Zum Inhalt springen

Monthly Report

Compliance Report — Juli 2026

Generated 17.08.2026 10:09

Executive Summary

37%

Overall Compliance

12

Critical/High Risks

0

Vendors Needing Attention

12

Active Alerts

Compliance Scores by Framework

37%

Overall

45%

DORA

30%

MaRisk

65%

ISO 27001

40%

NIS2

Risk Register Summary

2

Critical

10

High

1

Overdue

1

Completed

Risk Level Owner Status
Cloud Provider Outage — Critical Services high CTO / Cloud Architecture in_progress
Unauthorized Data Modification in Core Banking high CISO / Security Operations open
Third-Party Data Leakage via API high API Security Team open
Critical ICT Service Provider Concentration high Third-Party Risk Management in_progress
TLPT Non-Compliance (Overdue) critical CISO / Procurement overdue
Legacy System Single Point of Failure medium Infrastructure Team in_progress
Ransomware Attack on Critical Systems high Security Operations in_progress
Sub-Contractor Non-Compliance Cascade medium Vendor Management open

Vendor Scorecard Overview

0

Total Vendors

0

Needs Attention

0%

Average Score

Vendor Category Score Status

Active Alerts (13)

12 Critical 1 Medium

Überfällig: Unauthorized Data Modification in Core Banking

Frist war vor 2.4235558161458 Tagen (2026-08-15)

Owner: CISO / Security Operations

Überfällig: TLPT Non-Compliance (Overdue)

Frist war vor 18.423555816146 Tagen (2026-07-30)

Owner: CISO / Procurement

Überfällig: Ransomware Attack on Critical Systems

Frist war vor 16.423555816146 Tagen (2026-08-01)

Owner: Security Operations

Überfällig: DDoS Attack on Customer-Facing Platforms

Frist war vor 33.423555816146 Tagen (2026-07-15)

Owner: Network Security

Überfällig: Zero-Day Vulnerability in Core Banking Platform

Frist war vor 18.423555816146 Tagen (2026-07-30)

Owner: CISO / Application Security

Überfällig: Data Center Cooling System Failure

Frist war vor 2.4235558161458 Tagen (2026-08-15)

Owner: Facilities / Infrastructure

Evidence Gap Analysis

8

Gaps (No Coverage)

12

Covered Controls

60%

Coverage Rate

Compliance Recommendations

critical

Overdue risk treatment: TLPT Non-Compliance (Overdue)

Immediate treatment required. Escalate to CISO and schedule remediation.

Area: Risk Management · Effort: High

medium

TLPT schedule review

Verify that Threat-Led Penetration Testing is scheduled within the 3-year DORA cycle.

Area: Compliance · Effort: Low

low

Update evidence catalog

Review and update evidence items to ensure all controls have current evidence artifacts.

Area: Documentation · Effort: Medium

Resilience Platform — Monthly Compliance Report Juli 2026

Generated 17.08.2026 10:09 · Confidential