
- 01DORA's five pillars: ICT risk management with board accountability, classified incident reporting on tight timelines, threat-led penetration testing for significant entities, third-party risk with mandatory contractual clauses, and information sharing.
- 02The Article 28 third-party register is where most programs are still behind. Procurement, vendor management, and IT inventory systems disagree on what 'one vendor' means — reconciling those before submission is the actual work.
- 03Threat-led penetration testing (TLPT) is conducted on production by certified providers against business-specific threat models. It is not a quarterly pen test relabeled — plan budget and engineering capacity well in advance.
- 04Senior management is personally accountable. Board-level sign-off on the ICT risk framework is mandatory and named individuals must own each pillar. Generic 'CIO owns ICT risk' will not survive a competent-authority review.
The Digital Operational Resilience Act (DORA), in force since January 2025, harmonizes ICT risk management for EU financial entities — banks, insurers, investment firms, crypto-asset service providers, and many of their critical ICT third parties.
The five DORA pillars
- 01ICT risk management framework with board-level accountability
- 02ICT incident classification and reporting on tight regulatory timelines
- 03Threat-led penetration testing (TLPT) for significant entities
- 04ICT third-party risk management with mandatory contractual clauses
- 05Information sharing within trusted communities
The third-party register is harder than it looks
DORA Article 28 requires a register of all ICT third-party arrangements with detail on criticality, function supported, sub-contractor chain, and exit strategy. Most institutions discover that their procurement, vendor management, and IT inventory systems disagree on what 'one vendor' means. Reconciling those before submission is the work.
TLPT is real and expensive
Threat-led penetration testing is conducted on production systems, by certified providers, against threats specifically modeled on your business. It is not a quarterly pen test relabeled. Plan budget and engineering capacity well in advance.


