The digital operational resilience testing programme shall provide for the execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing.
Report documenting the results of vulnerability assessments and scans, including identified vulnerabilities, severity ratings, affected systems, and remediation recommendations as required by DORA Article 25.
vulnerability-assessment-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
VULNERABILITY ASSESSMENT REPORT
Nordvik Bank AG
Assessment ID: VA-2025-Q1-001
Assessment Date: 15 March 2025
Prepared by: Security Testing Lead
Reviewed by: Katrin Halvorsen, CISO
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
This report presents the findings of the Q1 2025 vulnerability assessment conducted
across Nordvik Bank AG's in-scope ICT infrastructure and applications. The assessment
was performed using a combination of automated scanning tools and manual validation,
covering 127 systems across all five security zones and the Bank's AWS cloud
environment.
Key Findings:
— Total vulnerabilities identified: 89
— Critical: 2 | High: 11 | Medium: 34 | Low: 42
— Remediation rate from Q4 2024 assessment: 91%
— New vulnerabilities since last assessment: 23
— Recurring vulnerabilities: 7 (flagged for systemic review)
The two critical vulnerabilities relate to an unpatched Apache Struts component in
a legacy regulatory reporting module and an exposed administrative interface on a
development-adjacent network segment. Both have been escalated to the CISO for
immediate remediation within the 72-hour SLA.
Overall, the Bank's vulnerability posture has improved compared to Q4 2024, with
the total vulnerability count decreasing by 12% and the critical count remaining
stable. The remediation programme continues to address findings within defined SLAs.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ASSESSMENT SCOPE
Scope Element Detail
─────────────────────────────────────────────────────────────────────────────
Systems assessed 127 (of 143 total ICT assets)
Network zones DMZ, Production, Management, User, Cloud (AWS)
Assessment type Infrastructure vulnerability scan + web
application scan + cloud configuration review
Tools used Qualys VMDR 10.x, Checkmarx SAST 9.6,
AWS Security Hub, Nessus Professional 10.7
Scan window 10–14 March 2025
Authenticated scanning Yes (credentialed scans for all zones)
Compliance benchmarks CIS Benchmarks v8, DORA Art. 25, PCI DSS 4.0
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
METHODOLOGY
The assessment followed a four-phase methodology:
Phase 1 — Discovery and Enumeration
Network discovery scans to identify active hosts, open ports, and running
services. Validated against the ICT asset inventory for completeness.
Phase 2 — Automated Vulnerability Scanning
Credentialed vulnerability scans using Qualys VMDR for infrastructure and
Checkmarx for application code. AWS Security Hub for cloud configuration
compliance. Scans executed during the approved maintenance window.
Phase 3 — Manual Validation
Manual verification of critical and high-severity findings to eliminate
false positives. Includes contextual risk assessment considering the
asset's criticality, network exposure, and existing compensating controls.
Phase 4 — Reporting and Prioritisation
Findings consolidated, deduplicated, and prioritised using the Bank's
risk-based vulnerability scoring methodology (CVSS base score adjusted
for asset criticality and threat intelligence).
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
FINDINGS SUMMARY
Severity Count % of Total Change vs Q4 2024
─────────────────────────────────────────────────────────────────────────────
Critical 2 2.2% 0 (stable)
High 11 12.4% -3 (improved)
Medium 34 38.2% -5 (improved)
Low 42 47.2% -4 (improved)
─────────────────────────────────────────────────────────────────────────────
Total 89 100.0% -12 (improved)
Findings by Asset Category:
Category Critical High Medium Low Total
─────────────────────────────────────────────────────────────────────────────
Servers (Windows) 0 3 8 12 23
Servers (Linux) 1 2 6 8 17
Network Equipment 0 1 4 5 10
Web Applications 1 3 7 6 17
Databases 0 1 3 4 8
Cloud Configuration 0 1 4 5 10
End-User Devices 0 0 2 2 4
─────────────────────────────────────────────────────────────────────────────
Total 2 11 34 42 89
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DETAILED FINDINGS — CRITICAL
VULN-2025-001: Unpatched Apache Struts (CVE-2024-53677)
Affected System: SYS-005 (Regulatory Reporting — ABACUS)
CVSS Score: 9.8 (Critical)
Description: Apache Struts 2.5.32 running on the ABACUS application
server is vulnerable to remote code execution via crafted
file upload parameters.
