Illustrative sample · Anonymized

Cyber & Technology Risk — Risk-Committee Dashboard

Period Q2 2026 Prepared for Risk Committee Profile Regional bank · ~$2.4B assets Framework NIST CSF 2.0

Overall cyber-risk posture is moderate and improving. Two of last quarter's four critical findings are closed; third-party and cloud concentration remains the top residual risk. Program maturity is on track to reach target tier by Q4.

Headline indicators
Overall cyber-risk rating
Moderate
▼ improving · within appetite
NIST CSF 2.0 maturity
2.9/ 3.5 target
▲ +0.3 vs Q1
Critical findings open
3
▼ from 7 in Q1
Mean time to remediate — critical
16days
target ≤ 30
NIST CSF 2.0 — function maturity
Govern
3.1/4
Identify
2.8/4
Protect
3.0/4
Detect
2.6/4
Respond
2.7/4
Recover
2.5/4
Current maturity Target (3.5) Scale 0–4 · higher is stronger
Top enterprise risks
RiskInherentResidualTrendOwnerStatus
Third-party & cloud concentrationHighElevatedCIOMitigating
Ransomware & recovery readinessHighModerateCISOOn track
Privileged identity & accessHighModerateCISOOn track
Legacy / end-of-life systemsMediumElevatedCTONeeds investment
AI & model governanceMediumModerateCIOEstablishing
Regulatory & assurance readiness
FFIEC CAT → NIST CSF 2.0 transition
Complete · baseline adopted Q1 2026
Next examination readiness
On track · target window Q3 2026
Cyber-insurance attestation
Requirements met · renewal Q4
Internal audit — cyber findings
2 open · 0 past due
Incident & resilience readiness
Incident-response plan
Approved · last reviewed Apr 2026
Most recent tabletop
May 2026 · ransomware scenario
Critical-service recovery test
RTO met on 4 of 5 services
Mean time to detect
4.2 hrs · ▼ from 9.1 hrs
Board-approved roadmap — progress
Remediation roadmap execution62%
18 of 29 actions complete · 4 due this quarter · 0 overdue

Illustrative composite. This sample reflects the format and metrics NorthBridge prepares for boards and risk committees. Figures are representative of a typical engagement and contain no client data.