The cost of a threat and risk analysis for a savings bank varies considerably and depends on factors such as the size of the institution, the complexity of its IT infrastructure, the number of locations, and the desired level of detail. It typically covers fees for external experts, data collection, the risk analysis itself, and the creation of a tailored security concept.

Strategic planning and cost optimisation for financial institutions

The security of savings banks is complex and requires a well-founded threat and risk analysis. Learn how to make costs transparent while guaranteeing the highest security standards.

Key Takeaways

  • A threat and risk analysis is a strategic investment for savings banks that goes beyond legal obligation, preventing damage in the long term and securing operational continuity.
  • The cost of a threat and risk analysis is largely determined by the institution's complexity, the level of detail required, and the expertise of the consultants involved, but it can be optimised through targeted planning.
  • Commissioning a manufacturer-independent planning and consulting firm like PLANATEL® ensures objective, needs-based solutions and prevents dependency on a single manufacturer, leading to an efficient cost-benefit ratio.

Financial institutions such as savings banks face the challenge of guaranteeing the highest level of security, both physically and digitally. The threat landscape is evolving rapidly, ranging from cyberattacks to physical robberies. A professional threat and risk analysis is the foundation of any effective security strategy. It identifies vulnerabilities and risks before they become existential problems. But what costs are associated with such an analysis, and how can this investment be managed optimally? This article examines the decisive factors and offers decision-makers at savings banks well-founded guidance.

Article image: Threat and Risk Analysis Cost for Savings Banks - hero

Carrying out a threat and risk analysis is, for financial institutions such as savings banks, not merely an option but a fundamental necessity that extends far beyond simply meeting statutory requirements. The specific role of savings banks as regional financial services providers, which often see high customer footfall and cash transactions, makes them a potential target for criminal activity. This ranges from physical robberies to complex cyberattacks aimed at sensitive customer data or the integrity of financial systems. A comprehensive analysis serves to systematically identify and assess these varied threats.

The dynamic nature of the threat landscape requires the continuous adaptation of security strategies. What was considered sufficient yesterday may already be a critical vulnerability today. A threat and risk analysis provides the necessary framework to act proactively rather than merely reacting once damage has occurred. It enables management to make well-founded decisions on allocating resources for security systems. This includes the planning of fire alarm systems (BMA) to DIN 14675 and VdS 2095, intrusion detection systems (EMA), video surveillance systems and access control systems, tailored to the specific risk profile of each location. Without such an analysis, investment in security systems tends to remain reactive and inefficient, since it may not address the most critical risks.

Furthermore, a savings bank's reputation is closely tied to its ability to guarantee the security of customer funds and data. A security incident can result not only in financial losses but also in a significant loss of trust among customers and the public. The cost of restoring trust and repairing reputational damage often exceeds the direct cost of the incident itself. A threat and risk analysis is thus a preventive measure that secures the institution's long-term success and stability. It is a strategic instrument for strengthening resilience against external and internal threats and for safeguarding operational continuity.

Components and phases of a comprehensive threat and risk analysis

A well-founded threat and risk analysis for a savings bank is a multi-stage process comprising several core components, undertaken to obtain a holistic picture of the security situation. The process typically begins with a detailed as-is survey. Here, all relevant physical and digital assets of the institution are captured, including buildings, IT infrastructure, data holdings, staffing structures and existing security systems such as fire alarm systems, intrusion detection systems and access control systems. Organisational processes and policies relevant to security are also documented.

The second phase is the threat analysis. In this step, potential threats that could affect the previously captured assets are identified. This covers a broad range of scenarios: from natural disasters and technical failures to criminal acts (burglary, robbery, fraud) and cyberattacks (malware, phishing, DDoS attacks). For each identified threat, the probability of occurrence and the potential scale of damage are assessed. Internal threats, such as human error or deliberate acts by staff, are also taken into account here.

