Continuous risk monitoring
Know your risk posture every month — not just once a year.
Controls drift. People change roles, vendors change hands, new systems appear, and patches slip. Our monitoring plan catches that drift early and turns it into a short, prioritized list of actions.
Monthly
Control health checks and KRI dashboard
Quarterly
Risk register review and executive report
Annually
Full risk assessment, policy review, and program plan
What we watch
Six monitoring domains, one view of risk.
Identity & access
- Joiner / mover / leaver timeliness
- Privileged account inventory and reviews
- MFA coverage across critical systems
Vulnerabilities & patching
- Open critical and high findings by age
- Patch SLA adherence
- External attack surface changes
Change & configuration
- Changes with approval and testing evidence
- Configuration drift from hardened baselines
- Unmanaged or unknown assets
Vendors & third parties
- Critical vendor reviews completed on schedule
- Expiring SOC reports, BAAs, and contracts
- New vendors onboarded without review
Detection & response
- Log source coverage and alert triage times
- Incidents, near-misses, and lessons learned
- Backup and restore test results
People & governance
- Security awareness completion and phishing results
- Policy acknowledgments and exceptions
- Open audit findings and corrective actions
The monitoring plan
A predictable cadence your leadership can count on.
| Cadence | Activities | Output | Audience |
|---|---|---|---|
| Continuous | Automated evidence collection and alerting where your tooling allows; triage of significant changes and incidents | Issue log with owners and due dates | Control owners |
| Monthly | Control health checks across the six domains; KRI refresh; follow-up on open actions | Control health dashboard (green / amber / red) | IT & security leads |
| Quarterly | Risk register review; new and emerging risks; vendor tier review; access review oversight | Executive risk report with trends and decisions needed | Leadership team |
| Semi-annual | Incident response tabletop; backup restore validation; policy exception review | Exercise report and improvement plan | Leadership & responders |
| Annual | Full risk assessment; policy and procedure review; maturity scoring; next-year program plan and budget input | Annual program report and roadmap | Executives & board |
Key risk indicators
Metrics that tell a story leadership understands.
We agree on a small set of KRIs with thresholds up front, so a red light always means the same thing and always comes with a recommended action.
Exposure
Critical vulnerabilities open past SLA; internet-facing assets without an owner.
Access
Terminated users with active access; privileged accounts not reviewed this quarter.
Resilience
Days since last successful restore test; critical systems without tested recovery.
Assurance
Controls failing monthly checks; audit findings past their corrective-action date.
Already certified and want to stay that way?
Our Sentinel plan wraps this entire monitoring program together with ongoing vCISO leadership.