<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[fromCISO]]></title><description><![CDATA[Cybersecurity and Compliance insights for fintech CTOs navigating without a CISO.
]]></description><link>https://www.fromciso.com</link><image><url>https://substackcdn.com/image/fetch/$s_!eH8c!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470088f8-8ca1-4ab9-99fc-d523fde37ab9_500x500.png</url><title>fromCISO</title><link>https://www.fromciso.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 03 Oct 2026 09:12:12 GMT</lastBuildDate><atom:link href="https://www.fromciso.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Andrey Gubarev]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[fromciso@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[fromciso@substack.com]]></itunes:email><itunes:name><![CDATA[Andrey Gubarev]]></itunes:name></itunes:owner><itunes:author><![CDATA[Andrey Gubarev]]></itunes:author><googleplay:owner><![CDATA[fromciso@substack.com]]></googleplay:owner><googleplay:email><![CDATA[fromciso@substack.com]]></googleplay:email><googleplay:author><![CDATA[Andrey Gubarev]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The job was never to remove the risk]]></title><description><![CDATA[I used to measure myself by the risks I'd eliminated. The list never got shorter, and that changed what I think the job actually is.]]></description><link>https://www.fromciso.com/p/the-job-was-never-to-remove-the-risk</link><guid isPermaLink="false">https://www.fromciso.com/p/the-job-was-never-to-remove-the-risk</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Tue, 28 Jul 2026 06:31:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/de0a014a-d3fd-47fc-bcdb-7d3bae29d43b_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Early in my career I thought a good security leader was someone who closed things. Open ports, weak passwords, unpatched servers, risky vendors, find them, shut them, move to the next. The scoreboard was the list of things I had eliminated.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/subscribe?"><span>Subscribe now</span></a></p><p>It took me a while to notice that the list never got shorter. Close ten risks, the business opens twelve. A new product, a new market, a new partner, a new piece of software someone in finance already signed up for. The work wasn&#8217;t reducing the risk to zero. The work was deciding which risks the company would carry on purpose, and making sure someone owned that decision.</p><p>That sounds like a small reframe. In practice it changes almost everything about how you do the job.</p><p>It became concrete for me in a conversation with a founder I reported to. I came in expecting us to talk about a specific exposure I wanted closed. That wasn&#8217;t the conversation he wanted. What he was actually asking for was a plan and a measurable before-and-after, evidence that we were moving in a direction, not a single fire put out. He wasn&#8217;t asking for a technical explanation, and he wasn&#8217;t asking me to make a particular risk disappear. He was asking me to show him progress he could see. I&#8217;d been about to hand him a closed ticket. What he needed was a trajectory.</p><p>Here is the distinction I keep coming back to. Fixing a vulnerability can be a technical act. You can do it alone, with tools, on a Friday afternoon. Deciding what the company does about the business risk underneath it is a governance act. It needs someone with the authority to say &#8220;yes, we accept this,&#8221; and a record that they said it. The first feels productive. The second is the one that holds up when something goes wrong and people ask who decided.</p><p>The trap for security people is that we are usually better at the first than the second. We came up through systems. Saying no to a firewall change is easy; the firewall doesn&#8217;t have a budget meeting. Saying to a board, in writing, with your name on it, &#8220;I recommend we accept this risk for the next two quarters, here&#8217;s why, and here&#8217;s what would make me change my mind&#8221; is a different muscle. Most of us build it late.</p><p>My own sharpest lesson here didn&#8217;t come from saying no. It came from not insisting. Early in a role I&#8217;d joined as the new security lead, I started where I always do: assessing how mature the processes and controls actually were. One of those checks was simple, what traffic was really going in and out of the network. The person who had effectively hired me, the CTO, pushed back: why do you need that, everything here is fine. I was new, I deferred, I moved the check down the list. A few weeks later it turned out that how he was using the infrastructure was exactly the kind of thing that check existed to catch. I would have found it earlier if I had trusted my own assessment instead of the person who hired me. So when I talk about a security leader&#8217;s right to say no, I mean something narrower and harder than vetoing changes: the duty to keep asking your own questions even when the most senior person in the room tells you not to. Sometimes &#8220;no&#8221; is just &#8220;I&#8217;m still going to look.&#8221;</p><p>A few things I try to hold onto, for whatever they&#8217;re worth:</p><ul><li><p><strong>A risk you accept deliberately is safer than one you&#8217;re carrying without knowing it.</strong> A documented, owned, time-bounded acceptance can be reviewed. A fix you marked done without recording what was left over has no owner and no review date, and those are the ones that come back.</p></li><li><p><strong>&#8220;It&#8217;s handled&#8221; is not a risk position.</strong> It&#8217;s a feeling. A position has an owner, a rationale, and a date it gets looked at again.</p></li><li><p><strong>The goal isn&#8217;t a smaller risk list. It&#8217;s a list the management body can actually see.</strong> A leader who hands the board ten risks they understand has done more than one who quietly carried fifty.</p></li></ul><p>None of this means I stopped closing things. Patches still matter; weak controls are still weak. And I want to be careful here, because &#8220;manage the risk, don&#8217;t just remove it&#8221; is easy to twist into &#8220;so I can leave things open and call it accepted.&#8221; That is not the failure I actually see. What I see is closer to the opposite: teams that don&#8217;t document at all, close only what is on fire, and leave the quieter risks both unfixed and unrecorded, no owner, no review date, nothing. In most of the teams I&#8217;ve seen up close, it isn&#8217;t deliberate neglect. They&#8217;re buried in operational routine because the process, the planning and the communication underneath were never built, so from the outside it looks like neglect. They miss the business risks not because they don&#8217;t care, but because they aren&#8217;t speaking the same language as the business, or they&#8217;ve been pushed so far from it that &#8220;doing the technology&#8221; starts to look like the whole job. In that world, managing risk isn&#8217;t permission to do less. It&#8217;s the thing that drags the quiet risks into the open where someone can finally own them. And an acceptance isn&#8217;t a waiver: signing one doesn&#8217;t move what the law, the regulator, or the contract already requires of you.</p><p>What changed is what I think the job is. I used to measure myself by what I had eliminated. Now I think a security leader&#8217;s real output is a smaller, stranger thing: a set of decisions the company made with its eyes open, that someone owns, that someone can defend. Most of the value isn&#8217;t in the risks you removed. It&#8217;s in the ones you chose to keep, and the fact that choosing was deliberate.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/p/the-job-was-never-to-remove-the-risk?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/p/the-job-was-never-to-remove-the-risk?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>You don&#8217;t get a clean scoreboard for that. The risks are still there, and they still belong to the company, not to me. What changed is that each one has a name against it and a date it gets looked at again. Chosen, not inherited. That&#8217;s the difference between running security and just reacting to it.