Digitalization of an ICT Risk Assessment framework and risk assessment
Bank oriented towards Italian SMEs and private individuals through its network of agents and its digital channels
The Chief Risk Officer requested MACFIN’s support for the review and initial implementation of the ICT Risk Assessment framework, as well as the digitalization of the process through smart-app development.
Goals
Strengthen,
the methodological approach and operational processes of ICT Risk Assessment
Digitalizing
ICT risk evaluation and reporting processes through IT solutions
Activity
Construction of data models
and identification of functional requirements of customized and dedicated IT solutions for digital management of periodic ICT Risk Assessment campaigns
Prototyping
different smart-app interfaces to support workflows
Key User Acceptance Test
setting up and conducting Key User Acceptance Tests and validating releases in the production environment
Operational and management reporting
based on business intelligence software
Development of ICT Risk assessment checklists
for the several stakeholders involved in the process and entitled to make judgments in terms of - for example - adverse risk scenarios, cyber threats, and control safeguards
Identifying areas for improvement
defining the remediation plan and sharing them with the responsible departments of the Bank
Results
Periodic ICT risk analysis
by collaborative ICT risk analysis processes (i.e. ICT, Business Owner, Compliance, CRO)
Data model management
of the information considered in the methodological approach (assets, risk scenarios, threats, controls)
Automated risk measurements
at the aggregate level and producing reporting on the outcome of the analyses conducted
Effective and timely reporting
to the Executive Management Team of the Bank
REQUEST A MEETING
Would you like more information or request a meeting with our consultants?
REQUEST INFORMATION
ABOUT OUR SERVICES
Would you like to have more information about our services and solutions? Enter your data and we will contact you as soon as possible.
Other Success Cases
Setting the "231" Framework of an International Gaming Player
Industry & Services | ESG, Risk & Compliance
Design of a Risk Reporting solution of an Insurance Group
Insurance | ESG, Risk & Compliance
Setting the "GDPR" Framework of a State-owned company
Non-Profit & Public | ESG, Risk & Compliance