Impact: Full system compromise; potential access to regulatory
reporting data and connected database.
Remediation: Upgrade Apache Struts to version 6.4.0 or later.
Interim mitigation: restrict file upload functionality
and apply WAF rule.
Deadline: 18 March 2025 (72-hour SLA)
Owner: IT Operations Team
VULN-2025-002: Exposed Administrative Interface
Affected System: SYS-014 (Firewall Management Interface)
CVSS Score: 9.1 (Critical)
Description: Palo Alto firewall management interface accessible from
the User network zone due to misconfigured access rule.
Should be restricted to Management zone only.
Impact: Potential unauthorised access to firewall configuration;
could enable network segmentation bypass.
Remediation: Restrict management interface access to Management zone
IP ranges. Review all firewall access rules.
Deadline: 18 March 2025 (72-hour SLA)
Owner: Network Operations Team
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RISK RATINGS
Overall Vulnerability Risk Rating: MEDIUM
The Bank's vulnerability posture is assessed as Medium risk. While two critical
vulnerabilities require immediate attention, the overall trend is positive with
a 12% reduction in total findings and a 91% remediation rate from the previous
quarter. The critical findings are isolated to specific systems and do not
indicate a systemic control failure.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REMEDIATION RECOMMENDATIONS
Priority Finding ID Action Deadline
─────────────────────────────────────────────────────────────────────────────
Immediate VULN-2025-001 Patch Apache Struts 18 Mar 2025
Immediate VULN-2025-002 Restrict firewall mgmt access 18 Mar 2025
High VULN-2025-003 Update OpenSSL on 3 servers 29 Mar 2025
through -013
Medium VULN-2025-014 Address medium findings 30 Jun 2025
through -047
Low VULN-2025-048 Address low findings 30 Sep 2025
through -089
Next scheduled assessment: Q2 2025 (June 2025)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Prepared by: Security Testing Lead
Reviewed by: Katrin Halvorsen, CISO
Date: 15 March 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
vulnerability_assessment_status — fs-vulnerability-assessment
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
"evidenceClassId": "vulnerability-assessment-report",
"factType": "vulnerability_assessment_status",
"data": {
"assessment_date": "2025-03-15",
"total_vulnerabilities": 89,
"critical_count": 2,
"high_count": 11,
"medium_count": 34,
"low_count": 42,
"remediation_in_progress": true,
"remediated_count": 66,
"next_assessment_date": "2025-06-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-20T09:00:00Z",
"supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
"evidenceClassId": "penetration-test-report",
"factType": "penetration_test_results",
"data": {
"test_date": "2025-02-14",
"tester_organisation": "CyberShield GmbH",
"findings_count": 18,
"critical_findings": 1,
"high_findings": 3,
"test_passed": false,
"retesting_completed": false,
"remediation_verified": false
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-20T09:00:00Z",
"supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
"evidenceClassId": "resilience-testing-programme",
"factType": "basic_testing_coverage_status",
"data": {
"reporting_period_end": "2025-03-31",
"vulnerability_assessments_performed": 4,
"penetration_tests_performed": 1,
"network_assessments_performed": 1,
"gap_analyses_performed": 1,
"source_code_reviews_performed": 2,
"scenario_based_tests_performed": 1,
"all_required_test_types_covered": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-04-05T09:00:00Z",
"supersededBy": null
}
Report documenting the results of penetration testing activities, including attack scenarios, findings, exploitation evidence, and remediation recommendations.
penetration-test-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
PENETRATION TEST REPORT
Nordvik Bank AG
Test ID: PT-2025-001
Test Date: 3–14 February 2025
Prepared by: CyberShield GmbH (External Penetration Testing Firm)
Reviewed by: Security Testing Lead, Nordvik Bank AG
Classification: Strictly Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
CyberShield GmbH was engaged by Nordvik Bank AG to conduct an annual penetration
test of the Bank's core banking platform, digital banking channels, and supporting
infrastructure. The test was performed between 3 and 14 February 2025 from both
external (internet-facing) and internal (assumed breach) perspectives.
Key Results:
— Total findings: 18
— Critical findings: 1
— High findings: 3
— Medium findings: 8
— Low findings: 6
— Overall assessment: The Bank's security posture is ADEQUATE with specific
areas requiring remediation.