</p>]]></content:encoded></item><item><title><![CDATA[What Actually Happens in Your First Year of Security After Licensing]]></title><description><![CDATA[It's a build project with a deadline, not an operations hire. Here's what the first 12 months look like and what regulators check first.]]></description><link>https://www.fromciso.com/p/first-year-security-after-fintech-licensing</link><guid isPermaLink="false">https://www.fromciso.com/p/first-year-security-after-fintech-licensing</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Wed, 01 Apr 2026 16:52:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9a6a33c4-606a-4f9a-b81b-def7bcfb54fd_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p>Your first year of security is a time-boxed build project (gap analysis, policies, incident response, vendor risk register, DORA Register of Information), not an ongoing operations function. Plan it like a product launch.</p></li><li><p>After the build phase, ongoing security maintenance for a 30-100 person fintech runs 10-15 hours per week. That&#8217;s not a full-time CISO job.</p></li><li><p>Three options to close the function: full-time CISO, fractional/vCISO, or security engineer + compliance consultant. The right choice depends on your stage, not your ambition.</p></li><li><p>The most expensive mistake isn&#8217;t overpaying. It&#8217;s hiring someone who builds the wrong framework and you discover it during your first regulatory inspection.</p></li><li><p>EU regulators (Latvijas Banka, Bank of Lithuania) are prioritizing ICT governance, business continuity, and the DORA Register of Information in 2025-2026 supervision cycles. Know what they look for before they arrive.</p></li></ul><div><hr></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/subscribe?"><span>Subscribe now</span></a></p><p>You just got your EMI license. Or your PI authorization. Or maybe you closed a Series A and the term sheet had a line about &#8220;information security governance&#8221; that you nodded through at 2am.</p><p>Now it&#8217;s Tuesday morning and three things landed in your inbox. Your banking partner wants evidence of PCI DSS compliance before onboarding. An investor&#8217;s due diligence questionnaire asks about your incident response plan (you don&#8217;t have one). And someone from <a href="https://www.bank.lv/en/">Latvijas Banka</a> sent a politely worded letter about DORA reporting obligations with a deadline that&#8217;s closer than you thought.</p><p>All of this is sitting on your desk because you&#8217;re the CTO. And you&#8217;re already building the product.</p><p>I&#8217;ve been on the other side of this conversation about a dozen times in the past three years, usually sitting across from a CTO in Riga, Vilnius, or Warsaw who looks exactly like this. Smart, technical, stretched thin, and slightly panicking about a domain they didn&#8217;t sign up to own. This article is what I wish someone had handed them on day one.</p><h2>The first year is a build project, not an operations role</h2><p>Here&#8217;s the thing most CTOs get wrong: they think hiring for security means hiring someone to do security, day in, day out, forever. That&#8217;s not what year one looks like.</p><p>Year one of security in a 30-100 person fintech is a build project. It has a scope, deliverables, and a deadline. It looks like this:</p><p><strong>Months 1-3:</strong> Gap analysis against your regulatory framework. For most EU fintechs right now, that means <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554">DORA (Regulation EU 2022/2554, fully applicable since January 17, 2025)</a> and whatever your license conditions require. You map what exists, what&#8217;s missing, and what&#8217;s urgent. You also scope your PCI DSS cardholder data environment if you&#8217;re processing payments. <a href="https://www.pcisecuritystandards.org/document_library/">PCI DSS 4.0.1</a> is now the only active version, and all future-dated requirements became mandatory on March 31, 2025. This isn&#8217;t optional if Visa or Mastercard is in your stack.</p><p><strong>Months 3-6:</strong> Policy development. <a href="https://www.fromciso.com/p/dora-compliance-roadmap">ICT risk management framework</a> (<a href="https://doralib.fromciso.com">DORA Articles 5-15</a>, or <a href="https://www.fromciso.com/p/dora-proportionality">Article 16 simplified framework</a> if you qualify), incident response procedures, business continuity plan, access control policy, change management. For a company of 50 people, this is typically 12-18 documents. Not boilerplate downloaded from a template site, but policies that actually reflect how your engineering team works.</p><p><strong>Months 6-9:</strong> Operational build-out. Incident response tabletop exercises. Vendor risk register populated with your actual third-party providers. DORA <a href="https://www.fromciso.com/p/dora-documents-library-guide">Register of Information</a> (the structured register of all ICT third-party contractual arrangements) compiled and formatted for regulatory submission. Security awareness training rolled out. Vulnerability scanning operationalized.</p><p><strong>Months 9-12:</strong> Testing and hardening. Internal audit of the framework. Penetration testing. Remediation of findings. Preparation for your first regulatory dialogue or supervision visit.</p><p>That&#8217;s the build phase. It&#8217;s intense. It&#8217;s 20-30 hours per week of dedicated security work, sometimes more during policy sprints.</p><p>And then it drops off a cliff.</p><h2>After the build: maintenance mode is smaller than you think</h2><p>Once the framework is standing, the ongoing work for a 30-100 person fintech looks different. I&#8217;ve tracked this across multiple engagements: <strong>10-15 hours per week</strong> covers it for a company in this size range that isn&#8217;t experiencing active incidents or going through a major audit cycle.</p><p>That weekly cadence breaks down roughly like this: monitoring and alert triage (2-3 hours), policy reviews and updates triggered by changes in your tech stack or org (2-3 hours), vendor risk management for new or renewing contracts (2-3 hours), incident response coordination when something happens (variable, but usually 1-2 hours of non-incident coordination), and board/management reporting plus regulatory correspondence (2-3 hours).</p><p><strong>This is not a full-time job.</strong> And that single fact should reshape how you think about your security hiring decision.</p><p>I&#8217;ve seen too many fintechs hire a full-time CISO at month one, pay them &#8364;120-180K per year, and then watch them run out of meaningful work by month eight. They start empire-building, requesting headcount, buying tools nobody needs, and turning a lean security function into a cost center that&#8217;s hard to unwind.</p><blockquote><p>The most important question isn&#8217;t &#8220;should I hire a CISO?&#8221; It&#8217;s &#8220;how many hours per week does this function actually need right now?&#8221;</p></blockquote><h2>Three ways to close the security function</h2><p>This isn&#8217;t a sales pitch for any one model. I&#8217;ve used all three, and each one has a place. Here&#8217;s when.</p><h3>Option 1: Full-time CISO</h3><p><strong>When it fits:</strong> Your security operations consistently require 30+ hours per week, you&#8217;re processing high volumes of sensitive data, you have multiple regulatory frameworks in play simultaneously, and you&#8217;re large enough (typically 200+ people) that the CISO needs to manage a team, not just a program.</p><p><strong>When it doesn&#8217;t:</strong> You&#8217;re a 40-100 person fintech in your first two years post-licensing. I&#8217;m not hedging here. I&#8217;ve seen this play out repeatedly, and the full-time CISO at this stage almost always leads to one of two outcomes: you overpay for the build phase and then have an expensive employee with not enough to do, or you hire someone junior enough to afford but too junior to build the framework correctly. Both are bad.</p><p><strong>Cost reality:</strong> Full-time CISO compensation in Europe ranges from &#8364;100K to &#8364;200K+ depending on jurisdiction and experience. In the US, total compensation (salary, benefits, equity) averages $260K-$330K for companies under $200M revenue, according to the <a href="https://www.iansresearch.com/resources/all-blogs/post/security-budget-benchmark-blog/2024/10/15/ciso-compensation-survey">IANS Research 2025 compensation data</a>. Add recruiting costs (20-25% of first-year salary) and you&#8217;re looking at a significant cash commitment before they&#8217;ve written a single policy.