What We Do

DORA Support for Information Security Officers and ICT Risk Control Functions

Additional expertise. Additional delivery capacity. Ready when you need us.

Digital-operational-resilience.net provides practical information on the Digital Operational Resilience Act, its regulatory technical standards, implementing technical standards and supervisory expectations.

When information must be translated into policies, risk assessments, controls, reports and auditable evidence, Leitner & Associates works alongside your existing Information Security and ICT Risk Control Functions.

We strengthen your team with specialist expertise, additional capacity and implementation-ready work products.

You retain responsibility and decision-making authority. We provide the additional expertise and delivery capacity.

DORA covers ICT risk management, ICT-related incident management and reporting, digital operational resilience testing and ICT third-party risk management. These requirements must be embedded in governance, policies, processes, controls, documentation and management reporting.


When DORA Responsibilities Require Additional Capacity

Information Security Officers and ICT Risk Control Functions face a continuously growing workload.

ICT risks must be identified, assessed, monitored and reported.

Policies and procedures must be reviewed and updated.

ICT controls must be performed and documented.

ICT-related incidents must be classified, managed and reported.

Digital operational resilience tests must be planned, conducted and evaluated.

ICT third-party risks must be assessed and monitored.

Registers, reports and evidence must remain complete, current and auditable.

At the same time, day-to-day operations, projects, audits and management enquiries continue.

This is where we support you.

With specialist expertise.

With practical implementation.

With substantial delivery capacity.


How We Support Your DORA Function

We work within your existing organisation and build on your established governance, policies, processes, controls, systems and reporting structures.

We take on clearly defined work packages, complete complex implementation tasks and deliver results that your function can use immediately.

Our support includes:

  • Reviewing and updating the ICT risk management framework
  • Updating information security and ICT risk management policies
  • Developing and enhancing operating procedures
  • Identifying and documenting ICT-supported business functions
  • Mapping ICT assets, information assets and dependencies
  • Performing ICT risk assessments
  • Developing risk indicators and management information
  • Designing, performing and documenting ICT controls
  • Preparing control plans and control reports
  • Supporting ICT-related incident management
  • Developing incident classification and escalation procedures
  • Preparing regulatory incident reporting processes and templates
  • Reviewing ICT business continuity arrangements
  • Developing ICT response and recovery procedures
  • Supporting backup, restoration and recovery requirements
  • Developing digital operational resilience testing programmes
  • Documenting and evaluating resilience tests
  • Supporting the management of ICT third-party risk
  • Performing ICT service provider risk assessments
  • Reviewing contractual arrangements
  • Supporting the register of information
  • Developing monitoring and control procedures for ICT service providers
  • Preparing exit strategies and transition plans
  • Preparing reports for the management body
  • Compiling audit and supervisory evidence
  • Addressing audit and supervisory findings
  • Developing and tracking remediation plans
  • Providing quality assurance for DORA documentation

DORA requires financial entities to maintain an ICT risk management framework, identify and document ICT-supported functions and assets, monitor ICT systems, manage incidents, conduct resilience testing and manage ICT third-party risk.


We Work With Your Existing Structures

Your organisation already has policies, processes, controls, committees, reporting lines and technical systems.

We familiarise ourselves with these structures quickly and develop them in line with DORA requirements and your organisation’s risk profile.

Our work is designed to:

  • preserve effective arrangements
  • strengthen existing governance
  • close identified gaps
  • improve documentation
  • increase control effectiveness
  • establish clear evidence
  • accelerate implementation
  • reduce pressure on internal functions

This approach protects operational continuity and allows your internal experts to remain fully in control of their responsibilities.


Support for Information Security Officers

We support Information Security Officers in the practical development and operation of the information security management framework.

Typical assignments include:

  • updating information security policies
  • reviewing information security governance
  • developing security standards and procedures
  • assessing information security risks
  • defining and documenting security controls
  • preparing control and status reports
  • supporting incident management
  • reviewing identity and access management arrangements
  • assessing operational information security
  • supporting awareness and training activities
  • preparing management reporting
  • compiling evidence for audits and supervisory reviews
  • addressing information security findings

The objective is a well-documented, effective and auditable information security framework that integrates into the organisation’s wider DORA governance.


Support for ICT Risk Control Functions

We support ICT Risk Control Functions in the independent monitoring, assessment and reporting of ICT risks.

