For the complete documentation index, see /llms.txt. Markdown version of this page: /en/services/dora.md.
← Back to services
Services

DORA

From DORA scoping to a resilience programme the supervisor can read in ten minutes, fitted to your tier and dependencies.

Maximilian Sharoyan
Maximilian Sharoyan
Co-founder & Principal Advisor

DORA reads like a checklist and runs like an enterprise transformation. I lead the GRC architecture work where the supervisor expects a coherent story across Chapter II, incident reporting, and third-party risk. Here is the shape of a programme that delivers that story without turning your operations team into auditors.

What we deliver

  • Maximilian Sharoyan
    DORA scoping

    Which class of financial entity you are, which articles apply, and which proportionality carve-outs are available to your tier.

  • Maximilian Sharoyan
    ICT risk management framework

    Chapter II in practice, from board role and policy stack down to controls, continuity, and recovery.

  • Maximilian Sharoyan
    Incident management and reporting

    Major ICT-related incident classification under Article 19, notification timelines to the supervisor, and templates that hold up during a real incident.

  • Maximilian Sharoyan
    Digital operational resilience testing

    A testing programme aligned to Article 26. Aikido AI Pentest covers continuous application security. Where Article 26(2) triggers threat-led penetration testing for in-scope entities, we scope the engagement and coordinate a qualified red-team provider.

  • Maximilian Sharoyan
    ICT third-party risk and register of information

    The provider register under Article 28, contract clauses, concentration risk, and dependency on critical third parties.

  • Maximilian Sharoyan
    Board oversight and ownership

    DORA gives the board an explicit role. We build the decision cadence, the documentation, and the reporting that let the board own the risk in practice.

How we deliver this service

  • In a project

    A DORA readiness assessment, gap report, and prioritised remediation plan, typically four to eight weeks.

  • In a role at the customer

    DORA programme owner inside the organisation for a bounded period, until the board has a real framework to report against.

  • As part of a service

    Included in Secured by FM CyberSecurity for in-scope financial entities under the threshold, alongside ISO 27001 and NIS2.

Recent insights on DORA

Talk to Max
Questions or inquiry? [email protected] Contact us →