Courseiva
CISMChapter 8 of 17Objective 2.4

Risk Monitoring, Reporting, and Communication

Risk monitoring, reporting, and communication is the process of keeping a constant watch on all the risks an organisation faces and making sure the right people know about them in time to act. It matters for CISM because even the best risk assessment is useless if nobody ever checks whether risks have changed or if decision-makers are kept in the dark when a threat emerges.

12 min read
Intermediate
Updated Jul 24, 2026
Reviewed by Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security

A simple way to picture Risk Monitoring, Reporting, and Communication

The Home Security Camera System Analogy

A home security CCTV system is a continuous loop of recording, reviewing, and alerting.

The cameras constantly monitor every room and entry point — this is risk monitoring. They don't just record passively; they are configured to detect specific events: a window breaking, a door opening at 3 AM, or a person lingering in the driveway. Each event generates a log entry and a notification — this is reporting. The system sends alerts to your phone and a central monitoring station, where a human decides if the police should be called — this is communication.

Now, what happens when you deliberately leave a window cracked open on a hot night? The system flags that open window as a "risk" — not a threat yet, but a vulnerability. Your monitoring dashboard shows a red indicator for that zone. You receive a daily summary email listing open windows and unlocked doors. This is a risk register. You discuss with your family whether the risk of burglary through that window is acceptable, or whether you should close it — that is risk treatment. The whole system helps you decide, in real time, whether your home is safe enough, and what to do if it isn't.

How It Actually Works

After an organisation identifies its risks and decides how to treat them (avoid, accept, mitigate, or transfer), the work is far from over. Risks are not static — they change over time as technology evolves, as new employees join, as regulations shift, and as the business itself grows or contracts. Risk monitoring is the ongoing process of watching those risks to detect changes and ensure that the controls put in place are still working as intended.

Risk monitoring can be done in several ways. One common method is to use automated tools that scan systems continuously for vulnerabilities, unauthorised access attempts, or configuration drifts. Another is to conduct regular manual reviews, such as quarterly audits of access logs or annual assessments of physical security. Many organisations also rely on key risk indicators, or KRIs — specific metrics that act as early warning signals. For example, a KRI might be the number of failed login attempts in a day. If that number spikes, it might indicate a brute force attack in progress.

Reporting is the activity of turning the raw data from monitoring into information that decision-makers can understand and act on. A risk report might take the form of an executive dashboard showing top risks, a monthly risk register update for the board, or an incident report following a security event. The quality of reporting matters enormously — a poorly structured report can lead to missed signals or, worse, to decision-makers ignoring genuine threats because they are buried in noise.

Communication is the final piece: ensuring that the right information reaches the right people at the right time. This includes both formal channels — such as regular risk committee meetings, board reports, and regulatory filings — and informal ones, like a quick email or a call when a critical risk emerges. Communication also involves training employees to report suspicious activity and establishing a clear escalation path so that incidents don't languish unnoticed.

The three activities — monitoring, reporting, and communication — form a loop. Monitoring produces data, which is turned into reports, which are communicated to decision-makers, who may then adjust the risk strategy, which changes what needs to be monitored next. Without this loop, an organisation is flying blind. With it, it can adapt quickly to new threats and keep its risk profile within acceptable limits.

For a CISM candidate, the key is to understand that risk monitoring is not just a technical task. It is a governance responsibility. The CISM exam focuses on the management and oversight aspects: ensuring that monitoring is aligned with business objectives, that reporting is timely and accurate, and that communication reaches the right levels of authority — especially the board of directors and senior leadership, who are ultimately responsible for risk acceptance.

The continuous cycle of risk monitoring, reporting, and communication, showing how alerts flow from data collection through communication to action, looping back to monitoring.

Walk-Through

1

Define Key Risk Indicators (KRIs)

Identify the metrics that will serve as early warning signals for the organisation's top risks. For example, if data breach is a top risk, a KRI might be the number of unpatched critical vulnerabilities. Each KRI needs a threshold that triggers an alert when exceeded.

