Headline indicators
Overall cyber-risk rating
Moderate
▼ improving · within appetite
NIST CSF 2.0 maturity
2.9/ 3.5 target
▲ +0.3 vs Q1
Critical findings open
3
▼ from 7 in Q1
Mean time to remediate — critical
16days
target ≤ 30
NIST CSF 2.0 — function maturity
Top enterprise risks
| Risk | Inherent | Residual | Trend | Owner | Status |
|---|---|---|---|---|---|
| Third-party & cloud concentration | High | Elevated | ▬ | CIO | Mitigating |
| Ransomware & recovery readiness | High | Moderate | ▼ | CISO | On track |
| Privileged identity & access | High | Moderate | ▼ | CISO | On track |
| Legacy / end-of-life systems | Medium | Elevated | ▲ | CTO | Needs investment |
| AI & model governance | Medium | Moderate | ▬ | CIO | Establishing |
Regulatory & assurance readiness
FFIEC CAT → NIST CSF 2.0 transition
Complete · baseline adopted Q1 2026
Next examination readiness
On track · target window Q3 2026
Cyber-insurance attestation
Requirements met · renewal Q4
Internal audit — cyber findings
2 open · 0 past due
Incident & resilience readiness
Incident-response plan
Approved · last reviewed Apr 2026
Most recent tabletop
May 2026 · ransomware scenario
Critical-service recovery test
RTO met on 4 of 5 services
Mean time to detect
4.2 hrs · ▼ from 9.1 hrs
Board-approved roadmap — progress
Remediation roadmap execution62%
18 of 29 actions complete · 4 due this quarter · 0 overdue
Illustrative composite. This sample reflects the format and metrics NorthBridge prepares for boards and risk committees. Figures are representative of a typical engagement and contain no client data.