Cybersecurity & Information Security Risk Posture

Vantara Financial Services | FCA SYSC & DORA Alignment | 90-Day Risk Window

Last Updated: 2023-10-27 06:15 UTC | Data Coverage: 2023-08-01 → 2023-10-26

Annual Loss Expectancy (ALE)
£2.8M
-18.2% YoY
Target: -20% YoY
Vuln Density (EPSS-Wtd)
142.3
+12.4%
Mean Time to Detect
18.2h
-8.5%
Priv Account Hygiene
87.4%
+3.2%
3rd-Party Rating Drift
-2.1
Decline
Patch Compliance
94.6%
+1.8%
Incident Containment
91.2%
+4.1%

Exploitability-Weighted Vulnerability Density (90-Day Trend)

CVSSv3 Score × EPSS Probability | Zero-Day Event (CVE-2023-44487) in Week 9 Caused Spike

Mean Time to Detect by Threat Category

Privileged Account Hygiene Components

MFA Enrollment 98.4%
Dormant Account % 4.1%
Standing Admin Access 8.2%
Password Rotation Compliance 89.6%
Composite Score: 87.4% (Target: ≥90%)

Third-Party Security Rating Drift

Patch Compliance Rate by Criticality

Security Control Coverage by Asset Class

% of Assets with All Required Controls Active
EDR
SIEM
DLP
Encryption
Vuln Scan
Patch Mgmt
Endpoints
98%
97%
96%
99%
94%
95%
Servers (On-Prem)
92%
100%
78%
97%
91%
96%
Cloud Workloads
84%
89%
72%
93%
81%
79%
Network Devices
100%
100%
98%
97%
IoT/OT
62%
74%
81%
68%
71%
SaaS Apps
91%
88%
95%
≥90%
75-89%
<75%
N/A

Phishing Simulation Results

Click-Through Rate
6.8%
-2.1%
Report Rate
42.3%
+8.4%

Data Exfiltration Attempt Rate

Confirmed DLP Violations per 1,000 Endpoints per Week

Cloud Misconfiguration Density by Provider

CSPM Findings per 100 Cloud Resources

Security Incident Summary (90 Days)

Severity Total Contained Rate Avg MTTD
Critical 3 3 100% 8.2h
High 14 13 92.9% 12.4h
Medium 37 34 91.9% 18.7h
Low 82 73 89.0% 26.3h
Total 136 123 90.4% 18.2h
Notable Event: CVE-2023-44487 (HTTP/2 Rapid Reset)
Week 9 zero-day triggered cloud workload vulnerability spike. All instances patched within 72h. No confirmed exploitation.