Zum Inhalt springen

Monthly Report

Compliance Report — September 2026

Generated 01.10.2026 12:52

Executive Summary

37%

Overall Compliance

12

Critical/High Risks

0

Vendors Needing Attention

20

Active Alerts

Compliance Scores by Framework

37%

Overall

45%

DORA

30%

MaRisk

65%

ISO 27001

40%

NIS2

Risk Register Summary

2

Critical

10

High

1

Overdue

1

Completed

Risk Level Owner Status
Cloud Provider Outage — Critical Services high CTO / Cloud Architecture in_progress
Unauthorized Data Modification in Core Banking high CISO / Security Operations open
Third-Party Data Leakage via API high API Security Team open
Critical ICT Service Provider Concentration high Third-Party Risk Management in_progress
TLPT Non-Compliance (Overdue) critical CISO / Procurement overdue
Legacy System Single Point of Failure medium Infrastructure Team in_progress
Ransomware Attack on Critical Systems high Security Operations in_progress
Sub-Contractor Non-Compliance Cascade medium Vendor Management open

Vendor Scorecard Overview

0

Total Vendors

0

Needs Attention

0%

Average Score

Vendor Category Score Status

Active Alerts (21)

19 Critical 1 High 1 Medium

Überfällig: Cloud Provider Outage — Critical Services

Frist war vor 1.5366985528588 Tagen (2026-09-30)

Owner: CTO / Cloud Architecture

Überfällig: Unauthorized Data Modification in Core Banking

Frist war vor 47.536698552859 Tagen (2026-08-15)

Owner: CISO / Security Operations

Überfällig: Third-Party Data Leakage via API

Frist war vor 0.5366985528588 Tagen (2026-10-01)

Owner: API Security Team

Überfällig: TLPT Non-Compliance (Overdue)

Frist war vor 63.536698552859 Tagen (2026-07-30)

Owner: CISO / Procurement

Überfällig: Ransomware Attack on Critical Systems

Frist war vor 61.536698552859 Tagen (2026-08-01)

Owner: Security Operations

Überfällig: Sub-Contractor Non-Compliance Cascade

Frist war vor 16.536698552859 Tagen (2026-09-15)

Owner: Vendor Management

Evidence Gap Analysis

8

Gaps (No Coverage)

12

Covered Controls

60%

Coverage Rate

Compliance Recommendations

critical

Overdue risk treatment: TLPT Non-Compliance (Overdue)

Immediate treatment required. Escalate to CISO and schedule remediation.

Area: Risk Management · Effort: High

medium

TLPT schedule review

Verify that Threat-Led Penetration Testing is scheduled within the 3-year DORA cycle.

Area: Compliance · Effort: Low

low

Update evidence catalog

Review and update evidence items to ensure all controls have current evidence artifacts.

Area: Documentation · Effort: Medium

Resilience Platform — Monthly Compliance Report September 2026

Generated 01.10.2026 12:52 · Confidential