Skip to content

Solutions / By mandate

DORA

Threat-led penetration testing and ICT risk evidence for financial entities in scope of DORA.

What you receive

  • Threat-led penetration testing (TLPT)
  • ICT third-party risk register support
  • Resilience testing programme
  • Incident classification workflow

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    You have been named for threat-led testing

    Article 24 asks for a programme covering the ICT systems that support critical or important functions, and Article 25 lists what belongs in it — vulnerability assessment, scenario-based testing, source code review, end-to-end testing. A single yearly penetration test is a line item in that programme, not the programme.

  • 02

    You are assembling the register of information

    Article 28(3) requires a register of every ICT third-party contractual arrangement, marking those that support critical or important functions, and it goes to your supervisor. The difficulty is the function mapping underneath, not the template.

  • 03

    You sell ICT services to financial entities

    Article 30 tells your clients what their contracts must contain — audit and access rights, data locations, service levels, exit strategies. Providers are asked to evidence all of it, and a critical designation adds Union-level oversight on top.

How it runs

  1. 01

    Where you actually are

    A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.

  2. 02

    What the obligation really requires

    We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.

  3. 03

    A scoped programme

    The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.

  4. 04

    Evidence, not a gap report

    The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Scope validation and the attestation that a threat-led test met Article 26 sit with the designated authority, not the testing provider.

  • Whether you fall under Article 2, or qualify for the simplified framework in Article 16, is a legal question for your own advisers.

  • The register of information is filed by you with your competent authority; this engagement builds its content, it does not submit it.

Measured against

DORA Regulation (EU) 2022/2554, Art. 26
Requires threat-led penetration testing on live production systems at least every three years for entities the authority identifies.
DORA Regulation (EU) 2022/2554, Art. 28(3)
Requires a register of all ICT third-party contractual arrangements, marking those supporting critical or important functions.
TIBER-EU
Splits the work between an external threat intelligence provider and a red team, with a control team inside the entity the only people who know the test is running.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Is an annual penetration test enough for DORA?

No. Article 24 requires a digital operational resilience testing programme, and entities other than microenterprises must test the ICT systems supporting critical or important functions at least yearly. Article 25 lists what those tests can be — vulnerability assessments, scenario-based tests, source code review and more. Article 26 threat-led testing is a separate, intelligence-driven exercise.

Can we use our own red team for TLPT?

Article 26 allows internal testers where the competent authority approves it, conflicts of interest are controlled and the threat intelligence provider is external, with external testers rotated in every third test. Article 27 sets what a tester must meet.

Does DORA replace our ICT risk framework?

It absorbs it. Chapter II names identification, protection, detection, response, recovery and learning as obligations, with the management body holding ultimate responsibility. Most entities remap what they already run rather than start again.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.