Resilience
you can prove.
DORA requires financial entities to document ICT risk management, report incidents, test resilience and keep a complete register of all ICT third parties. We prepare those four mandatory areas so they withstand review by BaFin or your supervisory authority — from the service provider’s perspective as well.
What is included.
For financial entities and their ICT service providers.
ICT risk management
Framework, roles, management-body accountability, asset and dependency inventory, business impact analysis.
Incident reporting
Classification against the thresholds, notification deadlines, notification paths, templates for initial, intermediate and final reports.
Resilience testing
A testing programme under Art. 24–27: scope, frequency, scenarios; and a judgement on whether threat-led penetration testing (TLPT) applies.
Third-party register
The Art. 28 register with the required fields, contract review against Art. 30, and an exit strategy per critical function.
Secureskies does not provide legal advice. The mapping to articles is our technical reading; what governs is the text of the regulation and the interpretation of your supervisory authority.
Five steps,
one deliverable.
Classification
Role as financial entity or ICT provider; identify critical or important functions.
Gap analysis
Check the four mandatory areas against the text of the regulation; review the evidence.
Register
Record third parties, assess contracts and exit capability.
Planning
Implementation plan with owners, dates and a test concept.
Report
Presentation to the management body and outsourcing function.