Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

HITGuard Release August 2026

Aus HITGuard User Guide
Diese Seite ist eine übersetzte Version der Seite HITGuard Release August 2026 und die Übersetzung ist zu 100 % abgeschlossen sowie aktuell.

Outlook: Business Continuity Management Add On

We would like to use this opportunity to tell you about our current projects: We are developing a new Business Continuity Management (BCM) Add On for HITGuard. Customer demand for such a module has risen sharply in recent months, particularly following the introduction of the CER Directive (Directive (EU) 2022/2557). While our customers have traditionally used the existing protection needs analysis within risk management and as a BIA for IT-BCM, the focus is now shifting towards a more comprehensive Business Impact Assessment that extends beyond IT resources to encompass a broader range of business-critical assets. the new BCM Add On will include capabilities for documenting workarounds and restart descriptions with workflow support. In addition, documentation options for emergency exercises (from the script to the exercise documentation) are planned. With this release, initial existing customers who have signed up as early-bird customers for the early phase of our product launch will be able to take a closer look at the new features. From autumn onwards, we will showcase the new Add On at trade fairs and events. Licenses can be purchased as of release 20206_R3 (planned for December 2026). If you would like to find out more about the roadmap, please feel free to contact us at support@togethersecure.at.

What's New in Risk Management

New protection targets and model segments

In order to prepare for the introduction of the BCM module mentioned above, we have implemented two changes. First, we have extended the Risk policy to include the protection target MTPD (Maximum Tolerable Period of Disruption). MTPD defines the maximum tolerable downtime and thus complements the existing RTO as a business-critical threshold. The new protection target is available in the protection needs analysis and the structural analysis and can also be evaluated in the structural analysis.


In addition, we have added a further model segment for resources. This model segment is called "Personnel" and allows you to model parts of the workforce as a resource and, where applicable, to assess them with regard to their criticality.

Workflow plans for risks and opportunities

In recent releases we already introduced workflow plans for protection needs analyses and gap analyses. These allow you to plan the reassessments of your reviews in advance and have HITGuard send them out automatically. Execution takes place in the background on a scheduled basis and enables a structured and automated reassessment.
Now there will also be a workflow plan for the risk workflow. This allows you to automatically send the risk to the risk owner or the advisor for reassessment at predefined intervals.


In addition, workflow plans can be managed directly at the risk or the opportunity, and relevant information such as the next reassessment and linked plans can be displayed clearly.

You can find out more about the risk workflow in the online help.

Message to the risk advisor included in the email

In the new risk workflow introduced in the last release, you have the option of entering a message to the advisor when you request a reassessment from them or send the assessment back for revision.


With the new release, HITGuard will include these messages in the email. This allows you to get in touch with your colleagues even more directly and to provide valuable context for your colleagues in the automatic HITGuard emails.


You can find out more about the risk workflow in our online help.

Inclusion of risk categories in risk reports

In order to make communication within the company and reporting on risk management even smoother, we have included the risk categories in the risk reports.

Log entry for the monetary impact of risks

HITGuard already offered the option of recording the monetary impact of risks. Changes to this value may be highly relevant under certain circumstances, but were not logged until now. With the new release, HITGuard will require a justification for the log entry when this value is changed. This makes the monetary impact an important value within the risk, just like status, strategy, probability of occurrence and damage extent.

What's New in Data Protection

Extension of the REST API to query processing activities and more

The REST API has been extended for the data protection module in order to retrieve data subject categories, organisation registers and processing activities (PAs) efficiently. Data subject categories can now be queried MMS-specifically, either in full or selectively by means of their internal HITGuard ID. In addition, the associated organisation registers and the active processing activities they contain can be determined for a data subject category. The new endpoints enable simple integration with third-party systems without having to manage additional external IDs.

What's New in Supplier Management

Linking suppliers and external parties

With this release, the management of suppliers and external parties in data protection has been revised. It is therefore now possible to create and track links between the two entities. The new linking functions in the overview lists make it possible to link existing records or to create missing counterparts.


Intelligent suggestions simplify the assignment of records with similar names and reduce manual effort. All existing links are displayed directly both in the overview and in the detail view, so that you can switch quickly and easily between two linked records. It is also possible to transfer relevant master data between suppliers and external parties. Links can also be deleted at any time if required.


You can find out more about these new functions in the online help.

What's New in Case Management

Transferring elements into the dossier

The assignment of reviews and risks to dossiers has been extended in order to considerably simplify the transfer of linked content. When linking or creating a review or a risk, you can link relevant measures, Controls and risks directly to the dossier. Indirectly linked measures as well as measures that have already been completed are now taken into account as well. This reduces manual effort, prevents relevant information from being overlooked and ensures more complete documentation within the dossier.

What's New in Audit Management

Audit-Gap-Control Matrix

The new Audit-Gap-Control Matrix provides you with a structured overview of audits, reviews, gaps and the associated Controls. In addition, the associated Control is displayed for each gap, together with important information such as frequency, last execution, responsible person and status.


The clear presentation simplifies the tracking of audit findings and supports a more efficient assessment of existing control measures. As usual, the results can also be exported to Excel.

