DORA focuses on the digital operational resilience of the financial sector: the ability to resist, respond and recover from ICT incidents.
It doesn't just affect banks or insurance companies. It can also impact technology providers that provide critical services to financial entities.
To prepare, it is advisable to connect ICT governance, risk management, resilience testing, suppliers and incidents.
What a company should review
- ICT risk management framework.
- Notification and management of relevant incidents.
- Digital operational resilience testing.
- Risk management of third-party ICT providers.
How we work at Blue Moon
The practical recommendation is not to approach each standard as an isolated folder. ISO 27001, ENS, NIS2, DORA, data protection and secure development share assets, risks, controls, suppliers, incidents and evidence.
We can review whether this rule affects your company and turn it into a clear, prioritized and acceptable roadmap.
Request diagnosis →