The single critical finding relates to an insecure direct object reference (IDOR)
vulnerability in the digital banking API that could allow an authenticated user to
access another customer's account summary data. This finding was reported to the
Bank's CISO immediately upon discovery on 5 February 2025 and a temporary mitigation
was applied within 6 hours.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SCOPE AND RULES OF ENGAGEMENT
Scope Element Detail
─────────────────────────────────────────────────────────────────────────────
Target systems Core Banking Platform (Temenos T24)
Digital Banking Portal (web application)
Mobile Banking API
Payment Gateway (SWIFT/SEPA interface)
Supporting infrastructure (AD, DNS, DB)
Test type Black-box (external), Grey-box (internal)
Network perspective External: internet-facing services
Internal: assumed breach from User zone
Social engineering Included: phishing simulation (50 targets)
Physical testing Excluded (separate assessment)
Testing window Business hours: 08:00–18:00 CET
Active exploitation: maintenance window only
Emergency contact Katrin Halvorsen, CISO (+41 XX XXX XX XX)
Data handling No production customer data accessed or exfiltrated
Test accounts provided by the Bank
Rules of Engagement:
— No denial-of-service testing against production systems
— No modification or deletion of production data
— Immediate notification to CISO for any Critical finding
— All test traffic logged and identifiable by source IP range
— Testing paused during any production incident
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
METHODOLOGY
The penetration test followed the OWASP Testing Guide v4.2 and PTES (Penetration
Testing Execution Standard) methodologies:
Phase 1 — Reconnaissance (Days 1–2)
Open-source intelligence gathering, DNS enumeration, service discovery,
and technology fingerprinting of internet-facing assets.
Phase 2 — Vulnerability Analysis (Days 3–5)
Automated and manual vulnerability identification across web applications,
APIs, network services, and infrastructure components.
Phase 3 — Exploitation (Days 6–8)
Controlled exploitation of identified vulnerabilities to assess real-world
impact. Includes privilege escalation, lateral movement, and data access
attempts.
Phase 4 — Post-Exploitation (Days 9–10)
Assessment of the extent of access achievable from compromised positions.
Evaluation of detection and response capabilities.
Phase 5 — Reporting (Days 11–12)
Consolidation of findings, risk assessment, and remediation recommendations.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ATTACK SCENARIOS
Scenario 1: External Attacker — Internet-Facing Services
Objective: Gain unauthorised access to customer data or internal systems
via internet-facing services.
Result: IDOR vulnerability in digital banking API exploited to access
account summary data (Critical finding PT-001). Web application firewall
bypassed for specific API endpoints.
Scenario 2: Insider Threat — Assumed Breach from User Zone
Objective: Escalate privileges and move laterally from a compromised
workstation in the User zone.
Result: Limited lateral movement achieved. Network segmentation effective
in preventing direct access to Production zone. However, a misconfigured
service account with excessive permissions was identified (High finding
PT-004).
Scenario 3: Phishing Simulation
Objective: Assess employee susceptibility to targeted phishing attacks.
Result: 8 of 50 targeted employees (16%) clicked the phishing link.
3 employees (6%) entered credentials on the simulated phishing page.
Results reported separately to HR and CISO for awareness training follow-up.
Scenario 4: API Security Assessment
Objective: Identify vulnerabilities in the mobile banking and payment APIs.
Result: Rate limiting insufficient on authentication endpoint (High finding
PT-002). JWT token validation weakness allowing token reuse after password
change (High finding PT-003).
