Meeting DORA requirements
The European DORA regulation places on the financial sector a requirement that is simple to state and heavy to implement: stay operational despite a digital incident, and prove it. It also reaches, indirectly, the IT providers who serve those entities.
A requirement of resilience, not merely of compliance
DORA (Digital Operational Resilience Act) structures the digital resilience of the financial sector around five pillars: governance of technology-related risk, incident management and reporting, resilience testing, control of third-party provider risk, and threat information sharing.
The spirit of the text differs from classic documentary compliance: it asks you to demonstrate that in the event of an outage, an attack or a supplier failure, the critical functions keep running. The burden of proof falls on tests, not on intentions.
Two areas carry most of the effort: the register of ICT providers — with the associated contractual clauses and exit strategies — and the testing programme, which ranges from conventional tests to threat-led penetration testing (TLPT) for the most significant entities.
Many organisations established in Switzerland are affected indirectly: a subsidiary in the Union, European clients, or the status of provider to an entity subject to the regulation.
- Critical functions not identified, therefore not protected
- Register of ICT providers incomplete or not maintained
- Incident reporting deadlines that cannot be met
- Testing programme absent or purely documentary
- No exit strategy in case a provider fails
Five pillars, one requirement of proof
How we proceed
We start from the critical functions and your real dependencies, rather than from an article-by-article reading of the regulation.
Applicability and critical functions
Determining your exposure to the regulation — directly or as a provider — and identifying the critical or important functions along with the systems that support them.
Gap analysis across the five pillars
Assessment of what exists: ICT risk governance, incident capability, testing programme, third-party management and threat intelligence. Gaps are prioritised by regulatory requirement and by risk.
Third-party register and contracts
Building the register of ICT providers, reviewing the contractual clauses expected and formalising the exit strategies — the workstream most often underestimated.
Incident capability
Classification, escalation procedures and reporting templates that make the regulatory deadlines achievable, tested through a crisis simulation exercise.
Testing programme
Setting up a regular programme — penetration tests, configuration reviews and, for the entities concerned, threat-led testing — producing evidence the regulator can use.
Several disciplines, a single point of contact
DORA brings governance, offensive testing and response capability together: we cover all three through a single point of contact.
- Applicability note and map of critical functions
- Gap analysis across the five pillars
- Register of ICT providers and clause review
- Incident procedures and reporting templates
- Resilience testing programme and associated reports
Frequently asked questions
DORA: are you in scope, and how far?
An applicability note and a gap analysis are enough to clarify your situation and frame the effort.