Typical assignments include:

  • developing ICT risk methodologies
  • reviewing ICT risk inventories
  • performing independent ICT risk assessments
  • developing risk indicators and thresholds
  • designing monitoring and control plans
  • conducting control activities
  • assessing control effectiveness
  • analysing incidents and risk developments
  • preparing ICT risk reports
  • supporting risk acceptance and escalation processes
  • reviewing ICT third-party risks
  • monitoring remediation measures
  • preparing reports for management and supervisory bodies
  • quality-assuring DORA implementation activities

We provide the additional analytical and operational capacity required to perform these responsibilities thoroughly and on time.


DORA Task Force for Audits, Reviews and Remediation

We are frequently engaged when Information Security and ICT Risk Control Functions face exceptional regulatory pressure.

Typical situations include:

  • DORA reviews and supervisory inspections
  • special audits under section 44 of the German Banking Act
  • reviews by BaFin or Deutsche Bundesbank
  • supervisory activities under the Single Supervisory Mechanism
  • enquiries from Joint Supervisory Teams
  • internal audit reviews
  • external audit engagements
  • extensive remediation programmes
  • findings with demanding implementation deadlines
  • major changes to ICT governance
  • ICT transformation projects
  • significant ICT incidents
  • short-term resource shortages
  • extensive documentation requirements

In these situations, we work as an experienced DORA task force alongside the responsible function holders.

We structure the work programme, take on substantial work packages, prepare the required documentation and create transparent evidence for management, auditors and supervisory authorities.


Addressing DORA Findings

Audit and supervisory findings require precise analysis, clear ownership, realistic measures and reliable evidence of completion.

We support you with:

  • analysing the underlying finding
  • identifying affected policies, processes and controls
  • assessing root causes
  • developing remediation measures
  • preparing detailed action plans
  • defining responsibilities and deadlines
  • updating policies and procedures
  • implementing or enhancing controls
  • preparing completion evidence
  • monitoring progress
  • quality-assuring remediation documentation
  • preparing responses for auditors and supervisory authorities

The result is a structured and traceable remediation process with clear, review-ready evidence.


Interim Management in Exceptional Circumstances

Where an Information Security Officer or the Head of an ICT Risk Control Function becomes unexpectedly unavailable, we can assume the role on an interim basis.

Typical reasons include:

  • unexpected resignation
  • serious illness
  • serious accident
  • bereavement
  • maternity leave
  • parental leave
  • retirement
  • an extended recruitment process

In these exceptional circumstances, we can act as:

  • Interim Information Security Officer
  • Interim Head of the ICT Risk Control Function

We ensure continuity until a permanent internal appointment is in place and support an orderly handover to the new function holder.


How We Work With You

Depending on your requirements, we support you as:

  • specialist sparring partner
  • coach
  • project resource
  • quality assurance partner
  • DORA task force
  • operational reinforcement for your function
  • interim function holder in exceptional circumstances

The scope of our involvement is aligned with your governance, priorities, deadlines and available internal capacity.


Who We Support

We support financial entities subject to DORA, including:

  • credit institutions
  • promotional and development banks
  • payment institutions
  • electronic money institutions
  • investment firms
  • asset management companies
  • insurance and reinsurance undertakings
  • financial services institutions
  • FinTechs
  • crypto-asset service providers
  • other regulated financial entities

DORA applies across a broad range of regulated financial entities and establishes common requirements for their ability to withstand, respond to and recover from ICT-related disruption.


Why Leitner & Associates?

Our work combines regulatory expertise with operational experience in information security, ICT risk management, governance, internal controls, audit and supervisory remediation.

We deliver practical work products that integrate directly into your organisation, including:

  • updated policies
  • complete procedures
  • documented risk assessments
  • control programmes
  • completed control reports
  • management reports
  • remediation plans
  • registers and inventories
  • audit files
  • supervisory evidence

Our objective is clear:

To strengthen your Information Security and ICT Risk Control Functions with the expertise, capacity and reliable delivery required to meet DORA expectations.


From DORA Information to DORA Implementation

Digital-operational-resilience.net gives you access to the DORA Regulation, its principal implementation topics and supporting resources. The website already covers areas such as governance, ICT risk management, ICT operations, business continuity, ICT third-party risk, operational information security and identity and access management.

Leitner & Associates provides the practical support required to turn those requirements into day-to-day governance, controls, reports and evidence.

You lead the function. We strengthen its delivery.