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
FINDINGS AND EVIDENCE
ID Severity Title CVSS
─────────────────────────────────────────────────────────────────────────────
PT-001 Critical IDOR in Digital Banking API 9.1
PT-002 High Insufficient Rate Limiting on Auth 7.5
PT-003 High JWT Token Reuse After Password Change 7.2
PT-004 High Excessive Service Account Permissions 7.0
PT-005 Medium Missing Security Headers (CSP, HSTS) 5.3
PT-006 Medium Verbose Error Messages in API 5.0
PT-007 Medium Outdated TLS Configuration (TLS 1.0) 5.5
PT-008 Medium Session Timeout Too Long (4 hours) 4.8
PT-009 Medium Missing Account Lockout on Admin Portal 5.8
PT-010 Medium Cross-Site Scripting (Stored) in CRM 6.1
PT-011 Medium SQL Injection (Blind) in Legacy Module 6.5
PT-012 Medium Insecure Cookie Attributes 4.3
PT-013 Low Information Disclosure in HTTP Headers 3.1
PT-014 Low Default Credentials on Test Instance 3.5
PT-015 Low Missing DNSSEC Configuration 2.8
PT-016 Low Weak Password Policy for Service Accts 3.8
PT-017 Low Unnecessary Open Ports on DB Server 3.2
PT-018 Low Outdated SSL Certificate on Internal Svc 2.5
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RISK ASSESSMENT
Overall Risk Rating: MEDIUM-HIGH
The critical IDOR vulnerability (PT-001) represents a significant risk to customer
data confidentiality. The three high-severity findings, if exploited in combination,
could enable an attacker to gain persistent access to internal systems. However, the
Bank's network segmentation, monitoring capabilities, and incident response readiness
provide meaningful compensating controls.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
REMEDIATION RECOMMENDATIONS
Priority Finding Recommended Action Deadline
─────────────────────────────────────────────────────────────────────────────
Immediate PT-001 Implement proper authorisation 21 Feb 2025
checks on all API endpoints
High PT-002 Implement rate limiting and 14 Mar 2025
account lockout on auth endpoints
High PT-003 Invalidate JWT tokens on password 14 Mar 2025
change; reduce token lifetime
High PT-004 Review and restrict service account 14 Mar 2025
permissions; implement least privilege
Medium PT-005 Implement CSP, HSTS, and other 30 Apr 2025
to PT-012 security headers; address remaining
medium findings
Low PT-013 Address low findings in next 30 Jun 2025
to PT-018 scheduled maintenance cycle
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RETESTING PLAN
Retesting of critical and high-severity findings is scheduled for 28 March 2025.
CyberShield GmbH will verify that remediation actions have been effectively
implemented and that no regression has occurred.
Retest Scope: PT-001 through PT-004
Retest Date: 28 March 2025
Retest Type: Targeted verification of remediated findings
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Prepared by: CyberShield GmbH
Lead Tester: [Lead Penetration Tester]
Reviewed by: Security Testing Lead, Nordvik Bank AG
Date: 14 February 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
vulnerability_assessment_status — fs-vulnerability-assessment
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
"evidenceClassId": "vulnerability-assessment-report",
"factType": "vulnerability_assessment_status",
"data": {
"assessment_date": "2025-03-15",
"total_vulnerabilities": 89,
"critical_count": 2,
"high_count": 11,
"medium_count": 34,
"low_count": 42,
"remediation_in_progress": true,
"remediated_count": 66,
"next_assessment_date": "2025-06-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-20T09:00:00Z",
"supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
"evidenceClassId": "penetration-test-report",
"factType": "penetration_test_results",
"data": {
"test_date": "2025-02-14",
"tester_organisation": "CyberShield GmbH",
"findings_count": 18,
"critical_findings": 1,
"high_findings": 3,
"test_passed": false,
"retesting_completed": false,
"remediation_verified": false
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-20T09:00:00Z",
"supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
"evidenceClassId": "resilience-testing-programme",
"factType": "basic_testing_coverage_status",
"data": {
"reporting_period_end": "2025-03-31",
"vulnerability_assessments_performed": 4,
"penetration_tests_performed": 1,
"network_assessments_performed": 1,
"gap_analyses_performed": 1,
"source_code_reviews_performed": 2,
"scenario_based_tests_performed": 1,
"all_required_test_types_covered": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-04-05T09:00:00Z",
"supersededBy": null
}
JSON-structured results of network security assessments including firewall rule reviews, network segmentation validation, and traffic analysis findings.
