Ga naar inhoud

Audit & bewijs ·

Security KPIs for ISO 27001 management review in 2026

The management review is a mandatory part of ISO 27001, and auditors do not check whether you have a nice dashboard, but whether the board actually discusses the ISMS performance and steers on it. For that you need a handful of KPIs that say something — not thirty charts no one reads, but a few numbers that give the conversation direction. This article shows which KPIs work and how to use them.

Why KPIs, not a dashboard full of charts

Measuring is only useful if someone acts on it. A dashboard that fills automatically but that no one looks at yields no audit evidence — worse, it raises the question of whether your ISMS is really alive. The purpose of security KPIs is to give management an honest picture of what is going well and badly, so it can make substantiated decisions about priorities and budget. Quality over quantity, then.

KPIs that really work

  • Open corrective actions (CAPs) and average closure time: shows whether findings are actually resolved, or left lying.
  • Patch SLA compliance (%): what share of your vulnerabilities you close within the agreed period — a direct measure of your basic resilience.
  • Phishing click rate and report rate: not just how many people click, but above all how many report — the latter is the sign of a healthy security culture.
  • Incidents per quarter, by severity: a trend, not an absolute number; is it rising or falling, and why?
  • Access review completion (%): whether your periodic access reviews are actually finished.

From number to decision

A KPI without a conversation is a number without meaning. The art is to formulate a so-what per KPI: if patch SLA compliance drops, what is the cause behind it and what decision does the board take? In your management review minutes, record not only the numbers but also the conclusions and the actions with an owner. That is exactly what an auditor looks for: evidence that management steered on the basis of the data.

Choose targets, not arbitrary numbers

A KPI only gains meaning with a target beside it. “Patch SLA compliance 95%” or “phishing report rate above 40%” makes clear at a glance whether you are on course. Set realistic targets and evaluate them periodically; targets too strict that you never meet get ignored, targets too loose say nothing. The trend over several quarters is often more valuable than the absolute value.

What the auditor concretely asks

Expect the auditor to request your management review minutes and check whether the KPIs appear there and were discussed. The classic finding is a neat dashboard that appears nowhere in decision-making. So make sure the link between your numbers and your management decisions is explicit and findable; that lifts you from “we measure” to “we steer”.

Common mistakes

  • Too many KPIs — thirty metrics drown the signal; choose a handful that really matter.
  • Measuring without a target — a number without a norm gives no direction.
  • Dashboard without a conversation — if the KPIs are not discussed in the management review, they do not count.
  • Measuring only click rate — the report rate often says more about your culture than the click rate.

Getting started

Choose three to five KPIs that match your biggest risks, give them a target, and put them on the agenda of your next management review — including the decisions that follow. Want to know more about the management review and audit preparation? See the ISO 27001 route or take the free readiness scan.

Deep dive in the knowledge base

Check audit readiness

Keep evidence, actions and open items aligned for stage 1 and stage 2.

View audit readiness

← Back to overview