Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

4.03 Resilience

DORA Compliance & Resilience Testing

Support across DORA ICT risk management, incident reporting, resilience testing, third-party risk and information-sharing requirements, including preparation for TLPT where applicable.

DORA has applied since 17 January 2025 and requires financial entities to maintain evidence across ICT risk management, incident management and reporting, resilience testing, ICT third-party risk and information sharing. We assess the current state and help establish practical controls and evidence.

For financial entities designated for TLPT, we support scoping, readiness and provider coordination for intelligence-led testing of live production systems in line with DORA and the updated TIBER-EU framework, including the required closure and purple-teaming activities.

We help determine applicability, structure the programme and connect findings to the ICT risk framework, the Register of Information and major-incident reporting processes.

17 Jan 2025
DORA in force across the EU
TIBER-EU
aligned threat-led testing

01

How it works

  1. 01

    Scoping & applicability

    Confirm DORA scope and TLPT applicability; identify critical or important functions and agree the governance and rules of engagement.

  2. 02

    Gap assessment

    Assess ICT risk management, third-party risk, incident reporting and resilience testing against the applicable DORA requirements and technical standards.

  3. 03

    Threat intelligence & targeting

    External provider builds threat scenarios and targeting against your critical functions.

  4. 04

    Red team execution

    Covert, intelligence-led testing of live systems with the blue team unaware.

  5. 05

    Closure & reporting

    Complete the required purple-team phase, remediation planning and evidence preparation for authority review.

02

Packages

Essential
DORA five-pillar gap assessment and resilience-testing readiness roadmap.
Comprehensive Popular
Full DORA program support with third-party risk and incident-reporting workflows.
Enterprise
End-to-end support for a TIBER-EU-aligned TLPT, with appropriately separated threat-intelligence and red-team functions and the required purple-team closure.

03

Supported by our own threat-intelligence platform

DORA requires financial entities to demonstrate operational resilience with appropriate governance, testing and evidence. Our services and supporting tools help establish and document those controls.

04

Helpful tools

05

All services

Scope a test

[email protected] +371 2256 5353

Direct access to a senior specialist · Reply within 24 hours · NDA available on request