Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Sectors›Banking and finance
Sectors

Banking and finance

Financial services is the only sector carrying two regimes at once. DORA governs ICT risk in more detail but does not displace the obligations under the Cybersecurity Act. The work is done once and reported in two directions.

Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational CERT
Sectoral authorityCroatian National Bank and HANFA

The measures that carry most of the work in this sector

03Risk management
DORA and the Regulation require the same risk register. Two methodologies mean two registers that diverge.
08Supply chain security
The DORA register of information on ICT provider contracts is the hardest part, and it fails on data quality, not on the rules.
11Incident handling
Notification to the competent CSIRT and DORA reporting run in parallel, with their own forms and deadlines.
12Business continuity
DORA requires resilience testing, which goes beyond a classical recovery plan.

What we most often find

  • A register of information populated by hand from three unconnected sources - procurement, IT and finance
  • Cloud provider contracts with no obligation to disclose subcontractors
  • A risk register that does not cover third-party risk
  • Recovery testing that is documented but never timed

Check for yourself

Tri alata koja rade u pregledniku, bez registracije:

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.