2

Set Up Monitoring Tools and Processes

Deploy automated tools (like vulnerability scanners or intrusion detection systems) to collect data on KRIs continuously. Also establish manual review processes for risks that cannot be measured automatically, such as employee compliance with security policies observed during spot checks.

3

Collect and Analyse Data

Gather the data from monitoring tools and human observations. Compare current KRI values against their thresholds. Identify patterns, trends, and anomalies — for example, a steady increase in failed logins over a week may indicate a coordinated attack.

4

Prepare and Distribute Risk Reports

Create reports tailored to different audiences. For the board, a high-level summary with a heat map of top risks. For IT operations, a detailed list of vulnerabilities and remediation steps. Ensure reports are timely, accurate, and clearly highlight what action is needed.

5

Communicate Findings and Escalate as Needed

Use the appropriate communication channel based on urgency. For critical risks (e.g., an active breach), escalate immediately via phone or secure messaging to the CISO and risk owner. For routine updates, use scheduled meetings or email summaries. Always document the communication for audit trails.

6

Update the Risk Register and Adjust Controls

After review, update the risk register with any changes in risk level, new risks discovered, or controls that need adjustment. The monitoring loop then continues with updated KRIs and thresholds, reflecting any decisions made by management.

7

Conduct Periodic Reviews and Audits

Regularly audit the monitoring and reporting process itself. Confirm that KRIs are still relevant, thresholds are appropriate, reports are reaching the right people, and communication channels are effective. Update the process as the business and threat landscape evolve.

What This Looks Like on the Job

Meet Priya, the Chief Information Security Officer (CISO) at a midsized retail company with 300 employees. The company stores customer payment information and runs an e-commerce platform. Priya's risk register currently lists 15 high-priority risks, including the risk of a data breach due to an outdated payment processing system.

Every day, Priya checks a dashboard that shows live data from the company's security tools. The dashboard displays: the number of phishing emails reported by employees, the count of failed login attempts, the patch status of all servers, and a colour-coded heat map of risk levels. This is real-time risk monitoring. This morning, she notices that the "patch completion" metric has dropped from 98% to 72% because the IT team delayed deploying critical updates due to a server migration. The dashboard flags this as a KRI breach.

Priya immediately pulls a report from the monitoring system that shows which servers are unpatched, how many days overdue each patch is, and which critical vulnerabilities remain exposed. She writes a one-page summary report for the monthly risk committee meeting, highlighting the patch gap and proposing a plan to accelerate the updates. But because this is urgent, she also sends a quick message to the Chief Information Officer (CIO) and the Head of IT Operations, asking for an emergency catch-up.

The risk committee meets that week. Priya presents the report, explaining the increased risk of exploitation and the potential cost of a breach (including regulatory fines under data protection law). The committee, comprising the CEO, CFO, and legal counsel, decides to approve overtime pay for the IT team to complete the updates over the weekend. Priya then communicates this decision to the IT team, who execute the patches. The dashboard reflects the fix within two days, and the KRI returns to green.

This scenario illustrates the full cycle: monitoring identified a deviation from the expected risk level, reporting turned that observation into actionable intelligence, communication ensured the right people knew about it and approved action, and the action fed back into monitoring to close the loop. Priya also ensures that a summary of this event is included in the quarterly board report, so the board understands how risks are managed and that leadership is responsive.

In practice, an IT professional like Priya spends time:

Defining which KRIs matter most for the business

Setting thresholds that trigger alerts (e.g., patch compliance below 90%)

Designing report templates that executives can digest quickly

Scheduling and facilitating risk review meetings

Maintaining an escalation path for critical incidents

Training staff on how to report security concerns

Auditing the monitoring systems themselves to confirm they work correctly

How CISM Actually Tests This

The CISM exam tests risk monitoring, reporting, and communication heavily, because it is the bridge between technical risk management and executive governance. Expect at least 10-15% of your exam questions to touch on these topics.

