DORA moves the conversation about ICT risk out of the technical corner and into management responsibility. It is no longer enough for a supplier to promise availability: the financial entity has to show it knows what depends on whom, and what it does when that thing fails.
We work with financial entities and with their ICT providers — the latter often reach us holding a contract their client wants renegotiated, full of clauses they do not recognise.
Situations in which we are called
- You are a financial entity and have to put your ICT risk framework in order
- A financial client asks you to renegotiate the ICT services contract
- You have to compile the register of information on providers
- An incident has occurred and it is unclear what has to be reported, and when
- You are outsourcing a critical function and concentration risk has to be assessed
- You are preparing digital operational resilience testing
What we cover
- The internal ICT risk management framework and management’s roles
- The register of information on ICT provider arrangements
- Review and renegotiation of ICT services contracts
- Incident classification and reporting procedures
- Concentration risk strategy and exit plans
- Assistance in dealings with the supervisory authority
How we work
We start from a dependency map: which business functions rely on which providers, and which of those are critical. Without that map the register of information is a formality and the exit plans stay theoretical.
On contracts, attention goes to the clauses that are hard to negotiate: audit rights, incident notification, exit assistance. These are precisely the ones large providers most often refuse, so they are raised early, not in the final week.
What helps us start
- The list of ICT providers and the contracts with them
- A description of the functions you consider critical
- Existing internal security and continuity policies
- The incident log for the recent period, if there is one
