Risk Monitoring

A continuous monitoring plan that keeps your program current and your leadership informed.

Continuous risk monitoring

Know your risk posture every month — not just once a year.

Controls drift. People change roles, vendors change hands, new systems appear, and patches slip. Our monitoring plan catches that drift early and turns it into a short, prioritized list of actions.

Monthly

Control health checks and KRI dashboard

Quarterly

Risk register review and executive report

Annually

Full risk assessment, policy review, and program plan

What we watch

Six monitoring domains, one view of risk.

Identity & access

  • Joiner / mover / leaver timeliness
  • Privileged account inventory and reviews
  • MFA coverage across critical systems

Vulnerabilities & patching

  • Open critical and high findings by age
  • Patch SLA adherence
  • External attack surface changes

Change & configuration

  • Changes with approval and testing evidence
  • Configuration drift from hardened baselines
  • Unmanaged or unknown assets

Vendors & third parties

  • Critical vendor reviews completed on schedule
  • Expiring SOC reports, BAAs, and contracts
  • New vendors onboarded without review

Detection & response

  • Log source coverage and alert triage times
  • Incidents, near-misses, and lessons learned
  • Backup and restore test results

People & governance

  • Security awareness completion and phishing results
  • Policy acknowledgments and exceptions
  • Open audit findings and corrective actions

The monitoring plan

A predictable cadence your leadership can count on.

CadenceActivitiesOutputAudience
ContinuousAutomated evidence collection and alerting where your tooling allows; triage of significant changes and incidentsIssue log with owners and due datesControl owners
MonthlyControl health checks across the six domains; KRI refresh; follow-up on open actionsControl health dashboard (green / amber / red)IT & security leads
QuarterlyRisk register review; new and emerging risks; vendor tier review; access review oversightExecutive risk report with trends and decisions neededLeadership team
Semi-annualIncident response tabletop; backup restore validation; policy exception reviewExercise report and improvement planLeadership & responders
AnnualFull risk assessment; policy and procedure review; maturity scoring; next-year program plan and budget inputAnnual program report and roadmapExecutives & board

Key risk indicators

Metrics that tell a story leadership understands.

We agree on a small set of KRIs with thresholds up front, so a red light always means the same thing and always comes with a recommended action.

Exposure

Critical vulnerabilities open past SLA; internet-facing assets without an owner.

Access

Terminated users with active access; privileged accounts not reviewed this quarter.

Resilience

Days since last successful restore test; critical systems without tested recovery.

Assurance

Controls failing monthly checks; audit findings past their corrective-action date.

Already certified and want to stay that way?

Our Sentinel plan wraps this entire monitoring program together with ongoing vCISO leadership.