IKT-Risikomanagement
IKT-Risikoregister
Risiken konsistent bewerten, Fristen priorisieren und Behandlungsmaßnahmen mit regulatorischen Anforderungen verbinden.
Referenzregister: Die 18 Beispielszenarien sind eine Arbeitsvorlage und keine produktiven Mandantendaten.
Lokale Änderungen verbleiben ausschließlich in diesem Browser.
Referenzszenarien gesamt
18
Kritisch / hoch
14
Überfällig
Berechnung ausstehend
Nächste 30 Tage
Berechnung ausstehend
Abgeschlossen
1
18 Referenzszenarien; keine Mandantendaten
| Risiko | Score | Owner | Status | Frist | Aktion |
|---|---|---|---|---|---|
| RISK-001: Cloud Provider Outage — Critical Services Extended outage of primary cloud provider affecting mission-critical hosted services with no automated failover. |
15 | CTO / Cloud Architecture (Beispiel) | in_progress (Beispiel) | 2026-09-30 (Beispiel) | Implement multi-region active-active failover. Test quarterly. |
| RISK-002: Unauthorized Data Modification in Core Banking Privileged user modifies transactional data without detection due to missing integrity monitoring. |
10 | CISO / Security Operations (Beispiel) | open (Beispiel) | 2026-08-15 (Beispiel) | Deploy database activity monitoring (DAM) with real-time alerts. |
| RISK-003: Third-Party Data Leakage via API Customer data exposed through insufficiently secured third-party API integrations with excessive data sharing. |
12 | API Security Team (Beispiel) | open (Beispiel) | 2026-10-01 (Beispiel) | API security audit, implement data minimization, deploy API gateway with threat detection. |
| RISK-004: Critical ICT Service Provider Concentration Single point of failure: more than 60% of critical ICT services depend on one provider (cloud/SaaS). |
12 | Third-Party Risk Management (Beispiel) | in_progress (Beispiel) | 2026-12-31 (Beispiel) | Develop exit strategy per DORA Art. 28. Identify alternative providers. |
| RISK-005: TLPT Non-Compliance (Overdue) Threat-Led Penetration Testing overdue by 6 months. Regulatory deadline missed. |
20 | CISO / Procurement (Beispiel) | overdue (Beispiel) | 2026-07-30 (Beispiel) | Immediate TLPT procurement. Contract with accredited provider within 30 days. |
| RISK-006: Legacy System Single Point of Failure Core legacy application running on end-of-life hardware with no redundancy or support contract. |
12 | Infrastructure Team (Beispiel) | in_progress (Beispiel) | 2027-03-31 (Beispiel) | Migration to modern platform. Interim: procured extended support + backup system. |
| RISK-007: Ransomware Attack on Critical Systems High-impact ransomware scenario: encrypted backups, business-critical data loss, regulatory reporting required. |
15 | Security Operations (Beispiel) | in_progress (Beispiel) | 2026-08-01 (Beispiel) | Air-gapped backups, ransomware playbook, EDR deployment, employee training. |
| RISK-008: Sub-Contractor Non-Compliance Cascade Critical outsourced service provider uses sub-contractors not covered by DORA compliance obligations. |
6 | Vendor Management (Beispiel) | open (Beispiel) | 2026-09-15 (Beispiel) | Audit all sub-contractor chains. Amend contracts with flow-down clauses. |
| RISK-009: DDoS Attack on Customer-Facing Platforms Large-scale DDoS attack could render online banking and customer portal unavailable. |
12 | Network Security (Beispiel) | completed (Beispiel) | 2026-07-15 (Beispiel) | DDoS protection service (scrubbing center), rate limiting, CDN integration. |
| RISK-010: Information Register Submission Delay Annual DORA information register submission to competent authority at risk due to data quality issues. |