</p><h3>Option 2: Fractional CISO / vCISO</h3><p><strong>When it fits:</strong> The build phase plus ongoing maintenance. A seasoned fractional CISO has done this build 5, 10, maybe 20 times across different companies. They know what Latvijas Banka asks for during ICT inspections because they&#8217;ve sat through those conversations before. They bring templates that have survived audits, not templates downloaded from an ISO 27001 vendor&#8217;s marketing page.</p><p><strong>The economics:</strong> In Europe, vCISO retainers typically run &#8364;5,000-&#8364;15,000 per month depending on scope. In North America, hourly rates range from $200-$350. A build-phase engagement (heavy hours for 6-9 months) followed by a maintenance retainer (lighter hours) might total &#8364;80-120K for the full first year. That&#8217;s less than a full-time hire, and you get someone who starts delivering from week one because they&#8217;ve done this before.</p><p><strong>What to watch for:</strong> Not all vCISOs are created equal. Some are former big-company CISOs who&#8217;ve never worked with a 50-person startup. Some are consultants who&#8217;ll hand you a gap analysis spreadsheet and disappear. The good ones stay accountable for the outcome: they&#8217;ll attend your regulatory meetings, own the DORA Register of Information, and pick up the phone when you have an incident at 11pm on a Saturday.</p><p><strong>The downside nobody mentions:</strong> Availability. A fractional CISO is working with 3-5 clients. If two clients have incidents in the same week, you&#8217;re sharing their attention. Get this into the contract: SLA for response times, clearly defined hours, and escalation procedures.</p><h3>Option 3: Security engineer + external compliance consultant</h3><p><strong>When it fits:</strong> You already have a strong internal engineer who&#8217;s technically capable, security-minded, and already handling some security work. What they lack isn&#8217;t technical skill but governance experience: how to write policies that satisfy a regulator, how to structure a risk register, how to prepare for a DORA supervision visit.</p><p>In this model, the engineer handles day-to-day security operations (vulnerability management, access reviews, incident triage) while an external compliance consultant builds the governance layer. The consultant comes in 2-3 days per month for framework design, policy review, and regulatory preparation. The engineer executes.</p><p><strong>When it breaks down:</strong> If the engineer doesn&#8217;t have governance instincts and the consultant isn&#8217;t technically competent enough to understand your stack. I&#8217;ve seen this model produce beautiful policy documents that have no connection to how the company actually operates. The regulator will notice.</p><h2>The Security Staffing Decision Matrix</h2><p>Here&#8217;s a simple model I use with CTOs. It maps the key factors to the right staffing model for fintechs in their first two years:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pesv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pesv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 424w, https://substackcdn.com/image/fetch/$s_!pesv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 848w, https://substackcdn.com/image/fetch/$s_!pesv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 1272w, https://substackcdn.com/image/fetch/$s_!pesv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pesv!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png" width="1200" height="393.13186813186815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91a22f5b-c623-4b29-af34-07a152068791_2460x806.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:477,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:351191,&quot;alt&quot;:&quot;Security staffing decision matrix comparing Full-time CISO, Fractional CISO, and Engineer + Consultant models across company size, regulatory complexity, internal capability, hours needed, cost, time to first deliverable, and cross-company experience&quot;,&quot;title&quot;:&quot;Security Staffing Decision Matrix&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/192637102?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Security staffing decision matrix comparing Full-time CISO, Fractional CISO, and Engineer + Consultant models across company size, regulatory complexity, internal capability, hours needed, cost, time to first deliverable, and cross-company experience" title="Security Staffing Decision Matrix" srcset="https://substackcdn.com/image/fetch/$s_!pesv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 424w, https://substackcdn.com/image/fetch/$s_!pesv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 848w, https://substackcdn.com/image/fetch/$s_!pesv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 1272w, https://substackcdn.com/image/fetch/$s_!pesv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91a22f5b-c623-4b29-af34-07a152068791_2460x806.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The Security Staffing Decision Matrix</figcaption></figure></div><blockquote><p>If your honest answer is &#8220;we need 10-15 hours per week after the build phase,&#8221; a full-time CISO is the wrong hire. Period.</p></blockquote><h2>The most expensive mistake: hiring the wrong person</h2><p>This one isn&#8217;t about money. It&#8217;s about time.</p><p>I worked with a Latvian EMI in 2024 that hired a security manager who&#8217;d spent 15 years in corporate IT at a telco. Good resume, real certifications, nice person. Six months later, they had an ISO 27001-style information security management system in place. Clean documentation. Proper control matrices.</p><p>One problem: the regulator didn&#8217;t ask for ISO 27001. They asked about DORA compliance. The DORA ICT risk management framework has specific requirements that ISO 27001 doesn&#8217;t cover: the Register of Information for third-party ICT providers (Article 28), specific incident classification and reporting timelines, <a href="https://www.fromciso.com/p/resilience-kpis">digital operational resilience testing</a> requirements, and the <a href="https://www.fromciso.com/p/board-accountability-in-dora">board accountability provisions</a>. The security manager had built the wrong framework, and six months of work needed to be substantially reworked.</p><p>That&#8217;s the real cost. Not the salary. The rework, plus the missed regulatory deadline, plus the reputational damage of showing up to a supervision dialogue unprepared.</p><h3>Four questions to screen a security hire (if you&#8217;re not a security expert yourself)</h3><p>If you&#8217;re a CTO interviewing CISO candidates and you&#8217;re not a security specialist, these four questions will tell you whether someone understands fintech-specific security work:</p><p><strong>1. &#8220;Walk me through how you&#8217;d build our DORA Register of Information. What data do you need, and where does it come from?&#8221;</strong></p><p>Good answer: They describe identifying all ICT third-party service providers, mapping contractual arrangements, classifying which support critical or important functions, and structuring the data into the ITS template format for regulatory submission. They mention talking to procurement, engineering, and operations to build the inventory.</p><p>Red flag: They don&#8217;t know what the Register of Information is, or they conflate it with a generic vendor list.</p><p><strong>2. &#8220;We process card payments. How would you scope our PCI DSS cardholder data environment, and where do you expect the boundaries to be?&#8221;</strong></p><p>Good answer: They ask about your payment flow, tokenization strategy, and which systems touch cardholder data. They talk about reducing scope through segmentation and outsourcing card data storage to a PCI-compliant processor.</p><p>Red flag: They jump straight to &#8220;we need to be PCI DSS compliant&#8221; without asking about your architecture first. Scope is everything in PCI DSS, and bad scoping wastes months.</p><p><strong>3. &#8220;If we had a ransomware incident at 3am on a Saturday, what&#8217;s the first hour look like?