Skip to main content

DORA

(Digital Operational Resilience Act)

Illustration of cybersecurity services

The Digital Operational Resilience Act (DORA) is an EU regulation that came into force on January 16, 2023, and will be applicable from January 17, 2025. The primary aim of DORA is to enhance the IT security of financial institutions such as banks, insurance companies, and investment firms, as well as their Information and Communication Technology (ICT) service providers. The regulation aims to ensure the operational resilience of these entities in the face of potential digital incidents.

One of the main components of DORA regulation is the requirement to conduct Threat-Led Penetration Testing. Due to the high complexity of TLPT tests and the risks involved in conducting them in a live production environment, TLPT testing should only be carried out by top-tier experts. Securitum has been working with leading financial institutions in Poland and abroad for years, delivering the highest quality of services. Our team meets all the requirements outlined in Article 5 of the regulatory technical standards for TLPT testing.

To ensure the completeness of the TLPT service, Securitum operates with two key, independent teams working in three phases:

Threat Intelligence Provider (TIP) Team

As a TIP, we gather intelligence data and analyze available public sources and other information to create a detailed report on Targeted Threat Intelligence (TTI). This report provides a comprehensive picture of potential threats and attack vectors. Based on these analyses, we prepare the attack scenarios for the Red Team.

Red Team (RT)

After completing the threat intelligence assessment, we provide full-scope, multi-layered attack simulation which measures how well your organization’s employees, networks, applications, and physical security controls can handle real-life attack scenarios.

After completing the audit, we will provide you with key information about the current technical security level of your organization. We will highlight areas that need improvement and present specific recommendations for corrective actions during joint, Purple Team Workshops, alongside your cybersecurity team. Our recommendations are designed to strengthen your security measures, reduce risks, and enhance the overall digital resilience of your organization.

Diagram showing TLPT service phases

FAQ

A professional cybersecurity consultant ready to assist with your inquiry.

Any questions?

Happy to get a call or email
and help!