The most common question types are scenario-based. You will be given a description of an organisation (often with a specific industry or regulatory context) and asked what the best next step is in monitoring, what a report should include, or how communication should be handled. Traps often involve confusing monitoring with reporting, or choosing a technical solution when a governance or communication answer is correct.

Concepts that are tested repeatedly include:

Key Risk Indicators (KRIs) vs. Key Performance Indicators (KPIs): KRIs measure risk, KPIs measure performance. A question might describe a metric and ask you to identify which type it is.

The difference between risk monitoring, risk reporting, and risk communication: you must be able to distinguish each and know examples of each.

The relationship between the risk register and monitoring: the risk register is a living document that should be updated based on monitoring results.

The role of the board and senior management: they receive summary-level reports, not raw data. They are the ultimate owners of risk acceptance.

Escalation procedures: questions often ask who should be notified first after a critical risk is detected. The answer is usually the CISO or the risk owner, then the board if threshold is exceeded.

Automated vs. manual monitoring: automated is continuous and efficient, but manual reviews are still needed for qualitative assessments and to validate automated outputs.

Exam traps include:

Answer choices that propose overly technical solutions ("deploy a new SIEM") when the correct answer is about process or communication ("update the risk register and inform the board").

Answers that suggest monitoring eliminates risk — it does not. Monitoring identifies changes and alerts, but the risk remains until treated.

Confusing "risk appetite" with "risk tolerance". Risk appetite is the amount of risk the organisation is willing to accept overall; tolerance is the variation allowed around a specific risk. Monitoring reports should compare current risk levels to tolerance thresholds.

Remember: the exam is written from the perspective of a manager, not a technician. When in doubt, choose the answer that emphasises governance, oversight, and communication over hands-on technical work.

Key Takeaways

Risk monitoring is a continuous process, not a periodic project — it must be built into daily operations and revisited after every significant change.

A Key Risk Indicator (KRI) is a metric that signals whether a specific risk is approaching an unacceptable level, such as the percentage of unpatched critical systems.

Risk reports for senior management must summarise, prioritise, and focus on decision-relevant information — never overwhelm them with raw data.

Communication of risk must reach the right person at the right time, using the right channel — urgent risks may require an immediate phone call, not a weekly email.

The risk register is a living document that must be updated based on monitoring results, not archived after the initial assessment.

The board of directors has ultimate responsibility for risk acceptance and must receive regular, clear reports on the current risk posture and any significant changes.

Automation supports monitoring but does not replace human judgement — automated alerts must be reviewed, tuned, and validated regularly.

Escalation procedures define who needs to be notified when a risk breaches a threshold — a critical risk may require immediate notification of the CISO and the board.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Key Risk Indicator (KRI)

Measures the level of a specific risk

Used as an early warning signal for potential problems

Example: number of unpatched critical vulnerabilities

Key Performance Indicator (KPI)

Measures the performance of a process or activity

Used to track efficiency or effectiveness

Example: average time to deploy a patch

Risk Monitoring

Continuous, ongoing process

Focused on real-time detection of changes

Owned by operational management

Risk Auditing

Periodic, point-in-time assessment

Focused on verifying compliance with policies

Conducted by internal or external audit teams

Formal Risk Communication

Structured, documented channels

Examples: board reports, risk committee meetings

Used for routine reporting and governance

Informal Risk Communication

Ad-hoc, less structured channels

Examples: instant messages, hallway conversations

Used for urgent or time-critical updates

Risk Tolerance

Specific acceptable variation around a single risk

Defined as a threshold (e.g., up to 5% downtime)

Used to set KRIs and alert triggers

Risk Appetite

Overall amount of risk the organisation is willing to accept

Broad strategic statement (e.g., 'low risk appetite')

Guides high-level risk management decisions

Watch Out for These

Mistake

Once a risk assessment is done, monitoring is just about checking boxes to satisfy auditors.