&#8221;</strong></p><p>Good answer: They describe a concrete incident response sequence: containment, evidence preservation, internal notification chain, regulatory notification assessment (DORA requires initial notification within 4 hours of classifying a major ICT incident), and communication to affected parties. They mention not wiping systems before forensic imaging.</p><p>Red flag: They start with &#8220;call the police&#8221; or &#8220;notify the insurance company.&#8221; Those come later. The first hour is about containment and evidence.</p><p><strong>4. &#8220;What does proportionality mean in the context of DORA implementation for a company our size?&#8221;</strong></p><p>Good answer: They reference Article 4 of DORA, explain that requirements should be implemented in proportion to size, risk profile, and complexity of services. They give a concrete example: &#8220;A 50-person EMI doesn&#8217;t need a dedicated ICT risk control function the way a bank does, but it still needs documented ICT risk management.&#8221;</p><p>Red flag: They&#8217;ve never heard of <a href="https://www.fromciso.com/p/dora-proportionality">proportionality</a> in DORA, or they treat every requirement as equally weighted regardless of company size. This person will over-engineer everything and burn your budget on controls you don&#8217;t need.</p><h2>What regulators actually look for (and where they find gaps)</h2><p>I want to be specific here because &#8220;what does the regulator check?&#8221; is the question every CTO asks, and the answers they find online are usually just lists of DORA articles. That&#8217;s not useful. Here&#8217;s what actually happens.</p><h3>Latvijas Banka (Latvia)</h3><p>Latvijas Banka published its <a href="https://www.bank.lv/en/operational-areas/supervision/supervision-priorities-and-inspection-plan/latvijas-banka-s-financial-market-supervision-plan-2026">2026 supervision priorities</a> in January. The fintech-relevant focus areas are explicit: DORA compliance, ICT governance, outsourcing management, operational resilience, and business continuity. For 2026, they&#8217;ve planned 3 ICT-focused on-site inspections across the financial sector, plus 11 thematic off-site inspections and supervisory dialogues.</p><p>In practice, here&#8217;s what I&#8217;ve seen them focus on during supervision visits and dialogues with fintechs:</p><p><strong><a href="https://roi.fromciso.com">Register of Information</a>.</strong> The first submission deadline was April 15, 2025 (with data as of March 31, 2025). Going forward, it&#8217;s annual by March 1 with data as of December 31. If your register is incomplete, poorly structured, or missing critical ICT providers, that&#8217;s the first finding. This is the single most visible compliance artifact because it&#8217;s submitted directly to the regulator.</p><p><strong><a href="https://www.fromciso.com/p/dora-cto-ciso-resilience">ICT governance documentation</a>.</strong> Do you have a documented ICT risk management framework? Does it match what you actually do? They&#8217;ll ask for the framework document and then ask your CTO or security lead to walk through it verbally. Mismatches between documentation and reality are a common finding.</p><p><strong>Business continuity and incident response.</strong> Not just &#8220;do you have a plan&#8221; but &#8220;when did you last test it?&#8221; They want evidence of tabletop exercises, test results, and lessons learned. A business continuity plan that&#8217;s never been tested is a finding waiting to happen.</p><p><strong>Outsourcing oversight.</strong> For fintechs that outsource heavily (and most do), they look at whether you&#8217;ve assessed the ICT risks of your outsourcing arrangements and whether your contracts include the mandatory DORA provisions (audit rights, exit strategies, sub-outsourcing controls).</p><h3><a href="https://www.lb.lt/en/">Bank of Lithuania</a></h3><p>Lithuania is one of the most fintech-dense jurisdictions in the EU. The Bank of Lithuania supervises hundreds of EMIs, PIs, and payment institutions. Their DORA supervision has been building since 2025, with particular attention to ICT risk management and outsourcing (a big deal in a market where many fintechs outsource development to third-party teams).</p><p>The pattern is similar: Register of Information compliance, ICT governance documentation, and incident reporting capability. But Lithuania also places heavy emphasis on AML/CFT alongside security, so expect supervision visits to cover both domains. If your security framework doesn&#8217;t address how security controls support AML transaction monitoring integrity, you&#8217;ve got a gap.</p><h3>What they all have in common</h3><p>Across Baltic and Central European regulators, the first supervision cycle post-DORA is focused on three things: do you have the framework documented, can you explain it, and have you submitted your Register of Information correctly? They&#8217;re not doing deep technical penetration testing of your systems. They&#8217;re checking governance. That&#8217;s both good news (it&#8217;s achievable) and a warning (you can&#8217;t fake it with a Confluence page labeled &#8220;Security Policy&#8221; that nobody reads).</p><h2>What to do on Monday morning</h2><p>If you&#8217;re a CTO reading this and recognizing yourself in the first paragraph, here&#8217;s the sequence:</p><p><strong>This week:</strong> Decide which model you need (full-time, fractional, or engineer + consultant). Use the decision matrix above. Be honest about your hours-per-week number.</p><p><strong>This month:</strong> If you don&#8217;t have a <a href="https://roi.fromciso.com">DORA Register of Information</a>, that&#8217;s priority one. The next submission cycle will come whether you&#8217;re ready or not.</p><p><strong>This quarter:</strong> Get your ICT risk management framework documented and reviewed. Not perfect, but documented. A regulator would rather see an honest framework with known gaps than a polished document that doesn&#8217;t match reality.</p><p><strong>By month six:</strong> Run your first <a href="https://www.fromciso.com/p/dora-compliance-audit">incident response tabletop exercise</a>. Invite your CTO, operations lead, and whoever handles customer communications. Record the findings. Fix them.</p><p>Security in a post-licensing fintech isn&#8217;t mysterious. It&#8217;s a project with knowable deliverables, reasonable timelines, and a clear finish line for the build phase. The trick is treating it that way instead of either ignoring it or over-engineering it.</p><p>The CTOs who get this right aren&#8217;t the ones who hire the most expensive CISO. They&#8217;re the ones who correctly estimate the scope.</p><div><hr></div><p><em>If you found this useful, share it with a CTO who just got licensed. And if you&#8217;ve been through this build phase yourself, I&#8217;d love to hear how your first year went. What surprised you? Reply or leave a comment.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/p/first-year-security-after-fintech-licensing?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/p/first-year-security-after-fintech-licensing?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div>]]></content:encoded></item><item><title><![CDATA[DORA Documents Library (doralib.fromciso.com): A Practical Guide for DORA Readiness]]></title><description><![CDATA[A fast way to find, filter, and share DORA regulatory sources for real compliance work.]]></description><link>https://www.fromciso.com/p/dora-documents-library-guide</link><guid isPermaLink="false">https://www.fromciso.com/p/dora-documents-library-guide</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Mon, 16 Feb 2026 07:01:38 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e7efad1a-f35b-4417-9c13-9b20ee50b2cd_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>TL;DR</h2><ul><li><p>DORA&#8217;s regulatory ecosystem spans 27+ documents across Level 1 legislation, Level 2 RTS/ITS, and Level 3 guidelines &#8212; scattered across EUR-Lex, EBA, ESMA, EIOPA, and ECB portals.</p></li><li><p><a href="https://doralib.fromciso.com">doralib.fromciso.com</a> is a free, searchable index that centralises all of them with filtering by category, keyword search, and a capability map view.</p></li><li><p>This guide walks through five real compliance scenarios where the library saves time: gap assessments, incident reporting setup, contract reviews, audit evidence, and TLPT preparation.