9 | Information Register Team (Beispiel) | in_progress (Beispiel) | 2026-11-30 (Beispiel) | Automated data quality checks, dedicated register team, monthly review cycles. |
| RISK-011: AI Governance Framework Deficiency No formal AI governance framework in place for machine learning models used in credit scoring and fraud detection. |
16 | Chief AI Officer / Data Governance (Beispiel) | open (Beispiel) | 2027-06-30 (Beispiel) | Develop AI governance policy per EU AI Act. Establish model validation committee and bias testing. |
| RISK-012: Cloud Exit Strategy Gap No documented and tested exit strategy for primary cloud provider, creating vendor lock-in risk. |
15 | Cloud Architecture / TPRM (Beispiel) | open (Beispiel) | 2026-12-15 (Beispiel) | Develop and test cloud exit plan per DORA Art. 28(3). Identify alternative providers and run tabletop exercise. |
| RISK-013: Insider Threat Data Exfiltration Privileged insider could exfiltrate sensitive customer data via removable media or cloud uploads without detection. |
10 | CISO / Security Operations (Beispiel) | open (Beispiel) | 2026-11-01 (Beispiel) | Deploy UEBA solution, implement DLP controls, enforce strict egress filtering, and conduct insider threat training. |
| RISK-014: Legacy Cryptographic Algorithm Risk Several internal systems still use SHA-1 and TLS 1.1, vulnerable to collision and downgrade attacks. |
9 | Cryptography Team / Platform Security (Beispiel) | in_progress (Beispiel) | 2027-03-31 (Beispiel) | Migrate all systems to SHA-256 and TLS 1.3. Decommission SHA-1 certificates by Q2 2027. |
| RISK-015: Supply Chain Audit Right Not Enforceable Existing contracts with critical ICT sub-contractors lack enforceable audit rights for DORA compliance verification. |
12 | Legal / Vendor Management (Beispiel) | open (Beispiel) | 2026-10-15 (Beispiel) | Renegotiate contracts to include mandatory audit clauses. Perform initial compliance audit within 90 days. |
| RISK-016: Zero-Day Vulnerability in Core Banking Platform Unpatched critical zero-day vulnerability discovered in the core banking application that could allow remote code execution. |
20 | CISO / Application Security (Beispiel) | open (Beispiel) | 2026-07-30 (Beispiel) | Immediate vendor hotfix deployment. Compensating WAF rules until patch is applied. Forensic investigation. |
| RISK-017: Data Center Cooling System Failure Primary data center cooling system has degraded performance with only N configuration left, risking thermal shutdown in summer months. |
8 | Facilities / Infrastructure (Beispiel) | in_progress (Beispiel) | 2026-08-15 (Beispiel) | Emergency HVAC maintenance contract. Deploy portable cooling units. Plan for N+1 upgrade. |
| RISK-018: GDPR Non-Compliance in Customer Data Processing Customer data processing workflows lack documented legal basis for three high-risk processing activities identified during internal audit. |
12 | DPO / Privacy Team (Beispiel) | open (Beispiel) | 2026-09-30 (Beispiel) | Update privacy notices, document legitimate interest assessments, implement consent management platform. |
Keine Risiken entsprechen den gewählten Filtern.
Behandlungsmaßnahme
Framework-Zuordnung
Lokaler Arbeitsstand
Diese Angaben sind ein Browserentwurf und werden nicht an den Mandantenserver übertragen.
Governance
Vom Referenzrisiko zum prüfbaren Mandantenprozess
-
1
Kontext festlegen
Kritische Funktion, Asset, Prozess und Abhängigkeit zuordnen.
-
2
Bruttorisiko bewerten
Wahrscheinlichkeit und Auswirkung anhand genehmigter Skalen bestimmen.
-
3
Kontrollen prüfen
Kontrolldesign, Wirksamkeit und aktuelle Evidence dokumentieren.
-
4
Nettorisiko entscheiden
Behandlung, Risikoakzeptanz und Eskalation nachvollziehbar genehmigen.
Verknüpfte Arbeitsräume