
SECTOR — FINANCIAL SERVICES
Banks, insurers, asset and wealth managers, payments and fintech. Under DORA, the FCA and the PRA, security is now a board-level obligation — not a line in the IT budget.
WHAT'S CHANGED
DORA has applied across the EU since January 2025. In the UK, the FCA and PRA have expected firms to identify their important business services, set impact tolerances and evidence resilience since 2022. Different regimes, one underlying question: can the firm keep operating — and recover — when something breaks?
The old answer, a thick policy set and an annual pen test, no longer passes. Supervisors want proof that resilience is designed into how the firm runs, owned by a named executive, and tested against scenarios you didn't get to choose.
WHERE THE PRESSURE SHOWS
HOW WE HELP FINANCIAL FIRMS
01
A regulator-facing security lead in the room — DORA, FCA and PRA handled by people who've sat on both sides of the table.
02
Important business services mapped, impact tolerances set, and testing that pushes them until the numbers mean something.
03
The cyber fluency SM&CR now expects of the executives and non-execs who are personally accountable for it.
THE RULES THAT APPLY TO YOU
Digital Operational Resilience Act — in force since January 2025 for financial entities and their critical ICT providers. →
UKFCA PS21/3 and the PRA rules — important business services, impact tolerances, and mapping. →
EUIf you run infrastructure or services in scope beyond financial regulation — the wider EU cyber baseline. →
Regulated shouldn't mean slow. We make the safe path the fast one.
Start a conversation