</p></li><li><p>Includes a quick-reference checklist: which DORA documents you actually need, by pillar.</p></li><li><p>The library is a research accelerator, not legal advice. Always validate applicability with your Legal and Compliance stakeholders.</p></li></ul><div><hr></div><p>Last quarter, a compliance lead at a mid-sized EMI asked me a simple question: &#8220;Where&#8217;s the final version of the DORA incident reporting RTS?&#8221;</p><p>She&#8217;d been looking for twenty minutes. She had three browser tabs open &#8212; EUR-Lex, the EBA website, and a Google search that kept returning the 2023 consultation draft instead of the adopted version (RTS 2025/301). Her legal team had sent her a different link the week before. Neither of them was sure they were reading the current text.</p><p>This is a compliance professional. She knows what she&#8217;s looking for. The problem isn&#8217;t knowledge &#8212; it&#8217;s that DORA&#8217;s regulatory sources are scattered across at least five EU institutional portals, published on different dates, with confusing version histories. And the documents themselves don&#8217;t make it easy: &#8220;Commission Delegated Regulation (EU) 2024/2956&#8221; doesn&#8217;t exactly roll off the tongue when you&#8217;re trying to explain to Procurement what the Register of Information template requires.</p><p>I built <a href="https://doralib.fromciso.com">doralib.fromciso.com</a> to fix that specific problem. Not a content library. Not a compliance platform. Just a fast, searchable index of every DORA regulatory source, organised so you can find the right document in under 30 seconds instead of twenty minutes.</p><p>Here&#8217;s how to get the most out of it.</p><div><hr></div><h2>What&#8217;s actually in the DORA regulatory ecosystem (and why it&#8217;s hard to navigate)</h2><p>Before the &#8220;how-to&#8221; part, some context on <em>why</em> a library like this is necessary.</p><p>DORA (Regulation (EU) 2022/2554) entered into force on 17 January 2025. But the regulation itself &#8212; the Level 1 text &#8212; is just the framework. The operational detail lives in a growing set of Level 2 technical standards and Level 3 guidelines developed by the European Supervisory Authorities (ESAs: EBA, EIOPA, and ESMA).</p><p>As of early 2026, the DORA ecosystem includes roughly <a href="https://www.fromciso.com/p/the-dora-library-all-27-regulatory">27 documents</a>:</p><ul><li><p><strong>2 Level 1 texts</strong> &#8212; the core DORA regulation and the amending directive</p></li><li><p><strong>~8 RTS</strong> (Regulatory Technical Standards) &#8212; defining what &#8220;good&#8221; looks like for ICT risk management, incident classification, third-party contractual policies, TLPT methodology, and subcontracting</p></li><li><p><strong>~3 ITS</strong> (Implementing Technical Standards) &#8212; standard templates and forms for incident reporting, the Register of Information, and related submissions</p></li><li><p><strong>Guidelines, opinions, and supporting reports</strong> &#8212; from the ESAs, ECB, and ENISA, covering everything from oversight cooperation to the TIBER-EU framework alignment</p></li></ul><p>These documents were published in batches across 2023&#8211;2025. Some went through multiple consultation rounds. The subcontracting RTS (2025/532) was adopted as late as March 2025 after the European Commission removed a provision that exceeded the original mandate. New guidance continues to appear.</p><p><strong>The practical problem:</strong> if you&#8217;re building a DORA control framework, writing policies, or preparing for an audit, you need to reference the <em>right version</em> of the <em>right document</em> &#8212; and the EU portals don&#8217;t make that easy. EUR-Lex has the legal text but no operational context. The ESAs publish final reports alongside the standards, but on separate pages. Google returns consultation drafts mixed with final versions.</p><blockquote><p><strong>DORA isn&#8217;t one PDF. It&#8217;s an ecosystem of 27+ documents, published across five portals, over three years. If you&#8217;re not sure you&#8217;re reading the current version, you&#8217;re not alone.</strong></p></blockquote><div><hr></div><h2>How to use doralib.fromciso.com in your workflow</h2><p>The library is at <a href="https://doralib.fromciso.com">doralib.fromciso.com</a>. No login, no paywall, no email gate. Bookmark it and share the link with your team &#8212; consistency in sources matters more than most people realise.</p><p>Here are five ways I use it (and recommend clients use it) in real DORA work.</p><h3>1. Running a DORA gap assessment</h3><p>When you start a gap assessment, you need to know which documents define the requirements for each DORA pillar. The library&#8217;s <strong>category filter</strong> (Regulation / RTS / ITS / Reports &amp; Opinions) lets you pull up just the Level 2 standards relevant to your scope.</p><p><strong>How I do it:</strong> I filter by RTS, scan the titles, and map each one to a DORA pillar in my assessment template. For ICT risk management alone, the relevant RTS prescribes 20 policies and procedures. I learned this the hard way &#8212; my first DORA gap assessment was scoped entirely from the Level 1 text, and I missed about half the required controls. The Level 2 detail is where the real implementation effort hides.</p><p>If you&#8217;re building a gap assessment from scratch, I wrote a <a href="https://www.fromciso.com/p/dora-compliance-roadmap">step-by-step DORA compliance roadmap</a> that walks through the full process, starting with governance and ownership.</p><blockquote><p><strong>Start your gap assessment from the RTS, not the regulation. The Level 1 text tells you </strong><em><strong>what</strong></em><strong> to do. The RTS tells you </strong><em><strong>how much</strong></em><strong> &#8212; and that&#8217;s where most teams underestimate the work.</strong></p></blockquote><h3>2. Setting up incident reporting</h3><p>Incident reporting is where DORA gets operationally demanding. The reporting timeline is tight &#8212; initial notification within 4 hours for major incidents, intermediate report within 72 hours, final report within one month. The classification criteria use six dimensions (clients affected, duration, geographic spread, data losses, economic impact, criticality of services).</p><p>The library groups the incident-related documents together:</p><ul><li><p><strong>RTS 2025/301</strong> &#8212; content and timelines for incident reports</p></li><li><p><strong>ITS 2025/302</strong> &#8212; the actual templates and forms</p></li><li><p><strong>The incident classification RTS</strong> &#8212; how to determine if an incident is &#8220;major&#8221;</p></li><li><p><strong>The ESA final report (JC 2023 83)</strong> &#8212; the rationale and worked examples behind the classification thresholds</p></li></ul><p>Most teams I work with start by reading the regulation text (Article 19), then try to build their own reporting templates from scratch. One fintech client spent three weeks designing custom forms before discovering that the ITS provides standard templates. Three weeks of wasted work. The library links the RTS, ITS, and supporting report together so you can pull up all three in one search instead of navigating three separate ESA publication pages.</p><h3>3. Reviewing vendor contracts for DORA compliance</h3><p>Third-party risk management (DORA Articles 28&#8211;30) requires specific contractual clauses: audit rights, data location provisions, exit strategies, subcontracting controls, and service level descriptions. The RTS on contractual policies adds detail. The subcontracting RTS (2025/532), adopted in March 2025, adds further constraints on how ICT services supporting critical functions can be subcontracted.</p><p><strong>How I use the library here:</strong> Before a contract review session with Legal and Procurement, I pull up the relevant RTS entries and share direct links. In a recent contract renegotiation with a cloud infrastructure provider, linking directly to Section 3 of the contractual policy RTS cut the back-and-forth from three review rounds to one &#8212; because everyone was reading the same text, not paraphrasing from memory.</p><p>When Legal, Procurement, and Security work from the same source links, the debate shifts from &#8220;which version are we reading?&#8221; to &#8220;how do we implement this clause?