1. Demo Company
Newest BIA edit 18 May 2026
76/ 100 · Developing
Resilience completeness, the same six-lever score the scorecard computes from your live analyses. Click for the full breakdown.
Resilience Command Centre

1. Demo Company

One live read across risk, controls, remediation, compliance, incidents, continuity and exercising. Every number on this page is computed from the connector at render time, states its own source, and clicks through to the records behind it.

i
5
BIA analyses
i
28
Risks on register
i
13
Open incidents
i
23
Actions overdue
RAiDAR AI · Executive read

Across 5 business impact analyses covering 30 key processes, 28 risks on the register, 47 controls, 1. Demo Company scores 76 out of 100 on resilience completeness, which places the programme in developing territory on the evidence recorded today. The single biggest exposure is concentration: 24 single points of failure sit under Tier 1 processes with no recorded workaround, and any one of them failing would carry a critical BIA past its own tolerance. On the risk side, 5 residual ratings sit at high or extreme even after controls are counted.

Synthesised at render time from the live risk, control, action, incident and continuity registers. Nothing in this paragraph is seeded or cached.
Open detailed view

Two minutes on posture ?

Residual risk heatmap ?

list-risks · residual consequence and likelihood
Insig.
Minor
Moderate
Major
Extreme
Almost certain
·
·
3
1
·
Likely
·
2
4
·
1
Possible
·
3
3
1
·
Unlikely
·
1
2
1
·
Rare
1
·
·
·
1

Key process criticality mix ?

list-bias · every process across the analyses

Single points of failure ?

list-bias · total reliance, no workaround
24
single points of failure, no workaround
Worst: Payment System

Hottest risks against their strongest control ?

list-risks joined to list-controls

Incident trend with severity ?

list-v3-incidents · logged, identified or occurred date

Overdue remediation ?

list-action-plans · due month, last 12 months

Six-lever resilience mix ?

the scorecard's own six levers

What changed lately ?

updated, logged and game dates across the registers, last 90 days
  • 20 July 2026Fire dire broke incident logged
  • 20 May 2026May - Crisis Management Exercise exercise run
  • 18 May 2026Customer Engagement analysis updated
  • 13 May 2026IT Services analysis updated
  • 13 May 2026Deposit Services analysis updated
  • 13 May 2026Asset Management analysis updated

Control assurance mix ?

list-controls · overall evaluation across the library

Module links at a glance ?

deduplicated record pairs
RisksCtrlsActionsIncid.Proc/BIAAppsSuppl.
Risks-84121466238
Ctrls84-513-3234
Actions1251-2---
Incid.132-211913
Proc/BIA46--21-3929
Apps6232-1939--
Suppl.3834-1329--

Supplier concentration ?

list-bias · BIAs per supplier, red is a SPOF
30
Key processes
Internal work that delivers the BIAs above, never the BIAs themselves. 30 carry a criticality tier.
47
Controls
24 sit at weak or marginal on their own overall evaluation, so the assurance under some ratings is thin.
18
Suppliers
8 are named as external dependencies in the analyses, so the rest are on the register but mapped to no BIA yet.
8
Exercises run
From 8 workshops in the programme, counting a run as a game date in the past. The spark shows cadence by quarter.
14
Continuity plans
5 are anchored to a business impact analysis, and a plan without that anchor recovers a guess rather than a measured process.
51
Requirements tracked
51 still await approval, and an unapproved requirement is an obligation nobody has signed off as met.

How the estate connects ?

Linkage coverage, weakest joins first ?

55% average across 11 measured joins
Applications with an RTO0 of 30 · 0%
Counts distinct applications named in the analyses that carry an it_app_rto_target on at least one row, and the wrong side has no recovery target anywhere. Click to list the 30 records on the wrong side.
Tier 1 BIAs exercised at least once0 of 3 · 0%
Counts Tier 1 BIAs whose name appears in the title, description or injects of at least one exercise. This is a name match, so treat it as indicative rather than audited. Click to list the 3 records on the wrong side.
Compliance requirements linked to a control8 of 51 · 16%
Counts compliance requirements whose linked controls list is populated, and the wrong side is every obligation the estate currently satisfies by assertion alone. Click to list the 43 records on the wrong side.
Continuity plans linked to a BIA5 of 14 · 36%
Counts response plans on list-plans carrying at least one related BIA guid, and the wrong side is every plan not anchored to a measured analysis. Click to list the 9 records on the wrong side.
Suppliers supporting at least one BIA8 of 18 · 44%
Counts providers on list-service-providers whose name also appears as an external dependency in at least one analysis, matched by name, and the wrong side is named in none. Click to list the 10 records on the wrong side.
High or extreme risks with a strong control3 of 5 · 60%
Counts risks rated high or extreme residual whose best linked control scores strong on the overall evaluation, and the wrong side is every elevated risk without one. Click to list the 2 records on the wrong side.
So-what chain of the day
Reputation Damage

Reputation Damage runs through Comm Biz into Tier 1 IT Services with only a partial control in the way. The Chains view walks every step of it, scored, explained and clickable, together with the seven chains behind it.

Unlinked records ?

zero links, all registers
91

Next best actions

ranked by impact on the completeness score and open exposure
  1. 1
    Set recovery targets on 30 applications
    Lifts the recovery lever from 0 per cent and is the largest single gain available on the completeness score.
  2. 2
    Record workarounds for 24 Tier 1 single points of failure
    Starting with Payment System, each recorded alternate removes a concentration a regulator will otherwise probe.
  3. 3
    Close or re-date 23 overdue action plans
    Every plan past its own due date is remediation the register says was promised and has not landed.
  4. 4
    Re-evaluate 31 controls not tested in 12 months
    An evaluation older than a year is stale assurance, and these are the controls your residual ratings quietly depend on.
  5. 5
    Refresh 1 analyses older than a year
    Stale analyses degrade every downstream figure on this page, and a refresh is discipline rather than spend.
Biggest risk right now

Payment System Application · single point of failure

This application underpins 4 Tier 1 processes across 5 BIAs, and not one of those links carries a recorded workaround or alternate. A single failure here would cascade through the most time-critical work the organisation does, and on the recorded tolerances the breach would begin before most response teams had finished assembling. Recording a workaround or standing up an alternate is the single cheapest resilience gain on this page, because it converts a concentration risk into a managed dependency without touching the risk register at all.

Resilience watchlist

auto-ranked from SPOFs, no-workaround reliance and tier · list-bias
BIATierSPOFsNo workaroundExposure
GovernanceTier 11013
IT ServicesTier 1710
Deposit ServicesTier 188
Customer EngagementTier 2312
Asset ManagementTier 227

Connections and linkages

55%LINKAGE HEALTH

Across 11 measured joins the linkage estate averages 55%, with applications with an rto the thinnest at 0%, and that join matters because an application without a recovery target cannot be tested against the MTPD of the BIAs running on it.

The Insights feed currently proves 61 findings from the joins alone, including 4 rated critical, and every one carries the record chain, the consequence and the action that closes it.

2026 © Battleground Group Pty Ltd · Master Dashboard · 2026.07.24Support