Client: Polish Financial Supervision Authority (UKNF)
Few teams know DORA from the supervisor’s side of the table. This engagement gave us exactly that perspective: helping shape the frameworks a regulator uses to assess the digital resilience of financial institutions.
The challenge
As DORA moved from legislation to supervisory practice, national regulators needed to build the frameworks and methodologies to oversee ICT risk and operational resilience across supervised financial institutions.
Our role
Our CTO contributed to the supervisory-level implementation of DORA, supporting the development of ICT risk and operational resilience oversight frameworks, regulatory procedures, and supervisory methodologies, including alignment with Threat-Led Penetration Testing (TLPT) expectations.
Outcome
Direct contribution to the regulatory infrastructure used to supervise ICT risk and resilience across the financial sector, giving our team first-hand insight into supervisory expectations that we bring into every client engagement.