DORA moves the conversation about ICT risk out of the technical corner and into management responsibility. It is no longer enough for a supplier to promise availability: the financial entity has to show it knows what depends on whom, and what it does when that thing fails.

We work with financial entities and with their ICT providers — the latter often reach us holding a contract their client wants renegotiated, full of clauses they do not recognise.

Situations in which we are called

  • You are a financial entity and have to put your ICT risk framework in order
  • A financial client asks you to renegotiate the ICT services contract
  • You have to compile the register of information on providers
  • An incident has occurred and it is unclear what has to be reported, and when
  • You are outsourcing a critical function and concentration risk has to be assessed
  • You are preparing digital operational resilience testing

What we cover

  • The internal ICT risk management framework and management’s roles
  • The register of information on ICT provider arrangements
  • Review and renegotiation of ICT services contracts
  • Incident classification and reporting procedures
  • Concentration risk strategy and exit plans
  • Assistance in dealings with the supervisory authority

How we work

We start from a dependency map: which business functions rely on which providers, and which of those are critical. Without that map the register of information is a formality and the exit plans stay theoretical.

On contracts, attention goes to the clauses that are hard to negotiate: audit rights, incident notification, exit assistance. These are precisely the ones large providers most often refuse, so they are raised early, not in the final week.

What helps us start

  • The list of ICT providers and the contracts with them
  • A description of the functions you consider critical
  • Existing internal security and continuity policies
  • The incident log for the recent period, if there is one