network-security-assessmentGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
{
"assessmentId": "NSA-2025-H1-001",
"assessmentDate": "2025-01-20",
"institution": "Nordvik Bank AG",
"assessedBy": "Network Security Engineer",
"reviewedBy": "Katrin Halvorsen, CISO",
"nextAssessmentDate": "2025-07-20",
"scope": {
"networksAssessed": 5,
"networkZones": ["DMZ", "Production", "Management", "User", "Cloud (AWS VPC)"],
"totalFirewallRules": 1247,
"firewallRulesReviewed": 1247,
"switchesAssessed": 34,
"routersAssessed": 8
},
"complianceScore": 87.5,
"complianceBenchmark": "CIS Benchmarks v8 — Network Devices",
"segmentationAssessment": {
"zonesValidated": 5,
"segmentationEffective": true,
"segmentationIssues": [
{
"issueId": "SEG-001",
"severity": "Medium",
"description": "Management zone accessible from User zone via legacy VPN tunnel configured for remote IT support. Tunnel should be restricted to specific source IPs.",
"affectedZones": ["User", "Management"],
"remediationAction": "Restrict VPN tunnel source IPs to IT support workstations only",
"targetDate": "2025-03-15"
},
{
"issueId": "SEG-002",
"severity": "Low",
"description": "Development zone has unrestricted outbound internet access. Should be proxied through the DMZ web proxy for logging and filtering.",
"affectedZones": ["Development"],
"remediationAction": "Route development zone internet traffic through DMZ proxy",
"targetDate": "2025-06-30"
}
]
},
"firewallRuleReview": {
"totalRules": 1247,
"activeRules": 1089,
"disabledRules": 158,
"shadowedRules": 23,
"overpermissiveRules": 7,
"expiredRules": 12,
"findings": [
{
"findingId": "FW-001",
"severity": "High",
"description": "Seven firewall rules permit traffic from 'any' source to internal services. These rules were created as temporary exceptions during a migration in Q3 2024 and were not removed.",
"affectedRules": ["FW-RULE-0892", "FW-RULE-0893", "FW-RULE-0894", "FW-RULE-0895", "FW-RULE-0896", "FW-RULE-0897", "FW-RULE-0898"],
"remediationAction": "Replace 'any' source with specific IP ranges or remove rules if migration is complete",
"targetDate": "2025-02-15"
},
{
"findingId": "FW-002",
"severity": "Medium",
"description": "23 shadowed rules detected where a broader rule higher in the rule base renders a more specific rule ineffective. Indicates rule base complexity requiring cleanup.",
"remediationAction": "Consolidate and reorder firewall rule base; remove shadowed rules",
"targetDate": "2025-04-30"
},
{
"findingId": "FW-003",
"severity": "Low",
"description": "12 rules reference expired temporary access grants (date-limited rules past their expiry). Rules are inactive but clutter the rule base.",
"remediationAction": "Remove expired rules during next maintenance window",
"targetDate": "2025-03-31"
}
]
},
"openPortsAnalysis": {
"totalOpenPorts": 342,
"expectedOpenPorts": 328,
"unexpectedOpenPorts": 14,
"unexpectedPortDetails": [
{
"host": "prod-app-srv-07",
"port": 8443,
"service": "Apache Tomcat (debug)",
"severity": "Medium",
"description": "Debug port left open after deployment troubleshooting"
},
{
"host": "prod-db-srv-02",
"port": 1521,
"service": "Oracle TNS Listener",
"severity": "Low",
"description": "Listener accessible from User zone; should be restricted to Production zone"
}
]
},
"trafficAnalysis": {
"analysisWindow": "2025-01-13 to 2025-01-19",
"totalFlowsAnalysed": 4523891,
"anomalousFlows": 127,
"anomalyCategories": [
{
"category": "Unexpected cross-zone traffic",
"count": 45,
"severity": "Medium",
"description": "Traffic from User zone to Management zone services not matching expected patterns"
},
{
"category": "High-volume data transfers",
"count": 12,
"severity": "Low",
"description": "Large data transfers during off-hours; verified as scheduled backup replication"
},
{
"category": "Unencrypted internal traffic",
"count": 70,
"severity": "Medium",
"description": "HTTP traffic between application servers in Production zone; should use TLS"
}
]
},
"overallRiskRating": "Medium",
"summary": "Network security posture is adequate with specific areas requiring attention. Firewall rule hygiene needs improvement, and two segmentation issues should be addressed. The network architecture provides effective zone separation for critical systems."
}
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
vulnerability_assessment_status — fs-vulnerability-assessment
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
"evidenceClassId": "vulnerability-assessment-report",
"factType": "vulnerability_assessment_status",
"data": {
"assessment_date": "2025-03-15",
"total_vulnerabilities": 89,
"critical_count": 2,
"high_count": 11,
"medium_count": 34,
"low_count": 42,
"remediation_in_progress": true,
"remediated_count": 66,
"next_assessment_date": "2025-06-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-20T09:00:00Z",
"supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
"evidenceClassId": "penetration-test-report",
"factType": "penetration_test_results",
"data": {
"test_date": "2025-02-14",
"tester_organisation": "CyberShield GmbH",
"findings_count": 18,
"critical_findings": 1,
"high_findings": 3,
"test_passed": false,
"retesting_completed": false,
"remediation_verified": false
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-20T09:00:00Z",
"supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
"evidenceClassId": "resilience-testing-programme",
"factType": "basic_testing_coverage_status",
"data": {
"reporting_period_end": "2025-03-31",
"vulnerability_assessments_performed": 4,
"penetration_tests_performed": 1,
"network_assessments_performed": 1,
"gap_analyses_performed": 1,
"source_code_reviews_performed": 2,
"scenario_based_tests_performed": 1,
"all_required_test_types_covered": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-04-05T09:00:00Z",
"supersededBy": null
}
CSV-structured gap analysis identifying areas where the institution's resilience testing programme falls short of DORA requirements, including coverage gaps and capability deficiencies.
