GRC

Digital Operational Resilience Act

Fit for DORA: Strengthen your digital resilience with our DORA consulting products

Regardless of whether you are still in the initial stages of implementing the DORA requirements or are already close to the finish line - we will help you to be ready in time for the deadline in January 2025.

External content - Typeform survey

Here you will find content from a third-party provider that you can display with one click

This may result in personal data being transmitted to the third-party provider. You can find more information in our privacy policy

General information on the EU DORA Regulation

The EU's DORA Regulation marks a significant step towards harmonising the regulatory requirements for digital resilience of financial companies within Europe.

This regulation was developed through close cooperation between European supervisory authorities and will come into force on 17 January 2025. Enforcement and monitoring of compliance is the responsibility of the respective national authorities.

Arrange a non-binding consultation appointment now
Ein Consultant berät sich mit seinem Team in einem Meeting.

The introduction of the DORA regulation brings with it a number of challenges for the financial services industry. This requires a thorough analysis and adaptation of business practices to ensure DORA compliance. Financial services companies are therefore faced with the task of finding pragmatic solutions to fulfil the requirements while minimising the resources required.

The four focus topics of DORA

ICT Risk Management
ICT Incidents
Digital Operational Resilience Testing
Managing of ICT Third-Party Risk

DORA requires financial services organisations to establish an appropriate information and communications technology (ICT) risk management framework that includes the identification, assessment, monitoring, reporting and mitigation of ICT risks. The framework should be tailored to the nature, scale, complexity and risk profile of the business and include clear allocation of responsibilities, appropriate resource allocation, effective governance and monitoring, and regular review and updating.

Financial services organisations must also take appropriate security measures to ensure the availability, integrity, confidentiality and authenticity of their ICT systems. This includes applying industry standards, conducting penetration tests and vulnerability assessments, implementing incident response plans and ensuring data recovery capabilities.

Read our paper on DORA and the management of ICT third party risk in the financial sector

Our DORA Services

Our DORA consulting services take a holistic view of the requirements and are optimised to meet individual customer needs.

Book a non-binding consultation appointment with us

DORA Readiness Analysis

In order to fulfil the DORA requirements, it is important to review the current implementation status. We can assess this using our in-depth expertise, industry-specific know-how and detailed analyses of guidelines, documentation and expert interviews, and propose improvement measures.

Our DORA readiness analysis is divided into four phases:

  1. Set-up: Define responsibilities, establish project organisation and conduct a joint kick-off.
  2. Self-assessment: Technical experts assess the status using a catalogue of questions on the DORA requirements and document discrepancies in the assessment tool.
  3. Interview: The Intero team validates the self-assessment through intensive consultation with your technical experts and identifies possible improvement measures.
  4. Presentation: Presentation of the results together with a mitigation plan.

If required, we also provide support in the further implementation of mitigations, for example in third-party risk management.

About our DORA Readiness Analysis

DORA Project Management

Stakeholders such as IT, information security, risk management, legal and compliance are essential. We ensure successful collaboration through project management in the DORA context.

Our range of services includes

 

  • Ensuring the exchange of information between organisational units
  • Monitoring and reviewing the content of project progress
  • Documentation and reporting: preparation and implementation of steering committee

ICT Risk Management

We organise information risk management in line with the requirements for ICT risk management in DORA. We work with you to develop customised approaches for recording, classifying and managing your ICT and information assets. In addition, we work with you to design the new ICT risk management control function and ensure that it is efficiently embedded in existing processes and organisational structures.

Our range of services includes

 

  • Adaptation of the determination of protection requirements, taking into account dependencies between ICT and information assets
  • Definition of an ICT risk lifecycle including the necessary controls, recertifications and reporting
  • Designing the ICT risk function in the context of the existing organisation while maintaining the necessary independence of the function

Third party risk management

We support you in setting up an effective and regulatory-compliant third-party risk management system and establishing it in your organisation. We are at your disposal with our experience in all areas from process definition to operationalisation.

Our range of services includes

 

  • Definition of the regulatory basis for third-party risk management
  • Setting up a compliant third-party life cycle including all necessary risk analyses and due diligence processes
  • Introduction into the organisation by means of accompanying change management
  • Identification, recording and documentation of contracts (operations support)

Read our paper on DORA and the management of ICT third party risk in the financial sector

External content - Typeform survey

Here you will find content from a third-party provider that you can display with one click

This may result in personal data being transmitted to the third-party provider. You can find more information in our privacy policy

Your DORA experts

[Translate to English:]

Jochen Friedrich

Partner
Dies ist ein Porträtfoto von Michael Lohmann.

Michael Lohmann

Associate Manager
[Translate to English:]

Philipp Fackler

Associate Manager

Our Competence Center GRC