Glossary
GLOSSARY Measurement fundamentals

Key Performance Indicator (KPI)

Last updated 27 Jul 2026

A key performance indicator is a metric chosen to track progress against a stated objective. The word “key” does the work. Every organization measures hundreds of things. Only a handful qualify as KPIs, because a KPI is meant to change what someone does.

What separates a KPI from an ordinary metric

Any number you can compute is a metric. A KPI is a metric with three extra properties: it is tied to an objective, it has a named owner, and it has a target or threshold that defines good and bad.

Count of open vulnerabilities is a metric. Share of critical vulnerabilities closed inside the agreed window, owned by the infrastructure lead, with a target of 95 percent, is a KPI.

Why security KPIs are harder than most

Security has more tools than almost any other function in the enterprise, and yet a large part of the program never appears in any of them. Training completion, tabletop exercises, audit findings, budget commitments, third-party assessments. These live in spreadsheets, ticket queues, HR platforms and people’s heads.

So security KPIs drift toward whatever the tools happen to export. Alert counts. Agent coverage. Scan results. Useful numbers, but they describe the tooling, not the program.

Common failure modes

Too many indicators. Twenty KPIs is a report. Six is a decision aid.

No owner. A number nobody is accountable for gets explained away every quarter.

No target. Without a threshold, every value is just a value.

A formula that changes when the tool changes. The trend line then compares two different things. See definition drift.

Indicators chosen because they were easy to pull rather than because they mattered. See Goodhart’s Law.