Surface
You cannot manage crypto-agility with vibes. Uptime dashboards tell you the API is green while a five-year-old signing key with no algorithm tag silently ages into a future incident. Treat cryptographic health like reliability: a small set of SLIs, owners, and review cadences.
This essay turns the series—agility, threat model, custody, incident rotation—into numbers you can put on a wall.

What “crypto health” means operationally
Crypto health is the ability to answer, any week:
- What algorithms and key lengths are we running in production?
- How old is each high-value key, and when was it last rotated or drilled?
- Are verifiers rejecting traffic for crypto reasons at abnormal rates?
- How fast did we detect and complete the last rotation drill?
If those answers require an archaeology sprint, you are flying blind.
Core SLIs (with example targets)
Targets below are illustrative starting points for a mid-size fintech platform. Tune to treasury size, regulatory posture, and chain finality—not to vanity green.
| SLI | Definition | Example target | Why it matters |
|---|---|---|---|
| Algorithm inventory coverage | % of production keys/certs with algorithm, length, purpose, owner tags | ≥ 98% | Unknown crypto cannot be migrated or alerted |
| Median production key age (signing) | Median days since creation or last rotation for hot/warm signers | ≤ 90 days hot; ≤ 180 days warm | Stale keys concentrate blast radius |
| Keys past policy age | % of keys exceeding age policy without waiver | ≤ 2% | Waivers should be rare and time-boxed |
| Failed crypto auth rate | AuthN/Z failures attributed to signature/TLS/cert validation | Baseline ± alert on 3σ or +50% week-over-week | Early signal of break, mis-issue, or attack |
| Rotation MTTD | Time from drill inject or real signal to confirmed detection | ≤ 1 hour (pager path) | Detection delay dominates incident cost |
| Rotation MTTR | Time from detect to old material unable to sign prod | ≤ 5 days for prepared hot/warm paths | The agility promise, measured |
| Dual-run readiness | % of critical verifiers that can accept dual algorithms/keys | ≥ 90% of Tier-0 services | Predicts whether MTTR is days or months |
| Cold ceremony currency | Days since last successful cold restore drill | ≤ 180 days | Cold that is never practiced is fiction |
Concrete metric examples you can copy into a scorecard
- 97.4% of production asymmetric keys have algorithm, purpose, and owner tags (gap: legacy batch jobs)
- Median hot signing key age: 47 days; p95 age 112 days (policy max 90 with waiver on two vendor-constrained keys)
- Rotation drill MTTR (last tabletop + technical): 63 hours contain-to-cutover for the primary hot payout key
- Failed JWT signature validations: 0.12% of auth attempts (7-day baseline); alert if > 0.25% for 15 minutes
- Dual-run ready: 11 of 12 Tier-0 services; remaining gap is a partner SFTP signer scheduled for Q4
- Cold restore drill: 94 days ago; next ceremony booked with dual control
These are the kinds of numbers leadership can review monthly without reading HSM manuals.
Signals worth wiring first
1. Secrets manager / PKI / HSM inventory export → warehouse with tags mandatory on create 2. Auth and gateway logs → label crypto-related failures separately from password failures 3. Signing service metrics — count, amount, destination novelty, approver latency 4. Chain monitors (where applicable) — unexpected admin txs or guardian events 5. Drill tickets — MTTD/MTTR as first-class fields, not free-text postmortems only
Anti-metrics
- “Number of CVEs closed” without mapping to *your* algorithm inventory
- Green TLS scores on a marketing site while treasury keys sit untagged
- Alert fatigue from every OpenSSL advisory without exposure context
Use threat modeling to decide which keys are Tier-0 before you drown in charts.
Cadence
- Weekly: failed crypto auth, signing anomalies, inventory drift (new untagged keys)
- Monthly: key age histograms, waiver review, dual-run gaps
- Quarterly: rotation drill for one Tier-0 path; cold ceremony currency
- Annually: full algorithm roadmap against NIST and vendor deprecations (PQC migration)
Breach-cost studies (IBM and peers) keep reminding boards that detection and containment time drive loss. Putting rotation MTTD/MTTR next to API latency makes that concrete for crypto—not only for ransomware playbooks.
From metrics to maturity
These SLIs feed the scorecard in the series finale: crypto-agility maturity checklist. Coverage and drill times are how you know you moved from slides to muscle.
How we implement
We instrument inventory and signing paths as part of observability and cyber security workstreams alongside blockchain delivery—so crypto health is not a side spreadsheet. Tie dashboards to the custody model in production signing and the boundaries in ledger boundaries for fintech.