&#8221; That&#8217;s a better use of everyone&#8217;s time. For more on the vendor side of DORA compliance, I covered the <a href="https://www.fromciso.com/p/dora-cto-ciso-resilience">CTO-CISO coordination model for vendor oversight</a> in a separate piece.</p><h3>4. Building audit evidence packs</h3><p>Auditors want to see that your controls trace back to regulatory requirements. The library helps you build a &#8220;Regulatory Sources&#8221; appendix in your evidence pack &#8212; a list of which documents you referenced, which version, and where the specific expectation comes from.</p><p><strong>How I did it last quarter:</strong> When I built an evidence pack for a PI client&#8217;s first DORA readiness review, the &#8220;Regulatory Sources&#8221; appendix took me about 15 minutes to compile. For an ICT risk management control like &#8220;annual risk assessment,&#8221; the appendix referenced:</p><ul><li><p>DORA Article 6 (Level 1 requirement)</p></li><li><p>The ICT Risk Management RTS (Level 2 detail on what the assessment must cover)</p></li><li><p>The ESA final report explaining the regulatory rationale</p></li></ul><p>Each entry included a library link. The auditor later told me this was the first evidence pack they&#8217;d reviewed where every regulatory reference was a working link to the current version. That shouldn&#8217;t be unusual, but it is.</p><h3>5. Preparing for threat-led penetration testing (TLPT)</h3><p>TLPT is the most operationally complex DORA requirement. Significant financial entities must complete their first TLPT exercise before 17 January 2028, with ongoing tests every three years thereafter.</p><p>I&#8217;ve started scoping TLPT for two significant entities this year. The first thing you discover is that the documentation is split between multiple institutions &#8212; the ESAs, the ECB, and the Official Journal &#8212; each publishing different parts of the puzzle. The library connects all three key documents:</p><ul><li><p><strong>RTS 2025/1190</strong> &#8212; scope, methodology, and assessor criteria for TLPT</p></li><li><p><strong>The TIBER-EU framework</strong> (updated by the Eurosystem in February 2025) &#8212; detailed phase-by-phase guidance for what is typically a 9&#8211;14 month process</p></li><li><p><strong>The ESA final report on TLPT</strong> &#8212; regulatory rationale and expectations</p></li></ul><p>Having all three accessible from one place &#8212; instead of navigating the ECB publications page, the Official Journal, and the ESA reports separately &#8212; saves real time during scoping. For entities tracking the relevant <a href="https://www.fromciso.com/p/resilience-kpis">resilience KPIs</a>, the TLPT section of the library maps directly to your testing pillar metrics.</p><div><hr></div><h2>The DORA Capability Map</h2><p>The library includes what I call the <strong>DORA Capability Map</strong> &#8212; a view that organises documents by operational pillar rather than document type.</p><p>This matters because DORA programs are usually structured around capabilities (ICT risk management, incident reporting, third-party risk, resilience testing, information sharing), not around document categories. The capability map lets you:</p><ul><li><p><strong>Assign document ownership</strong> &#8212; &#8220;Who in the team is responsible for the incident reporting pillar? Here are the four documents they need to know.&#8221;</p></li><li><p><strong>Spot coverage gaps</strong> &#8212; if your implementation backlog doesn&#8217;t have work items for TLPT, the capability map makes that visible immediately.</p></li><li><p><strong>Structure steering committee updates</strong> &#8212; report progress by capability area, with links to the relevant standards for each.</p></li></ul><blockquote><p><strong>If you take one thing from this guide: organise your DORA program by capability, not by document type. The DORA Capability Map is there to make that easier.</strong></p></blockquote><div><hr></div><h2>Quick reference: which documents do you actually need?</h2><p>Not every entity needs every document. Here&#8217;s a checklist by DORA pillar &#8212; find your scope, pull the relevant entries from the library, and ignore the rest.</p><p><strong>ICT Risk Management (all entities)</strong></p><ul><li><p>Core DORA regulation (Articles 5&#8211;16)</p></li><li><p>ICT Risk Management RTS (full or simplified framework)</p></li><li><p>ESA final report on ICT Risk Management (JC 2023 86) &#8212; for rationale and interpretation</p></li></ul><p><strong>Incident Reporting (all entities)</strong></p><ul><li><p>Incident Classification RTS &#8212; the 6 criteria for &#8220;major&#8221; incidents</p></li><li><p>RTS 2025/301 &#8212; reporting content and timelines</p></li><li><p>ITS 2025/302 &#8212; standard templates and forms</p></li><li><p>ESA final report (JC 2023 83) &#8212; worked examples and thresholds</p></li></ul><p><strong>Third-Party Risk Management (all entities with ICT outsourcing)</strong></p><ul><li><p>Contractual Policy RTS &#8212; 8 mandatory clauses</p></li><li><p>Subcontracting RTS (2025/532) &#8212; constraints on sub-outsourcing critical functions</p></li><li><p>Register of Information ITS (2024/2956) &#8212; templates for the mandatory ICT provider register</p></li></ul><p><strong>Resilience Testing (all entities; TLPT for significant entities only)</strong></p><ul><li><p>RTS 2025/1190 &#8212; TLPT scope and methodology</p></li><li><p>TIBER-EU framework (updated Feb 2025) &#8212; phase-by-phase guidance</p></li><li><p>ESA final report on TLPT &#8212; regulatory expectations</p></li></ul><p><strong>Oversight &amp; Cooperation (awareness &#8212; primarily for entities with designated CTPPs)</strong></p><ul><li><p>Oversight Harmonisation RTS &#8212; conditions for oversight activities</p></li><li><p>ESA Guidelines on cooperation and information exchange</p></li></ul><p>Use this checklist to build your initial reading list. Then link the relevant library entries to your controls, your evidence, and your steering committee slides. Consistency in sources across Legal, Risk, IT, and Procurement is half the battle.</p><div><hr></div><h2>What this isn&#8217;t</h2><p>A library speeds up research, but it doesn&#8217;t replace governance, gap analysis, or the hard operational work of implementing controls. It indexes regulatory sources &#8212; it doesn&#8217;t interpret them. Always validate applicability with your Legal and Compliance teams for your specific entity type, jurisdiction, and operating model. And check your document versions &#8212; the DORA ecosystem is still developing, with new ESA guidance arriving periodically.</p><div><hr></div><h2>Where to start</h2><p><strong>If you&#8217;re early in your DORA program:</strong></p><ol><li><p>Bookmark <a href="https://doralib.fromciso.com">doralib.fromciso.com</a>. Share the link with Legal, Risk, IT, and Procurement &#8212; get everyone on the same reference point.</p></li><li><p>Use the capability map to identify which documents are relevant to your entity type and operating model.</p></li><li><p>Start your gap assessment from the RTS, not the regulation. The Level 2 detail is where most of the implementation effort hides.</p></li></ol><p><strong>If you&#8217;re mid-program:</strong></p><ol><li><p>Link the relevant library entries to your controls and evidence packs.</p></li><li><p>Use direct document links in audit responses to reduce back-and-forth on &#8220;which version are you referencing?&#8221;</p></li><li><p>Check the TLPT and subcontracting sections &#8212; these are the most recent additions and often the least mature in existing programs.</p></li></ol><p><strong><a href="https://doralib.fromciso.com/?utm_source=fromciso_post&amp;utm_medium=try_out&amp;utm_campaign=dora_library&amp;utm_content=button">Open the DORA Documents Library &#8594;</a></strong></p><p>Which DORA pillar is giving your team the most trouble right now? Tell me in the comments &#8212; I read every reply.</p>]]></content:encoded></item><item><title><![CDATA[Turn the DORA Library into a 24/7 AI Assistant (Free) with NotebookLM]]></title><description><![CDATA[A step-by-step guide to uploading the full DORA document set into NotebookLM and querying it with citations.]]