresholds. Identify patterns, trends, and anomalies — for example, a steady increase in failed logins over a week may indicate a coordinated attack.
Prepare and Distribute Risk Reports
Create reports tailored to different audiences. For the board, a high-level summary with a heat map of top risks. For IT operations, a detailed list of vulnerabilities and remediation steps. Ensure reports are timely, accurate, and clearly highlight what action is needed.
Communicate Findings and Escalate as Needed
Use the appropriate communication channel based on urgency. For critical risks (e.g., an active breach), escalate immediately via phone or secure messaging to the CISO and risk owner. For routine updates, use scheduled meetings or email summaries. Always document the communication for audit trails.
Update the Risk Register and Adjust Controls
After review, update the risk register with any changes in risk level, new risks discovered, or controls that need adjustment. The monitoring loop then continues with updated KRIs and thresholds, reflecting any decisions made by management.
Conduct Periodic Reviews and Audits
Regularly audit the monitoring and reporting process itself. Confirm that KRIs are still relevant, thresholds are appropriate, reports are reaching the right people, and communication channels are effective. Update the process as the business and threat landscape evolve.
Meet Priya, the Chief Information Security Officer (CISO) at a midsized retail company with 300 employees. The company stores customer payment information and runs an e-commerce platform. Priya's risk register currently lists 15 high-priority risks, including the risk of a data breach due to an outdated payment processing system.
Every day, Priya checks a dashboard that shows live data from the company's security tools. The dashboard displays: the number of phishing emails reported by employees, the count of failed login attempts, the patch status of all servers, and a colour-coded heat map of risk levels. This is real-time risk monitoring. This morning, she notices that the "patch completion" metric has dropped from 98% to 72% because the IT team delayed deploying critical updates due to a server migration. The dashboard flags this as a KRI breach.
Priya immediately pulls a report from the monitoring system that shows which servers are unpatched, how many days overdue each patch is, and which critical vulnerabilities remain exposed. She writes a one-page summary report for the monthly risk committee meeting, highlighting the patch gap and proposing a plan to accelerate the updates. But because this is urgent, she also sends a quick message to the Chief Information Officer (CIO) and the Head of IT Operations, asking for an emergency catch-up.
The risk committee meets that week. Priya presents the report, explaining the increased risk of exploitation and the potential cost of a breach (including regulatory fines under data protection law). The committee, comprising the CEO, CFO, and legal counsel, decides to approve overtime pay for the IT team to complete the updates over the weekend. Priya then communicates this decision to the IT team, who execute the patches. The dashboard reflects the fix within two days, and the KRI returns to green.
This scenario illustrates the full cycle: monitoring identified a deviation from the expected risk level, reporting turned that observation into actionable intelligence, communication ensured the right people knew about it and approved action, and the action fed back into monitoring to close the loop. Priya also ensures that a summary of this event is included in the quarterly board report, so the board understands how risks are managed and that leadership is responsive.
In practice, an IT professional like Priya spends time:
Defining which KRIs matter most for the business
Setting thresholds that trigger alerts (e.g., patch compliance below 90%)
Designing report templates that executives can digest quickly
Scheduling and facilitating risk review meetings
Maintaining an escalation path for critical incidents
Training staff on how to report security concerns
Auditing the monitoring systems themselves to confirm they work correctly
The CISM exam tests risk monitoring, reporting, and communication heavily, because it is the bridge between technical risk management and executive governance. Expect at least 10-15% of your exam questions to touch on these topics.
The most common question types are scenario-based. You will be given a description of an organisation (often with a specific industry or regulatory context) and asked what the best next step is in monitoring, what a report should include, or how communication should be handled. Traps often involve confusing monitoring with reporting, or choosing a technical solution when a governance or communication answer is correct.
Concepts that are tested repeatedly include:
Key Risk Indicators (KRIs) vs. Key Performance Indicators (KPIs): KRIs measure risk, KPIs measure performance. A question might describe a metric and ask you to identify which type it is.
The difference between risk monitoring, risk reporting, and risk communication: you must be able to distinguish each and know examples of each.
The relationship between the risk register and monitoring: the risk register is a living document that should be updated based on monitoring results.
The role of the board and senior management: they receive summary-level reports, not raw data. They are the ultimate owners of risk acceptance.
Escalation procedures: questions often ask who should be notified first after a critical risk is detected. The answer is usually the CISO or the risk owner, then the board if threshold is exceeded.
Automated vs. manual monitoring: automated is continuous and efficient, but manual reviews are still needed for qualitative assessments and to validate automated outputs.
Exam traps include:
Answer choices that propose overly technical solutions ("deploy a new SIEM") when the correct answer is about process or communication ("update the risk register and inform the board").
Answers that suggest monitoring eliminates risk — it does not. Monitoring identifies changes and alerts, but the risk remains until treated.
Confusing "risk appetite" with "risk tolerance". Risk appetite is the amount of risk the organisation is willing to accept overall; tolerance is the variation allowed around a specific risk. Monitoring reports should compare current risk levels to tolerance thresholds.
Remember: the exam is written from the perspective of a manager, not a technician. When in doubt, choose the answer that emphasises governance, oversight, and communication over hands-on technical work.
Risk monitoring is a continuous process, not a periodic project — it must be built into daily operations and revisited after every significant change.
A Key Risk Indicator (KRI) is a metric that signals whether a specific risk is approaching an unacceptable level, such as the percentage of unpatched critical systems.