What's New in Document Management

Importing and exporting documents via REST API

In order to make the document management module more versatile and to enable connection to existing solutions, we have extended the REST API interface. It now allows documents to be created and versioned directly in HITGuard. Documents are uniquely identified by an external DOKID and managed within a management system, whereby new versions are updated automatically without overwriting existing content. Storage is structured in directories that are maintained consistently in order to ensure data integrity. This extension considerably improves the traceability and integration of documents from third-party systems.

Extension of the REST API for directories

In the course of the extension of the data interface discussed above, the option was also created to import entire directories from external data sources and transfer them into HITGuard. This allows you to avoid the time-consuming data maintenance that would be required when recreating such directories manually.

What's New in ESG Management

The ESG module has been extended in order to reflect the requirements of the ESRS more effectively. Multiple selection is now possible for the fields "Time horizon" and "Value chain", so that impacts can be assigned more precisely to several time periods and areas.


Existing restrictions to single values are therefore removed entirely. The extended assignments are also displayed correctly in reports. This increases technical accuracy and improves the transparency of the ESG assessment.

Renaming of "Fields of action"

In order to phrase the menu items more precisely and to make it easier for our users to find their way around the system, we have renamed the menu item "ESG topics" to "Fields of action".

Duplicating field of action structures

The duplication function makes it possible to quickly duplicate existing field of action structures (such as the ESRS fields of action), including all links, descriptions and individual adjustments, and to use them for alternative presentations. The function is specifically available for top-level nodes in order to ensure consistent and complete copies. Entire chapter structures can now be copied at the top level and inserted as a new structure. This is ideal for variants or annual updates, reduces manual effort and supports the efficient further development of existing content.

Revision of ESG reports

The ESG reports have been revised visually and structured more clearly in order to make impacts, risks and opportunities easier to grasp. The header data is now presented in a uniform design with subtle colours and clear highlighting. Impacts, risks and opportunities are additionally colour-coded according to their assessment, so that positive, negative and incomplete entries can be identified at a glance.


In addition, impacts are now clearly identified and displayed in a clear order before risks and opportunities. The headings of measures and Controls have also been adapted to the new ESG design and ensure a more consistent appearance of the reports.

General

New menu item for "Master data" and "Administration"

In order to make the structure of the navigation menu more logical and at the same time more intuitive, we have made some fundamental changes to the presentation. This applies in particular to the administration module for expert users, which now has a much clearer structure. Professional users will not see any changes.


First, a separate menu was created for "Master data". This new menu contains seven menu items that were previously located under Administration. As you can see in the screenshot, it includes not only the classic master data representing the organisation and its environment, but also standards and norms and knowledge bases.
The remaining "Administration" menu has been moved to the control bar at the top right.


Apart from this new module, we have removed the former menu item "Updates". This information can now be found under "Licensing" at the bottom left.
In addition, the Risk policy, which was previously located in the "Risk management" module, has been moved here to Administration. This makes it clearer that the Risk policy is likewise a set of settings that affects all management systems.
Finally, the AI prompt management was added, which we discuss in more detail in section ‎9.3.

Generating reports and Management Summary

The export function for reports has been fundamentally revised in order to make report creation more flexible and user-friendly. A central button now opens a configuration dialogue in which the format (PDF, Word), revision information and/or an individual file name can be defined.


In addition, it is now possible to have a Management Summary generated automatically via an AI connection. This Management Summary is then integrated directly into the report.
The prompts that HITGuard uses to create the Management Summaries can be edited in the new AI prompt management (see ‎7.4).
When revision information is used, the Management Summary is also saved in versioned form and remains editable afterwards. These extensions enable more efficient report creation and improve the traceability and individualisation of the results

AI prompt management

The AI prompt management has been newly added to the Administration module. For the first time, it enables centralised configuration for every feature that uses AI prompts. Prompts can now be defined at three levels (global, management-system-specific, user-specific) and are determined automatically via a clear fallback logic.


Users benefit from being able to adjust prompts directly in the context of use and to reset them to the default values at any time if required. In addition, an administration interface has been created in order to control global and system-specific settings in a targeted manner. This improves the consistency of the AI results while at the same time allowing flexible adaptation to individual requirements.

Extension of the design configurations for reports

The configuration options for reports have been extended in order to adapt their appearance more effectively to company-specific requirements. Font, font size, line spacing and scaling for Word exports can now be defined centrally and ensure a uniform layout across the supported reports. Only individual formatting that has been entered directly in HTML fields remains unchanged. This allows you to adapt reports more easily to existing documentation and design standards without having to edit content manually.


Improved presentation of standard mappings

The presentation of standard mappings has been improved in order to make the assignment to different standards easier to grasp. Under Master data > Standards and norms you can now assign tags and mark the standards with colours, which makes mappings clearer and easier to distinguish.


In addition, the assignment of standard chapters has been completely revised with a new, clearly structured linking dialogue. This dialogue displays all activated standards centrally and enables the convenient selection of chapters within a tree structure.


A cross-standard search simplifies the finding of relevant content and automatically hides standards that do not match. Selected chapters are displayed transparently and can be accessed directly, which also makes extensive standards easier to manage.

Attaching documents to processes

Processes can now be supplemented with documents and web links, so that further information and external process descriptions can be stored directly at the respective process. This simplifies in particular the linking of documentation from third-party applications and improves the traceability of process information.
Attached documents are also automatically included in the document archive and can be processed further in the document management add-on. This makes process-relevant documents available centrally and consistently.