></description><link>https://www.fromciso.com/p/turn-the-dora-library-into-a-free-ai-assistant</link><guid isPermaLink="false">https://www.fromciso.com/p/turn-the-dora-library-into-a-free-ai-assistant</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Mon, 26 Jan 2026 08:07:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2a213fff-e7e1-4332-a1a7-02385c7830f1_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you&#8217;re working on <a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en">DORA</a> in a fintech, your browser history probably looks exactly as I described in <a href="https://www.fromciso.com/p/the-dora-library-all-27-regulatory">the DORA Library post</a>: a crime scene of EUR-Lex tabs, PDFs, and &#8220;wait, which RTS is <em>the</em> one for incident reporting?&#8221; moments.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/subscribe?"><span>Subscribe now</span></a></p><p>That library did well because it solved a very specific pain:</p><ul><li><p>DORA isn&#8217;t one PDF. It&#8217;s a <em>system</em> of documents.</p></li><li><p>Teams lose hours cross-checking Level 1 vs Level 2 (RTS/ITS) vs Level 3 guidance.</p></li><li><p>People needed a single, structured reference point and a &#8220;bookmark + share&#8221; workflow.</p></li></ul><p>In the comments and DMs on <a href="https://www.linkedin.com/feed/update/urn:li:activity:7418386977906974722/">LinkedIn</a>, the next natural step showed up quickly:<br><code>&#8220;Great! Now, how do we turn this into something that helps us work daily, not just read?&#8221;</code></p><p>This article is my answer: <strong>build a DORA-focused AI assistant in NotebookLM</strong> using the exact <a href="https://www.fromciso.com/p/the-dora-library-all-27-regulatory">DORA Library</a> sources so that you can query the framework like a living knowledge base.</p><p>No selling. No &#8220;magic compliance.&#8221; Just a practical workflow that many teams are already using in other domains, but not everyone is applying it to DORA yet.</p><div><hr></div><h2>Who this is for</h2><ul><li><p><strong>CISOs / CTOs</strong> in fintechs who need fast, defensible answers grounded in the actual text</p></li><li><p><strong>GRC / compliance</strong> leads mapping requirements &#8594; controls &#8594; evidence</p></li><li><p><strong>Risk / audit</strong> teams doing reviews and gap analysis under time pressure</p></li></ul><div><hr></div><h2>What you&#8217;ll build in 20&#8211;30 minutes</h2><p>A &#8220;DORA Notebook&#8221; that:</p><ul><li><p>uses <strong>your selected DORA sources</strong> as grounding</p></li><li><p>answers questions <strong>based on the sources you uploaded</strong></p></li><li><p>generates <strong>usable outputs</strong> (briefings, mind maps, audio/video overviews, reports, infographics, slide decks, etc.) to support implementation and internal alignment</p></li></ul><p><a href="https://notebooklm.google/">NotebookLM</a> is explicitly designed to work from <em>your sources</em>; if something isn&#8217;t in the sources, you should expect weaker answers, and you should adjust your question or sources.</p><div><hr></div><h2>NotebookLM: what it is (and why it fits DORA work)</h2><p>Think of <a href="https://notebooklm.google/">NotebookLM</a> as a research and synthesis layer that sits <em>on top of a curated document set</em>. For DORA, that means:</p><ul><li><p>fewer &#8220;hallucinated&#8221; answers (because you push it back to citations and sources)</p></li><li><p>faster cross-referencing across RTS/ITS/guidelines</p></li><li><p>repeatable workflows: incident reporting, ICT risk, TPRM registers, oversight prep, TLPT prep</p></li></ul><div><hr></div><h2>Limits (free plan): why the DORA Library fits</h2><p>As of today, NotebookLM&#8217;s <strong>free</strong> limits are:</p><ul><li><p><strong>100 notebooks</strong></p></li><li><p><strong>up to 50 sources per notebook</strong></p></li><li><p><strong>up to 500,000 words per source</strong> (or up to <strong>200MB</strong> per uploaded file)</p></li><li><p>daily limits: <strong>50 chat queries</strong> and <strong>3 audio generations</strong></p></li></ul><p>Since the DORA Library is 27 documents, it fits cleanly inside the 50-source limit.</p><div><hr></div><h2>Step-by-step: build your &#8220;DORA AI Assistant&#8221; in NotebookLM</h2><h3>Step 1. Open NotebookLM</h3><p>Go to <a href="https://notebooklm.google/">NotebookLM</a> and sign in with your Google account.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ouXQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ouXQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 424w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 848w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 1272w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ouXQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png" width="1456" height="692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:692,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:164520,&quot;alt&quot;:&quot;Screenshot 1: NotebookLM home screen / &#8220;Create notebook&#8221; entry point&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 1: NotebookLM home screen / &#8220;Create notebook&#8221; entry point" title="Screenshot 1: NotebookLM home screen / &#8220;Create notebook&#8221; entry point" srcset="https://substackcdn.com/image/fetch/$s_!ouXQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 424w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 848w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 1272w, https://substackcdn.com/image/fetch/$s_!ouXQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fbf38d1-93c1-41a2-8859-2d19bc47ba0f_2674x1270.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 1: NotebookLM home screen / &#8220;Create notebook&#8221; entry point</figcaption></figure></div><div><hr></div><h3>Step 2. Create a new notebook</h3><p>Name it something obvious, for example:</p><ul><li><p><strong>DORA Copilot &#8212; RTS/ITS/Guidelines</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9mIV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9mIV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 424w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 848w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 1272w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9mIV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png" width="1456" height="826" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:826,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:422374,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9mIV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 424w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 848w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 1272w, https://substackcdn.com/image/fetch/$s_!9mIV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4468959b-1de9-46b4-834a-63eadbe8cfd5_2920x1656.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Screenshot 2: New notebook name + empty Sources panel</em></figcaption></figure></div></li></ul><div><hr></div><h3>Step 3. Add sources from the DORA Library</h3><p>Open <a href="https://www.fromciso.com/p/the-dora-library-all-27-regulatory">the DORA Library article</a> and start adding sources into NotebookLM.</p><blockquote><p>For those who prefer a faster, more practical way to work with the source texts, I&#8217;ve also compiled all 27 DORA regulatory documents into a single archive.</p><p>Each file is renamed and ordered for quick scanning, so your compliance, risk, IT/security, and audit teams can find what they need in seconds instead of hours.</p><p>Free download here: <strong><a href="http://store.fromciso.com/l/EU-DORA-Official-Docs-Pack">store.fromciso.com/l/EU-DORA-Official-Docs-Pack</a></strong></p></blockquote><p>NotebookLM supports multiple source types (PDFs, web URLs, Google Docs/Drive, Word files, etc.).<br>For DORA, <strong>web URLs + official PDFs</strong> are typically the cleanest.</p><p>How to add:</p><ol><li><p>In your notebook, click <strong>+</strong> <strong>Add sources</strong> in the Sources panel.</p></li><li><p>Paste the URLs (or upload PDFs) from the DORA Library list.</p></li><li><p>Keep titles consistent (important for later querying).</p></li></ol><p><strong>Practical naming convention (recommended):</strong></p><ul><li><p><code>DORA-01 Regulation (EU) 2022-2554</code></p></li><li><p><code>DORA-04 RTS ICT Risk Management (EU) 2024-1774</code></p></li><li><p><code>DORA-24 RTS Joint Examination Teams (EU) 2025-420</code></p></li></ul><p>This makes it easier to tell NotebookLM exactly where to look later (&#8220;use sources 8, 9, and 10&#8221;).