City of London skyline at dusk

SECTOR — FINANCIAL SERVICES

For financial firms with a regulator to answer to.

Banks, insurers, asset and wealth managers, payments and fintech. Under DORA, the FCA and the PRA, security is now a board-level obligation — not a line in the IT budget.

WHAT'S CHANGED

The rules moved. The expectations moved with them.

DORA has applied across the EU since January 2025. In the UK, the FCA and PRA have expected firms to identify their important business services, set impact tolerances and evidence resilience since 2022. Different regimes, one underlying question: can the firm keep operating — and recover — when something breaks?

The old answer, a thick policy set and an annual pen test, no longer passes. Supervisors want proof that resilience is designed into how the firm runs, owned by a named executive, and tested against scenarios you didn't get to choose.

Canary Wharf towers against the sky

Supervisors don't grade the binder. They grade the recovery.

WHERE THE PRESSURE SHOWS

HOW WE HELP FINANCIAL FIRMS

THE RULES THAT APPLY TO YOU

Regulated shouldn't mean slow. We make the safe path the fast one.

Start a conversation
ALSO WORK IN Critical infrastructure & OT → Central government →