Governance
Tycho Engineering
Client
Q3 2026
Quarter
View Client Presentation
QBR Dashboard: Internal Review
Watchlist

9 items to raise in the meeting

Removable Media Policy

Policy

Review was due 06 Jan 2026 and has not been completed.

Remote Working Security Policy

Policy

Review was due 06 Dec 2025 and has not been completed.

Ransomware Attack

Risk

Residual score 20 remains high while open.

Unpatched Operating Systems

Risk

Residual score 16 remains high while open.

Phishing and Social Engineering

Risk

Residual score 15 remains high while open.

Insider data exfiltration

Incident

Reported 01 Jul 2026: Investigating (High severity).

GDPR subject access request breach

Incident

Reported 18 Jun 2026: Contained (High severity).

Patch deployment failure exposes vulnerability

Incident

Reported 13 Jul 2026: Open (Medium severity).

Unauthorised remote access attempt

Incident

Reported 03 Jun 2026: Contained (Medium severity).

Compliance

34% overall compliance rate (20 compliant / 19 partial / 0 non-compliant / 19 unknown of 58 requirements)

▼ 32pts vs Q1 2026

Evidence coverage 48% · Source alignment 39%
Policy Coverage

65% coverage (13 of 20 policies covered: 2 overdue, 2 missing)

▲ 3pts vs Q1 2026

55% of policies are within their review cycle (11 of 20)

Reviewed in Q3 2026 (0)

Risk Posture

19 open risks of 27 total (3 high residual, avg residual score: 7.6)

▲ 12 vs Q1 2026

Reviewed in Q3 2026 (0)

Incident History

2 open of 5 total (2 critical/high severity, 1 closed)

▼ 3 vs Q1 2026

Reported in Q3 2026 (2)

Patch deployment failure exposes vulnerability

reported 13 Jul 2026: Medium severity

Open

Insider data exfiltration

reported 01 Jul 2026: High severity

Investigating
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.