← Expertise

DORA

DORA — the Digital Operational Resilience Act — sets EU-wide rules for how financial entities manage ICT and cyber risk, so the sector can withstand and recover from digital disruptions.

The essentials

What DORA requires

DORA brings ICT risk, incident reporting, resilience testing and third-party oversight under one harmonised framework for banks, insurers, investment firms and many of their providers.

ICT risk management

A governance framework for identifying, protecting against and recovering from ICT risk.

Incident reporting

Classify and report major ICT-related incidents within the required timelines.

Third-party oversight

Map and manage critical ICT providers, with the right contractual safeguards.

How we help

Resilience you can evidence

We help financial entities and their providers meet DORA without duplicating what they already do well.

01

Gap analysis

We benchmark your ICT risk and contracts against DORA.

02

Remediation

Policies, registers and contract updates to close the gaps.

03

Testing & reporting

Resilience testing and incident-reporting processes that hold up.

Questions & answers

Does DORA apply to us?

It applies to most regulated financial entities and many of their ICT providers. We help you confirm scope.

How does DORA relate to NIS2?

They overlap on cyber resilience; DORA is the sector-specific regime for finance and generally takes precedence there.

What about our cloud providers?

Critical ICT third parties are squarely in scope, including contractual and oversight requirements.