This is followed by the vulnerability analysis. Here, existing security systems and processes are critically examined to uncover gaps or shortcomings that the identified threats could exploit. This may include reviewing the compliance of fire alarm systems with DIN 14675 and VdS 2095, the effectiveness of video surveillance systems, or the robustness of the IT security architecture. The analysis assesses how well the current measures are suited to mitigating the identified risks.

The results of these analyses feed into a risk assessment. Here, the identified risks are prioritised based on their probability of occurrence and potential scale of damage. This makes it possible to identify the most critical risks requiring immediate action. Finally, a security concept is developed, containing concrete recommendations for technical, organisational and personnel measures to minimise risk. This may include planning new systems or optimising existing ones, adjusting processes, or training staff. Detailed planning of the proposed system technology is a central component of this.

Cost factors of a threat and risk analysis: what influences the price?

The cost of a threat and risk analysis at a savings bank is not a fixed figure, but is shaped by a range of factors. A major driver is the size and complexity of the institution. A small branch with few staff and a manageable IT infrastructure requires a lower analytical effort than a head office with several hundred employees, complex data centres and numerous specialist departments. The number of locations also plays a role; an analysis for an institution with ten branches involves more effort than one with only two.

Another decisive factor is the level of detail of the analysis. Is only a broad overview of the main risks required, or is an in-depth examination of every individual vulnerability desired, including penetration tests for IT systems or detailed site walkthroughs to assess physical security? The more granular the analysis, the greater the time required and thus the cost. Including specific risk areas, such as an analysis of ATM security or an assessment of cash logistics processes, can further increase the scope and cost.

The qualifications and experience of the commissioned experts also affect cost. Highly specialised consultants with many years of experience in the financial sector and comprehensive knowledge of relevant standards such as BaFin, VdS 2095 or DIN 14675 typically charge higher fees. This is, however, often a worthwhile investment, as their expertise ensures more precise risk identification and more effective solutions. The fee structure may be agreed on an hourly basis, as a fixed fee for defined project phases, or as a fixed price for the entire scope of services.

Additional costs may arise from producing specific documentation and reports, particularly where these are required for internal audits, external reviews, or submission to supervisory authorities such as BaFin. Integrating findings into existing risk management systems, or providing support during the implementation of measures, can also broaden the scope of services and thus the overall cost. A study from 2024 shows that financial institutions in Germany spend, on average, between 0.5% and 1.5% of their annual revenue on IT security and physical security systems, with a significant portion allocated to planning and analysis.

Article image: Threat and Risk Analysis Cost for Savings Banks - mid

Cost-benefit analysis: the return on investment in security

Consideration of the cost of a threat and risk analysis for a savings bank must not be viewed in isolation, but must always be seen in the context of the potential benefit and the return on investment (ROI). At first glance, the fees for external experts and the internal resource effort may appear to be a considerable expense. Yet this investment typically pays for itself by avoiding or minimising damage that could result from security incidents. A successful cyberattack or a physical robbery can cause not only direct financial losses running into the millions, but also long-term effects on reputation, customer trust and operational capability.

The benefit of a threat and risk analysis manifests itself across several dimensions. First, it enables the targeted and efficient allocation of security budgets. Rather than investing in generic or possibly oversized security systems, funds are deployed where the greatest risks exist. This leads to optimised spending on fire alarm systems, intrusion detection systems, video surveillance and access control, since only the components and systems that are actually required are planned and implemented. Second, the analysis contributes to compliance with statutory and regulatory requirements, in particular BaFin circulars such as BAIT. Avoiding fines and sanctions from supervisory authorities represents a direct financial benefit.

Third, a well-founded threat and risk analysis improves the savings bank's operational continuity and resilience. By identifying and mitigating risks, downtime is minimised and the institution's ability to maintain operations even under adverse circumstances is strengthened. This safeguards not only revenue but also service quality for customers. Fourth, it strengthens customer and partner trust. A proactive security strategy signals a sense of responsibility and professionalism, which has a positive effect on image and competitiveness. The cost of planning a complex fire alarm system to DIN 14675 and VdS 2095 can range between EUR 15,000 and EUR 150,000 depending on building size and risk profile, an investment that is modest compared with the potential damage caused by a fire.