gap-analysis-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
requirement_ref,requirement_description,current_status,gap_description,severity,remediation_action,target_date,responsible_owner DORA Art.24(1),Establish comprehensive digital operational resilience testing programme,Compliant,No gap — programme established and approved by Board Risk Committee,N/A,N/A,N/A,CISO DORA Art.24(2),Testing programme shall be proportionate to size and risk profile,Compliant,No gap — risk-based scope definition in place covering 88.8% of ICT assets,N/A,N/A,N/A,Security Testing Lead DORA Art.24(3),Testing programme shall include range of tests and assessments,Partially Compliant,Source code reviews not yet integrated into CI/CD pipeline for all applications; currently manual and ad-hoc for legacy systems,Medium,Integrate SAST/DAST into CI/CD pipeline for all production applications,2025-06-30,AppSec Team Lead DORA Art.24(4),Testing programme shall be reviewed and updated at least annually,Compliant,No gap — annual review completed January 2025,N/A,N/A,N/A,CISO DORA Art.24(5),Testing shall be undertaken by independent parties,Partially Compliant,Internal vulnerability scans conducted by first-line IT team without formal independence attestation; external penetration tests properly independent,Medium,Establish formal independence attestation process for internal testing activities,2025-03-31,Head of Internal Audit DORA Art.24(6),Maintain records of all testing activities for at least 5 years,Compliant,No gap — document retention policy covers all testing records with 5-year minimum,N/A,N/A,N/A,Compliance Officer DORA Art.25(1),Perform vulnerability assessments and scans,Compliant,No gap — quarterly vulnerability assessments in place using Qualys VMDR,N/A,N/A,N/A,Security Testing Lead DORA Art.25(1),Perform open-source analyses,Partially Compliant,Snyk deployed for new applications but legacy applications not yet onboarded for dependency scanning,Medium,Onboard all production applications to Snyk dependency scanning,2025-06-30,AppSec Team Lead DORA Art.25(1),Perform network security assessments,Compliant,No gap — semi-annual network security assessments conducted,N/A,N/A,N/A,Network Security Engineer DORA Art.25(1),Perform gap analyses,Compliant,No gap — this gap analysis fulfils the requirement,N/A,N/A,N/A,Compliance Officer DORA Art.25(1),Perform physical security reviews,Partially Compliant,Physical security reviews conducted by Facilities team but not formally integrated into the resilience testing programme,Low,Integrate physical security review results into resilience testing programme reporting,2025-09-30,Security Testing Lead DORA Art.25(1),Perform scenario-based tests,Compliant,No gap — quarterly tabletop exercises and annual simulation exercise conducted,N/A,N/A,N/A,Business Continuity Manager DORA Art.25(1),Perform penetration testing,Compliant,No gap — annual external penetration testing by CyberShield GmbH,N/A,N/A,N/A,Security Testing Lead DORA Art.25(1),Perform source code reviews,Non-Compliant,No formal source code review programme for legacy applications; only new development covered by automated SAST,High,Establish source code review programme covering all critical applications including legacy systems,2025-06-30,AppSec Team Lead DORA Art.26(1),Carry out TLPT at least every 3 years,Non-Compliant,TLPT has not yet been performed; Bank is assessing whether it meets the designation criteria under Article 26(8),High,Complete TLPT designation assessment; if designated begin TLPT planning phase,2025-09-30,CISO DORA Art.26(2),TLPT shall cover critical and important functions,Not Applicable,Pending TLPT designation assessment,N/A,Complete designation assessment first,2025-06-30,CISO DORA Art.26(3),TLPT shall include threat intelligence phase,Not Applicable,Pending TLPT designation assessment,N/A,Complete designation assessment first,2025-06-30,CISO DORA Art.27(1),Testers shall meet requirements for independence and expertise,Partially Compliant,External testers meet independence requirements; internal testing independence not formally attested,Medium,Implement formal tester independence attestation process,2025-03-31,Head of Internal Audit DORA Art.27(2),Use external testers for TLPT,Not Applicable,Pending TLPT designation assessment,N/A,Identify qualified TLPT providers,2025-09-30,CISO DORA Art.27(3),Ensure adequate resources for testing,Partially Compliant,Testing budget adequate for current programme but TLPT budget not yet allocated,Medium,Allocate TLPT budget in 2025 financial plan,2025-03-31,CFO