Risk reports for senior management must summarise, prioritise, and focus on decision-relevant information — never overwhelm them with raw data.
Communication of risk must reach the right person at the right time, using the right channel — urgent risks may require an immediate phone call, not a weekly email.
The risk register is a living document that must be updated based on monitoring results, not archived after the initial assessment.
The board of directors has ultimate responsibility for risk acceptance and must receive regular, clear reports on the current risk posture and any significant changes.
Automation supports monitoring but does not replace human judgement — automated alerts must be reviewed, tuned, and validated regularly.
Escalation procedures define who needs to be notified when a risk breaches a threshold — a critical risk may require immediate notification of the CISO and the board.
These come up on the exam all the time. Here's how to tell them apart.
Key Risk Indicator (KRI)
Measures the level of a specific risk
Used as an early warning signal for potential problems
Example: number of unpatched critical vulnerabilities
Key Performance Indicator (KPI)
Measures the performance of a process or activity
Used to track efficiency or effectiveness
Example: average time to deploy a patch
Risk Monitoring
Continuous, ongoing process
Focused on real-time detection of changes
Owned by operational management
Risk Auditing
Periodic, point-in-time assessment
Focused on verifying compliance with policies
Conducted by internal or external audit teams
Formal Risk Communication
Structured, documented channels
Examples: board reports, risk committee meetings
Used for routine reporting and governance
Informal Risk Communication
Ad-hoc, less structured channels
Examples: instant messages, hallway conversations
Used for urgent or time-critical updates
Risk Tolerance
Specific acceptable variation around a single risk
Defined as a threshold (e.g., up to 5% downtime)
Used to set KRIs and alert triggers
Risk Appetite
Overall amount of risk the organisation is willing to accept
Broad strategic statement (e.g., 'low risk appetite')
Guides high-level risk management decisions
Mistake
Once a risk assessment is done, monitoring is just about checking boxes to satisfy auditors.
Correct
Monitoring is an ongoing, dynamic process that detects changes in the risk environment and verifies that controls remain effective over time, not a one-time compliance exercise.
Beginners often think risk management is a project with an end date, not a continuous cycle. They focus on the assessment phase because that feels concrete, and overlook the fact that risks evolve constantly.
Mistake
Risk reporting means sending every security alert to senior management so they know everything.
Correct
Reporting to senior management should be summarised and focused on decision-relevant information — raw alerts overwhelm and obscure real threats.
People assume more information is always better. In reality, senior leaders need concise, prioritised reports that highlight what requires their attention, not a firehose of data.
Mistake
Risk communication only happens through formal reports and meetings.
Correct
Effective risk communication includes informal methods like instant messages, phone calls, and hallway conversations, especially for time-critical risks, and also includes training staff to report concerns.
Beginners often equate communication with formal documentation. They miss the fact that speed and relationships matter — formal channels can be too slow for urgent risks.
Mistake
Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) are the same thing with different names.
Correct
KRIs measure potential negative events (e.g., number of failed logins), while KPIs measure how well processes are operating (e.g., average system uptime). They serve different purposes in monitoring.
The acronyms sound similar, and many real-world dashboards mix them up. Beginners often assume any metric is a KRI if it is tracked for security purposes.
Mistake
If monitoring tools are automated, you can set them and forget them.
Correct
Automated tools require regular tuning, review, and validation — false positives can flood the system, and controls degrade over time if not maintained.
The word 'automated' gives a false sense of permanence. Beginners think automation replaces human attention, but in practice, someone must calibrate thresholds, handle exceptions, and confirm the tool is still fit for purpose.
Mistake
The board of directors only cares about financial risks, so you should only report financial impacts of security risks.
Correct
The board cares about all strategic risks that could affect the organisation's objectives, including reputational, operational, and regulatory risks, not just financial ones.
This misconception stems from the stereotype that boards only look at budgets. In reality, boards have broad fiduciary duties and need a holistic risk picture, and exam questions reflect that.
Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.
Risk monitoring is the process of continuously watching risks and controls to detect changes. Risk reporting is the activity of turning the data from monitoring into structured information for decision-makers. Monitoring generates data; reporting communicates it.
Typically quarterly, but the frequency should be defined by the organisation's risk governance policy. For critical changes or incidents, an immediate ad-hoc report may be necessary. The key is that the board is never surprised by a risk they were not told about.
A KRI is a metric that signals the level of a specific risk, such as the percentage of systems without the latest security patches. A KPI measures the performance of a process, like average time to patch. KRIs warn of potential problems; KPIs measure how well things are running.
Ultimately, the board and senior management are responsible for oversight. The CISO or risk management function typically owns the operational monitoring process. However, every employee has a role in reporting risks they encounter, as part of the organisation's overall communication policy.
A summary of the current top risks (with heat maps or colour coding), trends over time, any breaches of risk tolerance thresholds, updates on risk treatment actions, and a clear statement of what decision or action is needed from them. Keep it concise and decision-focused.
Use predefined escalation thresholds from the risk policy. If a risk exceeds the organisation's defined tolerance (e.g., a critical vulnerability without a patch), it should be communicated immediately to the risk owner and CISO. Any risk that could cause significant harm or legal liability is urgent.
No. Automation is excellent for collecting data and detecting known patterns, but humans are needed to interpret context, identify false positives, assess novel threats, and make judgement calls about whether a risk is truly critical. The two are complementary.
You've finished Risk Monitoring, Reporting, and Communication. Continue through the CISM study guide to build a complete picture of the exam.
Done with this chapter?