Composite: a regional bank getting DORA-ready in two quarters
A composite of DORA engagements with mid-size financial firms: what a bank with a capable IT team but no single resilience owner did first, and the order that worked.
The starting point
A regional bank with solid IT operations, but resilience spread across security, IT, procurement, legal and risk. No one owned the DORA picture end to end, and the register of information existed as three spreadsheets that disagreed with each other.
What they did, in order
They named a single accountable owner. They mapped important business services and the ICT and third parties each one depends on. They rebuilt the register of information once, as an operational record tied to procurement and the CMDB rather than a reporting artefact. Only then did they layer incident classification, resilience testing and third-party oversight onto that map.
Where it landed
One map now answers most DORA questions. The register maintains itself from operations instead of being rebuilt each submission, and the supervisory conversation became a report the bank runs. Whether and how DORA applies to a specific entity remains a question for counsel, confirmed during onboarding rather than asserted here.
Questions, answered
Is this a real client?
Why start with the service map?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.