DORA

DORA: UK financial entities must map ICT third-party risk

Under DORA, UK banks and fintechs must map ICT third-party risk and run resilience testing.

Key steps: register critical/important providers, run coordinated TLPT for systemic entities, embed security clauses.

The MiliSec method

What we run for our Virtual CISO clients:

  • Map ICT third-party risk.
  • Test exit and continuity of providers.
  • Evidence resilience to the regulator.

Going further

DORA targets financial-sector resilience against third-party ICT risk.

Map, test and evidence continuity of critical providers.

Besoin d'un RSSI Virtuel ?

Notre veille alimente nos recommandations de conformité. Contactez-nous pour un diagnostic.

Demander un audit