Leading indicators (early warning indicators) are measurable metrics that signal impending disruptions, risks, or negative trends before an actual incident occurs. They enable proactive action.
Examples in the ISMS context: rising numbers of failed login attempts, growing patch backlogs, increasing count of open risks without treatment plans, declining participation rates in security training. Leading indicators are the counterpart to lagging indicators, which are only measurable after an incident (e.g., number of security incidents). A good ISMS KPI system combines both types for forward-looking and retrospective management.