In summary, the cost of a threat and risk analysis represents an investment in the future security and long-term success of a savings bank. The ROI arises from avoiding damage, optimising security spending, complying with regulations and strengthening trust. Independent consulting, such as that offered by PLANATEL®, can help maximise this ROI by developing manufacturer-independent, needs-based solutions.

For savings banks, legal compliance and adherence to established standards in the field of security are of critical importance. These frameworks form the basis for every threat and risk analysis and the security concepts derived from it. The Federal Financial Supervisory Authority (BaFin) plays a central role here. Through its circulars, in particular the Supervisory Requirements for IT in Financial Institutions (BAIT), it defines detailed requirements for the IT security and risk management of financial institutions. These requirements cover, among other things, the management of information security risks, contingency management and the governance of outsourcing arrangements. A threat and risk analysis must explicitly take these BaFin requirements into account and demonstrate how the savings bank achieves the required protection objectives.

In addition to BaFin's regulatory requirements, technical standards and guidelines are decisive for the planning and operation of security systems. For fire alarm systems (BMA), DIN 14675 and VdS 2095 are of central importance. DIN 14675 governs the structure and operation of fire alarm systems and sets out the requirements for planning, design, installation, commissioning, acceptance and servicing. VdS 2095, issued by VdS Schadenverhütung, supplements these standards and offers detailed guidelines for the planning and installation of fire alarm systems, which often go beyond the minimum requirements of the DIN standard and are required by insurers. Compliance with these standards is decisive not only for the functionality of the systems, but also for recognition by insurers and in the event of a claim.

For further hazard warning systems such as intrusion detection systems (EMA) or video surveillance systems, the DIN VDE 0833 series and specific VdS guidelines (e.g. VdS 2311 for EMA) are relevant. These standards define technical requirements for components, installation and operation to ensure a high level of reliability and effectiveness of the systems. A threat and risk analysis must therefore not only identify risks, but also ensure that the proposed technical solutions comply with these established standards. PLANATEL®'s expertise in planning fire alarm systems to DIN 14675 and VdS 2095, as well as other hazard warning systems, ensures that the concepts developed are always legally compliant and reflect the current state of the art.

Strategies for cost optimisation in the threat and risk analysis

The cost of a threat and risk analysis is an investment that can nonetheless be optimised through strategic approaches, without compromising the quality or level of detail of the results. One of the most effective strategies is the clear definition of the analysis scope in advance. Precisely determining which areas, systems and locations should be examined, and in what depth, prevents unnecessary effort and focuses resources on the most critical aspects. A detailed needs assessment before the actual threat and risk analysis begins can help make the scope realistic and targeted.

The use of existing internal resources and documentation can also help reduce costs. Savings banks often have internal IT security experts, risk managers, or facility managers who can provide valuable information and insight. Good preparation, including the provision of relevant documents such as existing security concepts, contingency plans, IT architecture plans, or maintenance logs for fire alarm systems, reduces the research effort required from external consultants. This speeds up the process and lowers fee costs.

Carrying out the analysis in phases is another way to control costs. Rather than conducting a comprehensive analysis of all areas simultaneously, one can initially concentrate on the most critical areas and use the results to plan subsequent phases. This allows for more flexible budgeting and the opportunity to learn from initial findings and adjust the approach for subsequent phases. For example, an analysis of the core IT systems and the main branch could be conducted first, before other locations or less critical areas are considered.

Finally, the selection of an independent and experienced consulting firm is decisive for cost optimisation. A manufacturer-independent partner such as PLANATEL® has no interest in selling particular products or solutions, but focuses exclusively on developing the security strategy that is optimal and most cost-efficient for the savings bank. This prevents misguided investment in overpriced or unsuitable systems and ensures that the proposed measures genuinely meet the need and remain viable in the long term. HOAI fee bands under §56 can serve as a point of reference for assessing planning services, even though the HOAI has no longer been binding since 2021.

