ATALAIA
  1. Home
  2. Solutions
  3. DORA
Solutions · Regulation

DORA

For financial entities: ICT risk management, incident reporting, resilience testing and third-party risk, with evidence.

DORA

Where you are

DORA has applied since January 2025. Supervisors now ask for an ICT risk framework that works, tests that are run, and a register of the ICT providers you depend on.

Sounds familiar?

  • Resilience testing is one pentest a year
  • No register of the software suppliers you depend on
  • Incident classification decided in the moment

What you need

Each need, why it matters, and what covers it: the services that set it up, and the tower modules that will keep watching it.

  1. An ICT risk framework

    Policies, risk assessment and owners, kept current.

    Atalaia tower · Soon

  2. Resilience testing

    A testing programme, from scans to scenario-based tests.

    Atalaia tower · Soon

    Services only, for now.

  3. Third-party risk

    Your software supply chain, recorded and assessed.

    Atalaia tower · Soon

  4. Incidents you can classify

    Detection and a runbook that matches the reporting rules.

    Atalaia tower · Soon

    Services only, for now.

What it asks, and where the evidence comes from

A simplified reading. Your compliance team decides how it applies to you.

DORA asks forEvidence from the lineWho helps
ICT risk management frameworkPolicies with owners, risk registerPolicies, Compliance & Risk
ICT incident reportingDetections, classification runbookDetection Engineering
Digital operational resilience testingTest plan, pentest and retest recordsPentest, Security Scans
ICT third-party riskSupplier and package registerSupply Chain Security, Package firewall

We help you produce the evidence. We are not your auditor or your lawyer.

What you end up with

  • A framework supervisors can read
  • A testing programme with retests
  • A register of what you depend on

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.