Financial services
Banks, payment institutions, insurers, asset managers and the ICT providers they depend on.
What is driving it
DORA applies in full, and it is unusually specific: an ICT risk management framework, incident classification against defined thresholds, a register of information covering every contractual arrangement, tested resilience, and threat-led penetration testing for the entities that meet the criteria. Supervisors have started asking for the register rather than asking whether it exists.
Where we usually start
A register of information built from the actual contract base rather than from memory, and a gap review of third-party contracts against the DORA clauses. That work exposes most of the rest: concentration risk, missing audit rights, and exit plans nobody has written.