The role of independent planning and consulting: manufacturer-independence as an advantage

When carrying out a threat and risk analysis and subsequently developing a security concept for a savings bank, choosing the right partner is of decisive importance. Here, manufacturer-independence plays a central role. An independent planning and consulting firm such as PLANATEL® operates without any financial ties to manufacturers of security systems or IT solutions. This ensures that recommendations and plans serve solely the interests of the savings bank and are not influenced by sales targets or commissions.

The advantage of manufacturer-independence is obvious: the savings bank receives an objective assessment of its security situation and tailored solution proposals that are optimally suited to its specific needs and risk profile. There is no attempt to unnecessarily replace existing systems or push oversized new investments. Instead, the focus is on the efficient use of existing resources and the integration of new components that genuinely add value. This may include the planning of fire alarm systems to DIN 14675 and VdS 2095, the optimisation of video surveillance, or the design of access control systems, always with a view to finding the best technical and economic solution.

As an independent partner, PLANATEL® brings over 34 years of experience in planning and consulting for complex infrastructures. This long-standing expertise, combined with a deep knowledge of BaFin's regulatory requirements and technical standards such as DIN and VdS, makes it possible to develop well-founded and future-proof concepts even for complex threat situations. We plan servicing concepts and select certified installers, without carrying out installations or servicing ourselves. This ensures that the savings bank does not become dependent on a single manufacturer, but retains the freedom to select the best providers to implement the planned measures.

PLANATEL®'s independence also means that we can focus on optimising costs and processes. A detailed tender and award process for the planned systems fosters fair competition among providers, resulting in transparent pricing and high implementation quality. The savings bank's management can rely on the fact that the security concepts developed are not only technically excellent, but also economically optimal.

Common mistakes and best practices in implementation

When carrying out a threat and risk analysis and implementing the resulting security measures, savings banks can make various mistakes that impair effectiveness and cost-efficiency. A common mistake is the insufficient involvement of relevant stakeholders. Security is a cross-cutting task that affects every department, from IT and facility management to senior management. If the analysis is carried out in isolation, important perspectives are missing and acceptance of the subsequent measures suffers. Best practice here is early and continuous communication, together with the formation of an interdisciplinary project team.

Another mistake is neglecting to keep the analysis up to date. A threat and risk analysis is not a one-off task, but an ongoing process. The threat landscape, technology and a savings bank's internal processes are constantly evolving. An analysis carried out five years ago may no longer be relevant today. Best practice is to establish regular review cycles, ideally every two to three years, or whenever there are significant changes to infrastructure or business processes. This ensures that the security concept always reflects current circumstances.

It is also often a mistake to focus exclusively on technical solutions while neglecting organisational and personnel aspects. Even the most modern fire alarm systems or video surveillance systems are only as effective as the people operating them and the processes supporting them. Inadequate staff training, unclear responsibilities, or missing contingency plans can undermine the best technical precautions. Best practice is a holistic approach that gives equal consideration to technical systems, organisational procedures, and staff awareness and training.

Finally, a lack of documentation and traceability is a critical issue. Without detailed documentation of the analysis findings, the decisions taken and the measures implemented, it is difficult to demonstrate legal compliance, pass audits, or make future adjustments. Best practice is complete and comprehensible documentation covering every phase of the threat and risk analysis and the security concept. PLANATEL® places great importance on transparent and traceable documentation that serves savings banks as a reliable basis for their security strategy.

Article image: Threat and Risk Analysis Cost for Savings Banks - bottom

Next step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de

Frequently asked questions

What is the difference between a threat and risk analysis and a security concept?

A threat and risk analysis is the process of identifying, assessing and prioritising potential threats and vulnerabilities. It delivers a detailed overview of the risk situation. A security concept, by contrast, is the outcome of this analysis: it is a plan proposing concrete technical, organisational and personnel measures to mitigate the identified risks, describing their implementation in detail. The analysis is the foundation; the concept is the resulting course of action.

