Monthly Report
Compliance Report — September 2026
Generated 01.10.2026 12:52
Executive Summary
37%
Overall Compliance
12
Critical/High Risks
0
Vendors Needing Attention
20
Active Alerts
Compliance Scores by Framework
37%
Overall
45%
DORA
30%
MaRisk
65%
ISO 27001
40%
NIS2
Risk Register Summary
2
Critical
10
High
1
Overdue
1
Completed
| Risk | Level | Owner | Status |
|---|---|---|---|
| Cloud Provider Outage — Critical Services | high | CTO / Cloud Architecture | in_progress |
| Unauthorized Data Modification in Core Banking | high | CISO / Security Operations | open |
| Third-Party Data Leakage via API | high | API Security Team | open |
| Critical ICT Service Provider Concentration | high | Third-Party Risk Management | in_progress |
| TLPT Non-Compliance (Overdue) | critical | CISO / Procurement | overdue |
| Legacy System Single Point of Failure | medium | Infrastructure Team | in_progress |
| Ransomware Attack on Critical Systems | high | Security Operations | in_progress |
| Sub-Contractor Non-Compliance Cascade | medium | Vendor Management | open |
Vendor Scorecard Overview
0
Total Vendors
0
Needs Attention
0%
Average Score
| Vendor | Category | Score | Status |
|---|
Active Alerts (21)
Überfällig: Cloud Provider Outage — Critical Services
Frist war vor 1.5366985528588 Tagen (2026-09-30)
Owner: CTO / Cloud Architecture
Überfällig: Unauthorized Data Modification in Core Banking
Frist war vor 47.536698552859 Tagen (2026-08-15)
Owner: CISO / Security Operations
Überfällig: Third-Party Data Leakage via API
Frist war vor 0.5366985528588 Tagen (2026-10-01)
Owner: API Security Team
Überfällig: TLPT Non-Compliance (Overdue)
Frist war vor 63.536698552859 Tagen (2026-07-30)
Owner: CISO / Procurement
Überfällig: Ransomware Attack on Critical Systems
Frist war vor 61.536698552859 Tagen (2026-08-01)
Owner: Security Operations
Überfällig: Sub-Contractor Non-Compliance Cascade
Frist war vor 16.536698552859 Tagen (2026-09-15)
Owner: Vendor Management
Evidence Gap Analysis
8
Gaps (No Coverage)
12
Covered Controls
60%
Coverage Rate
Compliance Recommendations
Overdue risk treatment: TLPT Non-Compliance (Overdue)
Immediate treatment required. Escalate to CISO and schedule remediation.
Area: Risk Management · Effort: High
TLPT schedule review
Verify that Threat-Led Penetration Testing is scheduled within the 3-year DORA cycle.
Area: Compliance · Effort: Low
Update evidence catalog
Review and update evidence items to ensure all controls have current evidence artifacts.
Area: Documentation · Effort: Medium
Resilience Platform — Monthly Compliance Report September 2026
Generated 01.10.2026 12:52 · Confidential