DORA
From DORA scoping to a resilience programme the supervisor can read in ten minutes, fitted to your tier and dependencies.
DORA reads like a checklist and runs like an enterprise transformation. I lead the GRC architecture work where the supervisor expects a coherent story across Chapter II, incident reporting, and third-party risk. Here is the shape of a programme that delivers that story without turning your operations team into auditors.
What we deliver
-
DORA scopingWhich class of financial entity you are, which articles apply, and which proportionality carve-outs are available to your tier.
-
ICT risk management frameworkChapter II in practice, from board role and policy stack down to controls, continuity, and recovery.
-
Incident management and reportingMajor ICT-related incident classification under Article 19, notification timelines to the supervisor, and templates that hold up during a real incident.
-
Digital operational resilience testingA testing programme aligned to Article 26. Aikido AI Pentest covers continuous application security. Where Article 26(2) triggers threat-led penetration testing for in-scope entities, we scope the engagement and coordinate a qualified red-team provider.
-
ICT third-party risk and register of informationThe provider register under Article 28, contract clauses, concentration risk, and dependency on critical third parties.
-
Board oversight and ownershipDORA gives the board an explicit role. We build the decision cadence, the documentation, and the reporting that let the board own the risk in practice.
How we deliver this service
- In a project
A DORA readiness assessment, gap report, and prioritised remediation plan, typically four to eight weeks.
- In a role at the customer
DORA programme owner inside the organisation for a bounded period, until the board has a real framework to report against.
- As part of a service
Included in Secured by FM CyberSecurity for in-scope financial entities under the threshold, alongside ISO 27001 and NIS2.
Recent insights on DORA
- How long does ISO 27001 take?
The ISO 27001 timeline depends on your starting point, the controls you need to implement and the certification body's audit schedule.
- Where AI can help with ISO 27001 preparation
AI can help draft policies and organise evidence. People still need to make risk decisions, implement controls and verify that the records describe reality.
- ISO 27001 or NIS2 first?
Build shared security processes, but track legal duties and certification separately. Applicable legal deadlines take priority over commercial preferences.