What role does the size of a savings bank play in the cost of the analysis?

The size of a savings bank is a key cost factor. A larger institution with more branches, a more complex IT infrastructure and a higher headcount requires a significantly greater analytical effort. This is reflected in a larger scope of data collection, more site visits, and a more extensive risk assessment, which increases the fees for external consultants and the consumption of internal resources.

How often should a threat and risk analysis be carried out?

A threat and risk analysis should not be regarded as a one-off project. It is recommended that it be updated regularly, ideally every two to three years. In addition, a renewed analysis is strongly advisable following significant changes to IT infrastructure, business processes, building structure, or the threat situation (for example, after a major security incident) to ensure the continued relevance and effectiveness of the security concept.

What qualifications should an external consultant bring to a threat and risk analysis?

An external consultant should bring comprehensive expertise in IT security, physical security systems and risk management. Industry knowledge of the financial sector is also important, to understand BaFin's specific regulatory requirements and the particularities of savings banks. Certifications and demonstrable experience in planning fire alarm systems to DIN 14675 or VdS 2095 are also an advantage. Manufacturer-independence is decisive for objective results.

Which areas does a threat and risk analysis cover for a savings bank?

A comprehensive threat and risk analysis for a savings bank typically covers both physical and digital security areas. This includes assessing building security (access control, video surveillance, fire alarm systems, intrusion detection systems), IT infrastructure (networks, servers, applications, data), organisational processes (contingency management, access rights), personnel (training, awareness), and compliance with relevant statutory and regulatory requirements such as BaFin's BAIT.

How can PLANATEL® support savings banks with a threat and risk analysis?

PLANATEL® supports savings banks as an independent planning and consulting firm in carrying out threat and risk analyses. We offer a manufacturer-independent as-is survey, threat and vulnerability analysis, and the development of tailored security concepts. Our more than 34 years of experience and expertise in planning fire alarm systems to DIN 14675, intrusion detection systems and other security systems ensure legally compliant, economically optimised solutions tailored to your savings bank's specific needs.

Why is a threat and risk analysis essential for savings banks?

A threat and risk analysis is essential for savings banks to protect against the dynamic threat landscape, ranging from cyberattacks to physical robberies. It proactively identifies vulnerabilities, protects sensitive customer data, and ensures legal compliance with BaFin requirements. It also safeguards the reputation and operational continuity of the financial institution.

What statutory requirements must savings banks observe regarding security?

Savings banks must primarily observe the requirements of the Federal Financial Supervisory Authority (BaFin), in particular the Supervisory Requirements for IT in Financial Institutions (BAIT). These define standards for IT security and risk management. For technical systems, standards such as DIN 14675 and VdS 2095 for fire alarm systems, as well as DIN VDE 0833 for hazard warning systems, are also relevant.

How long does a threat and risk analysis typically take?

The duration of a threat and risk analysis depends heavily on the size and complexity of the savings bank as well as the desired level of detail. For a single branch, it may take a few weeks, while a comprehensive analysis for a large institution with multiple locations and a complex IT infrastructure can take several months.

Can a threat and risk analysis save costs?

Yes, a threat and risk analysis can save costs in the long term. By precisely identifying risks, it enables targeted, efficient investment in security systems, avoids misguided investment, and minimises the risk of costly security incidents that could lead to financial losses and reputational damage.

Sources and further information

  • Risikoklassifizierung – Sparkassen Rating und Risikosysteme GmbH
  • Mindestanforderungen an das Risikomanagement Interpretationsleitfaden – Stiftung für die Wissenschaft
  • Risikomanagement im Unternehmen | Sparkasse.de
  • Risikomanagement für Ihren Versicherungsschutz | Sparkasse Bad Hersfeld-Rotenburg
  • Arbeitssicherheit in Kassen und Zahlstellen der öffentlichen Hand – Kommunale Unfallversicherung Bayern