Zum Inhalt springen

IKT-Risikomanagement

IKT-Risikoregister

Risiken konsistent bewerten, Fristen priorisieren und Behandlungsmaßnahmen mit regulatorischen Anforderungen verbinden.

Referenzregister: Die 18 Beispielszenarien sind eine Arbeitsvorlage und keine produktiven Mandantendaten.

Lokale Änderungen verbleiben ausschließlich in diesem Browser.

Referenzszenarien gesamt

18

Kritisch / hoch

14

Überfällig

Berechnung ausstehend

Nächste 30 Tage

Berechnung ausstehend

Abgeschlossen

1

18 Referenzszenarien; keine Mandantendaten

PDF-Vorlage
Risiko Score Owner Status Frist Aktion
RISK-001: Cloud Provider Outage — Critical Services

Extended outage of primary cloud provider affecting mission-critical hosted services with no automated failover.

15 CTO / Cloud Architecture (Beispiel) in_progress (Beispiel) 2026-09-30 (Beispiel) Implement multi-region active-active failover. Test quarterly.
RISK-002: Unauthorized Data Modification in Core Banking

Privileged user modifies transactional data without detection due to missing integrity monitoring.

10 CISO / Security Operations (Beispiel) open (Beispiel) 2026-08-15 (Beispiel) Deploy database activity monitoring (DAM) with real-time alerts.
RISK-003: Third-Party Data Leakage via API

Customer data exposed through insufficiently secured third-party API integrations with excessive data sharing.

12 API Security Team (Beispiel) open (Beispiel) 2026-10-01 (Beispiel) API security audit, implement data minimization, deploy API gateway with threat detection.
RISK-004: Critical ICT Service Provider Concentration

Single point of failure: more than 60% of critical ICT services depend on one provider (cloud/SaaS).

12 Third-Party Risk Management (Beispiel) in_progress (Beispiel) 2026-12-31 (Beispiel) Develop exit strategy per DORA Art. 28. Identify alternative providers.
RISK-005: TLPT Non-Compliance (Overdue)

Threat-Led Penetration Testing overdue by 6 months. Regulatory deadline missed.

20 CISO / Procurement (Beispiel) overdue (Beispiel) 2026-07-30 (Beispiel) Immediate TLPT procurement. Contract with accredited provider within 30 days.
RISK-006: Legacy System Single Point of Failure

Core legacy application running on end-of-life hardware with no redundancy or support contract.

12 Infrastructure Team (Beispiel) in_progress (Beispiel) 2027-03-31 (Beispiel) Migration to modern platform. Interim: procured extended support + backup system.
RISK-007: Ransomware Attack on Critical Systems

High-impact ransomware scenario: encrypted backups, business-critical data loss, regulatory reporting required.

15 Security Operations (Beispiel) in_progress (Beispiel) 2026-08-01 (Beispiel) Air-gapped backups, ransomware playbook, EDR deployment, employee training.
RISK-008: Sub-Contractor Non-Compliance Cascade

Critical outsourced service provider uses sub-contractors not covered by DORA compliance obligations.

6 Vendor Management (Beispiel) open (Beispiel) 2026-09-15 (Beispiel) Audit all sub-contractor chains. Amend contracts with flow-down clauses.
RISK-009: DDoS Attack on Customer-Facing Platforms

Large-scale DDoS attack could render online banking and customer portal unavailable.

12 Network Security (Beispiel) completed (Beispiel) 2026-07-15 (Beispiel) DDoS protection service (scrubbing center), rate limiting, CDN integration.
RISK-010: Information Register Submission Delay

Annual DORA information register submission to competent authority at risk due to data quality issues.

9 Information Register Team (Beispiel) in_progress (Beispiel) 2026-11-30 (Beispiel) Automated data quality checks, dedicated register team, monthly review cycles.
RISK-011: AI Governance Framework Deficiency

No formal AI governance framework in place for machine learning models used in credit scoring and fraud detection.

16 Chief AI Officer / Data Governance (Beispiel) open (Beispiel) 2027-06-30 (Beispiel) Develop AI governance policy per EU AI Act. Establish model validation committee and bias testing.
RISK-012: Cloud Exit Strategy Gap

No documented and tested exit strategy for primary cloud provider, creating vendor lock-in risk.

15 Cloud Architecture / TPRM (Beispiel) open (Beispiel) 2026-12-15 (Beispiel) Develop and test cloud exit plan per DORA Art. 28(3). Identify alternative providers and run tabletop exercise.
RISK-013: Insider Threat Data Exfiltration

Privileged insider could exfiltrate sensitive customer data via removable media or cloud uploads without detection.

10 CISO / Security Operations (Beispiel) open (Beispiel) 2026-11-01 (Beispiel) Deploy UEBA solution, implement DLP controls, enforce strict egress filtering, and conduct insider threat training.
RISK-014: Legacy Cryptographic Algorithm Risk

Several internal systems still use SHA-1 and TLS 1.1, vulnerable to collision and downgrade attacks.

9 Cryptography Team / Platform Security (Beispiel) in_progress (Beispiel) 2027-03-31 (Beispiel) Migrate all systems to SHA-256 and TLS 1.3. Decommission SHA-1 certificates by Q2 2027.
RISK-015: Supply Chain Audit Right Not Enforceable

Existing contracts with critical ICT sub-contractors lack enforceable audit rights for DORA compliance verification.

12 Legal / Vendor Management (Beispiel) open (Beispiel) 2026-10-15 (Beispiel) Renegotiate contracts to include mandatory audit clauses. Perform initial compliance audit within 90 days.
RISK-016: Zero-Day Vulnerability in Core Banking Platform

Unpatched critical zero-day vulnerability discovered in the core banking application that could allow remote code execution.

20 CISO / Application Security (Beispiel) open (Beispiel) 2026-07-30 (Beispiel) Immediate vendor hotfix deployment. Compensating WAF rules until patch is applied. Forensic investigation.
RISK-017: Data Center Cooling System Failure

Primary data center cooling system has degraded performance with only N configuration left, risking thermal shutdown in summer months.

8 Facilities / Infrastructure (Beispiel) in_progress (Beispiel) 2026-08-15 (Beispiel) Emergency HVAC maintenance contract. Deploy portable cooling units. Plan for N+1 upgrade.
RISK-018: GDPR Non-Compliance in Customer Data Processing

Customer data processing workflows lack documented legal basis for three high-risk processing activities identified during internal audit.

12 DPO / Privacy Team (Beispiel) open (Beispiel) 2026-09-30 (Beispiel) Update privacy notices, document legitimate interest assessments, implement consent management platform.

Governance

Vom Referenzrisiko zum prüfbaren Mandantenprozess

  1. 1

    Kontext festlegen

    Kritische Funktion, Asset, Prozess und Abhängigkeit zuordnen.

  2. 2

    Bruttorisiko bewerten

    Wahrscheinlichkeit und Auswirkung anhand genehmigter Skalen bestimmen.

  3. 3

    Kontrollen prüfen

    Kontrolldesign, Wirksamkeit und aktuelle Evidence dokumentieren.

  4. 4

    Nettorisiko entscheiden

    Behandlung, Risikoakzeptanz und Eskalation nachvollziehbar genehmigen.