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
vulnerability_assessment_status — fs-vulnerability-assessment
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
"evidenceClassId": "vulnerability-assessment-report",
"factType": "vulnerability_assessment_status",
"data": {
"assessment_date": "2025-03-15",
"total_vulnerabilities": 89,
"critical_count": 2,
"high_count": 11,
"medium_count": 34,
"low_count": 42,
"remediation_in_progress": true,
"remediated_count": 66,
"next_assessment_date": "2025-06-15"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-03-20T09:00:00Z",
"supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
"evidenceClassId": "penetration-test-report",
"factType": "penetration_test_results",
"data": {
"test_date": "2025-02-14",
"tester_organisation": "CyberShield GmbH",
"findings_count": 18,
"critical_findings": 1,
"high_findings": 3,
"test_passed": false,
"retesting_completed": false,
"remediation_verified": false
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-20T09:00:00Z",
"supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
"factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
"evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
"evidenceClassId": "resilience-testing-programme",
"factType": "basic_testing_coverage_status",
"data": {
"reporting_period_end": "2025-03-31",
"vulnerability_assessments_performed": 4,
"penetration_tests_performed": 1,
"network_assessments_performed": 1,
"gap_analyses_performed": 1,
"source_code_reviews_performed": 2,
"scenario_based_tests_performed": 1,
"all_required_test_types_covered": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-04-05T09:00:00Z",
"supersededBy": null
}
fs-vulnerability-assessmentDORA-Art25-P1assessment_datecritical_count{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"critical_count": {
"minimum": 0,
"type": "integer"
},
"high_count": {
"minimum": 0,
"type": "integer"
},
"low_count": {
"minimum": 0,
"type": "integer"
},
"medium_count": {
"minimum": 0,
"type": "integer"
},
"next_assessment_date": {
"format": "date",
"type": "string"
},
"remediated_count": {
"minimum": 0,
"type": "integer"
},
"remediation_in_progress": {
"type": "boolean"
},
"total_vulnerabilities": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"assessment_date",
"total_vulnerabilities",
"critical_count",
"high_count",
"remediation_in_progress"
],
"type": "object"
}
fs-penetration-test-resultsDORA-Art25-P1test_datecritical_findings{
"properties": {
"critical_findings": {
"minimum": 0,
"type": "integer"
},
"findings_count": {
"minimum": 0,
"type": "integer"
},
"high_findings": {
"minimum": 0,
"type": "integer"
},
"remediation_verified": {
"type": "boolean"
},
"retesting_completed": {
"type": "boolean"
},
"test_date": {
"format": "date",
"type": "string"
},
"test_passed": {
"type": "boolean"
},
"tester_organisation": {
"minLength": 1,
"type": "string"
}
},
"required": [
"test_date",
"tester_organisation",
"findings_count",
"critical_findings",
"test_passed"
],
"type": "object"
}
fs-basic-testing-coverageDORA-Art25-P1reporting_period_endvulnerability_assessments_performedpenetration_tests_performed{
"properties": {
"all_required_test_types_covered": {
"type": "boolean"
},
"gap_analyses_performed": {
"minimum": 0,
"type": "integer"
},
"network_assessments_performed": {
"minimum": 0,
"type": "integer"
},
"penetration_tests_performed": {
"minimum": 0,
"type": "integer"
},
"reporting_period_end": {
"format": "date",
"type": "string"
},
"scenario_based_tests_performed": {
"minimum": 0,
"type": "integer"
},
"source_code_reviews_performed": {
"minimum": 0,
"type": "integer"
},
"vulnerability_assessments_performed": {
"minimum": 0,
"type": "integer"
}
},
"required": [
"reporting_period_end",
"vulnerability_assessments_performed",
"penetration_tests_performed",
"network_assessments_performed"
],
"type": "object"
}