Correct

Monitoring is an ongoing, dynamic process that detects changes in the risk environment and verifies that controls remain effective over time, not a one-time compliance exercise.

Beginners often think risk management is a project with an end date, not a continuous cycle. They focus on the assessment phase because that feels concrete, and overlook the fact that risks evolve constantly.

Mistake

Risk reporting means sending every security alert to senior management so they know everything.

Correct

Reporting to senior management should be summarised and focused on decision-relevant information — raw alerts overwhelm and obscure real threats.

People assume more information is always better. In reality, senior leaders need concise, prioritised reports that highlight what requires their attention, not a firehose of data.

Mistake

Risk communication only happens through formal reports and meetings.

Correct

Effective risk communication includes informal methods like instant messages, phone calls, and hallway conversations, especially for time-critical risks, and also includes training staff to report concerns.

Beginners often equate communication with formal documentation. They miss the fact that speed and relationships matter — formal channels can be too slow for urgent risks.

Mistake

Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) are the same thing with different names.

Correct

KRIs measure potential negative events (e.g., number of failed logins), while KPIs measure how well processes are operating (e.g., average system uptime). They serve different purposes in monitoring.

The acronyms sound similar, and many real-world dashboards mix them up. Beginners often assume any metric is a KRI if it is tracked for security purposes.

Mistake

If monitoring tools are automated, you can set them and forget them.

Correct

Automated tools require regular tuning, review, and validation — false positives can flood the system, and controls degrade over time if not maintained.

The word 'automated' gives a false sense of permanence. Beginners think automation replaces human attention, but in practice, someone must calibrate thresholds, handle exceptions, and confirm the tool is still fit for purpose.

Mistake

The board of directors only cares about financial risks, so you should only report financial impacts of security risks.

Correct

The board cares about all strategic risks that could affect the organisation's objectives, including reputational, operational, and regulatory risks, not just financial ones.

This misconception stems from the stereotype that boards only look at budgets. In reality, boards have broad fiduciary duties and need a holistic risk picture, and exam questions reflect that.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between risk monitoring and risk reporting?

Risk monitoring is the process of continuously watching risks and controls to detect changes. Risk reporting is the activity of turning the data from monitoring into structured information for decision-makers. Monitoring generates data; reporting communicates it.

How often should risk reports be sent to the board?

Typically quarterly, but the frequency should be defined by the organisation's risk governance policy. For critical changes or incidents, an immediate ad-hoc report may be necessary. The key is that the board is never surprised by a risk they were not told about.

What is a Key Risk Indicator (KRI) and how is it different from a KPI?

A KRI is a metric that signals the level of a specific risk, such as the percentage of systems without the latest security patches. A KPI measures the performance of a process, like average time to patch. KRIs warn of potential problems; KPIs measure how well things are running.

Who is responsible for risk monitoring in an organisation?

Ultimately, the board and senior management are responsible for oversight. The CISO or risk management function typically owns the operational monitoring process. However, every employee has a role in reporting risks they encounter, as part of the organisation's overall communication policy.

What should be included in a risk report to senior management?

A summary of the current top risks (with heat maps or colour coding), trends over time, any breaches of risk tolerance thresholds, updates on risk treatment actions, and a clear statement of what decision or action is needed from them. Keep it concise and decision-focused.

How do I know if a risk needs to be communicated urgently?

Use predefined escalation thresholds from the risk policy. If a risk exceeds the organisation's defined tolerance (e.g., a critical vulnerability without a patch), it should be communicated immediately to the risk owner and CISO. Any risk that could cause significant harm or legal liability is urgent.

Can automated monitoring replace human review?

No. Automation is excellent for collecting data and detecting known patterns, but humans are needed to interpret context, identify false positives, assess novel threats, and make judgement calls about whether a risk is truly critical. The two are complementary.

Terms Worth Knowing

Keep going

You've finished Risk Monitoring, Reporting, and Communication. Continue through the CISM study guide to build a complete picture of the exam.

Done with this chapter?