Crypto Agility & AI Security Assessment

Demonstration Posture Report

Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.

Enterprise scope & evidence coverage

Scenario / customer scope
Banking · Production
Accounts / organizational units
1,000 / 25
Regions observed
4
Evidence model
Synthetic / provenance simulated

Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.

61
Elevated
Enterprise posture score / 100
250,000
Systems assessed
189,503
Security findings
504,006
Evidence & audit events
42,900
HNDL-exposed systems
2,284
Migrations blocked
6.0%
PQC-ready systems
10
Business units

Findings by severity

Critical 12598
High 120743
Medium 56162

Cryptographic estate

ECC P-256 50098
RSA-2048 39989
AES-256 32371
RSA-3072 30211
ECC P-384 29859
AES-128 20058

Top risk signals

Click a signal to filter the finding explorer below.

HNDL exposure42900
PQC migration required42900
Certificate expires <90d18451
Certificate expires <30d16179
Missing asset owner13906
HSM capability gap12982
Weak RSA key9972
Key rotation overdue8627
Missing evidence6271
SHA-1 usage4964

Systems by business unit

Click a business unit to filter the finding explorer below.

Payments25245
Data & Analytics25233
Security25193
Cloud Infrastructure25063
Digital Channels25042
Corporate IT24987
Customer Platforms24946
Insurance24873

GenAI & Internal LLM Risk Assessments

AI risk by severity

Critical 1688
High 24621
Moderate 124410
Low 201637

AI risk profile

500,000
AI assessments
422
Critical
8,207
High

Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.

Top AI risk signals

Click a signal to filter the unified Finding Explorer to AI Risk.

GenAI exposure: Sensitive data to model125140
Internal LLM misuse: Sensitive internal prompt56690
GenAI exposure: Unapproved external model45296
Internal LLM misuse: Unapproved model or endpoint34963
GenAI exposure: Shadow AI use30141
Internal LLM misuse: Excessive data access24744
Internal LLM misuse: Policy bypass behavior20193
GenAI exposure: Prompt exfiltration signal15189

AI risk by business unit

Click a business unit to filter the unified Finding Explorer to AI Risk.

Security35574
Cloud Infrastructure35571
Data & Analytics35546
Digital Channels35469
Payments35458
Corporate IT35425
Insurance35241
Customer Platforms34944
Wealth & Markets34775
Retail Banking34353

C-level summary

Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.

Finding Explorer

One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.

DomainSeveritySignalSystemBusiness unitRecommended action
CryptographyMediumWeak RSA keyVendor-Integration-00001Digital ChannelsMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighHSM capability gapHSM-Service-00002Digital ChannelsUpgrade/configure HSM before migration.
CryptographyHighHNDL exposureIdentity-Platform-00003Customer PlatformsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredIdentity-Platform-00003Customer PlatformsSelect approved hybrid target and schedule migration.
CryptographyMediumCertificate expires <90dIdentity-Platform-00003Customer PlatformsSchedule rotation.
CryptographyHighHNDL exposureAPI-Gateway-00005PaymentsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredAPI-Gateway-00005PaymentsSelect approved hybrid target and schedule migration.
CryptographyHighKey rotation overdueAPI-Gateway-00005PaymentsRotate key and capture evidence.
CryptographyHighHNDL exposureBackup-Platform-00006Cloud InfrastructurePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredBackup-Platform-00006Cloud InfrastructureSelect approved hybrid target and schedule migration.
CryptographyMediumWeak RSA keyBackup-Platform-00006Cloud InfrastructureMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighHSM capability gapCertificate-Authority-00007Data & AnalyticsUpgrade/configure HSM before migration.
CryptographyHighHNDL exposureAnalytics-Lake-00008Customer PlatformsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredAnalytics-Lake-00008Customer PlatformsSelect approved hybrid target and schedule migration.
CryptographyHighKey rotation overdueAnalytics-Lake-00008Customer PlatformsRotate key and capture evidence.
CryptographyHighHNDL exposureIdentity-Platform-00010Corporate ITPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredIdentity-Platform-00010Corporate ITSelect approved hybrid target and schedule migration.
CryptographyHighPolicy violationVendor-Integration-00011Digital ChannelsReplace primitive and validate dependent applications.
CryptographyCriticalHNDL exposureCustomer-Portal-00013Digital ChannelsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCustomer-Portal-00013Digital ChannelsSelect approved hybrid target and schedule migration.
CryptographyHighKey rotation overdueCustomer-Portal-00013Digital ChannelsRotate key and capture evidence.
CryptographyMediumMissing evidenceCustomer-Portal-00013Digital ChannelsCollect and seal evidence snapshot.
CryptographyHighKey rotation overdueIdentity-Platform-00018Digital ChannelsRotate key and capture evidence.
CryptographyMediumWeak RSA keyBackup-Platform-00020SecurityMove to approved stronger or hybrid profile during lifecycle work.
CryptographyMediumMissing asset ownerBackup-Platform-00020SecurityAssign an owner and establish review cadence.
CryptographyMediumWeak RSA keyKubernetes-Cluster-00021SecurityMove to approved stronger or hybrid profile during lifecycle work.
CryptographyMediumMissing asset ownerHSM-Service-00023InsuranceAssign an owner and establish review cadence.
CryptographyMediumMissing evidenceHSM-Service-00023InsuranceCollect and seal evidence snapshot.
CryptographyMediumMissing asset ownerAnalytics-Lake-00024Digital ChannelsAssign an owner and establish review cadence.
CryptographyHighHSM capability gapHSM-Service-00026Corporate ITUpgrade/configure HSM before migration.
CryptographyHighHNDL exposureMainframe-00027InsurancePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredMainframe-00027InsuranceSelect approved hybrid target and schedule migration.
CryptographyMediumCertificate expires <90dCustomer-Portal-00028Cloud InfrastructureSchedule rotation.
CryptographyMediumMissing evidenceCustomer-Portal-00028Cloud InfrastructureCollect and seal evidence snapshot.
CryptographyHighHNDL exposureData-Warehouse-00029PaymentsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredData-Warehouse-00029PaymentsSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureData-Warehouse-00031PaymentsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredData-Warehouse-00031PaymentsSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dKubernetes-Cluster-00033PaymentsRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureCI/CD-Platform-00034Digital ChannelsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCI/CD-Platform-00034Digital ChannelsSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureCI/CD-Platform-00037Retail BankingPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCI/CD-Platform-00037Retail BankingSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureCI/CD-Platform-00038Digital ChannelsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCI/CD-Platform-00038Digital ChannelsSelect approved hybrid target and schedule migration.
CryptographyMediumMissing asset ownerCI/CD-Platform-00038Digital ChannelsAssign an owner and establish review cadence.
CryptographyHighCertificate expires <30dCI/CD-Platform-00038Digital ChannelsRotate certificate and validate dependent chains.
CryptographyHighHSM capability gapHSM-Service-00044Data & AnalyticsUpgrade/configure HSM before migration.
CryptographyMediumCertificate expires <90dMainframe-00045Data & AnalyticsSchedule rotation.
CryptographyMediumMissing asset ownerPayment-Service-00049SecurityAssign an owner and establish review cadence.

How to read this report

Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.

Evidence model

begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.

Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally