How we work
01Gap assessment
Current state against the DORA requirements, by pillar.
02ICT risk management framework
Governance, roles, risk methodology and reporting to the management body.
03Register of information
Contractual arrangements with ICT providers, function criticality, subcontracting and processing locations.
04Incident management
Classification, reporting and the register of ICT-related incidents.
05Resilience testing
A testing programme proportionate to the entity's size and risk profile.
06Exit strategies
Substitutability assessment and exit plans for critical providers.
What you get
Gap assessment
ICT risk framework
Register of information
Incident procedure
Testing programme
Exit strategies
Measures of Annex II this service covers
02 Management of software and hardware assets
03 Risk management
08 Supply chain security
11 Incident handling
12 Business continuity and cyber crisis management
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.