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bp6g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bp6g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 424w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 848w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 1272w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bp6g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png" width="1194" height="772" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:772,&quot;width&quot;:1194,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196142,&quot;alt&quot;:&quot;Screenshot 3: Sources panel partially filled (10+ sources added)&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 3: Sources panel partially filled (10+ sources added)" title="Screenshot 3: Sources panel partially filled (10+ sources added)" srcset="https://substackcdn.com/image/fetch/$s_!bp6g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 424w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 848w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 1272w, https://substackcdn.com/image/fetch/$s_!bp6g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc25fe11-824d-45ae-b8d4-18d4586f6ed7_1194x772.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Screenshot 3: Sources panel partially filled (10+ sources added)</em></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n82l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n82l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 424w, https://substackcdn.com/image/fetch/$s_!n82l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 848w, https://substackcdn.com/image/fetch/$s_!n82l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 1272w, https://substackcdn.com/image/fetch/$s_!n82l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n82l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png" width="624" height="544" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:544,&quot;width&quot;:624,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109059,&quot;alt&quot;:&quot;Screenshot 4: One source opened, showing its auto-summary / source guide&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 4: One source opened, showing its auto-summary / source guide" title="Screenshot 4: One source opened, showing its auto-summary / source guide" srcset="https://substackcdn.com/image/fetch/$s_!n82l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 424w, https://substackcdn.com/image/fetch/$s_!n82l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 848w, https://substackcdn.com/image/fetch/$s_!n82l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 1272w, https://substackcdn.com/image/fetch/$s_!n82l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a6af3e-a112-40a5-83f8-7887d495c8f2_624x544.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Screenshot 4: One source opened, showing its auto-summary / source guide</em></figcaption></figure></div><p><strong>Important operational detail:</strong> NotebookLM stores a <strong>static copy</strong> of what you upload/import. Drive sources can be manually re-synced; other source types may need re-uploading if the original changes.</p><div><hr></div><h2>Step 4. Validate the notebook (quick check)</h2><p>Before you &#8220;trust&#8221; anything, run one check:</p><h3>Check: coverage</h3><p>Prompt:</p><blockquote><p>&#8220;List all sources currently loaded in this notebook, grouped by DORA pillar.&#8221;</p></blockquote><p>(You&#8217;re validating that the notebook actually contains what you think it contains.)</p><p>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YyBW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YyBW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 424w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 848w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 1272w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YyBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png" width="781" height="663" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:663,&quot;width&quot;:781,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:134562,&quot;alt&quot;:&quot;Screenshot 5:Validate the notebook&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 5:Validate the notebook" title="Screenshot 5:Validate the notebook" srcset="https://substackcdn.com/image/fetch/$s_!YyBW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 424w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 848w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 1272w, https://substackcdn.com/image/fetch/$s_!YyBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1075dea6-b7ba-414b-914d-459a0c469d00_781x663.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Screenshot 5: </em>Validate the notebook</figcaption></figure></div><div><hr></div><h1>Using your DORA Notebook: Chat workflows that actually help</h1><p>Below are practical prompts I&#8217;ve used (and seen work well for CISOs/CTOs/GRC). These are written to reduce ambiguity and force useful outputs&#8212;basic prompt-engineering hygiene that consistently improves quality.</p><h2>1) &#8220;Tell me what I must implement&#8221;</h2><p>Prompt:</p><blockquote><p>&#8220;Act as a fintech GRC lead. From the sources, extract the DORA requirements relevant to ICT incident reporting. Output a table with: Requirement, Trigger/Threshold, Timeline, Evidence Artifact, Owner Role, and the source citation.&#8221;</p></blockquote><p>Why it works: role + scope + structured output.<br>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hz10!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hz10!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 424w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 848w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 1272w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hz10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png" width="773" height="722" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:722,&quot;width&quot;:773,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:160409,&quot;alt&quot;:&quot;Screenshot 6: Tell me what I must implement&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 6: Tell me what I must implement" title="Screenshot 6: Tell me what I must implement" srcset="https://substackcdn.com/image/fetch/$s_!Hz10!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 424w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 848w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 1272w, https://substackcdn.com/image/fetch/$s_!Hz10!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee0b8351-3cfb-47af-8b1d-0e3c4b70c88d_773x722.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 6: Tell me what I must implement</figcaption></figure></div><h2>2) &#8220;Map obligations to controls&#8221;</h2><p>Prompt:</p><blockquote><p>&#8220;Create a control-mapping draft for ICT third-party risk management under DORA. Output as a control catalog: Control Objective, Control Statement, Evidence, Testing Approach, Frequency, RACI, and citations.&#8221;</p></blockquote><p>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hiyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hiyh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 424w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 848w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 1272w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hiyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png" width="838" height="716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:716,&quot;width&quot;:838,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120308,&quot;alt&quot;:&quot;Screenshot 7: Map obligations to controls&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 7: Map obligations to controls" title="Screenshot 7: Map obligations to controls" srcset="https://substackcdn.com/image/fetch/$s_!hiyh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 424w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 848w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 1272w, https://substackcdn.com/image/fetch/$s_!hiyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f6e93dc-33cc-422f-a78f-55f5e38aa2f9_838x716.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 7: Map obligations to controls</figcaption></figure></div><h2>3) &#8220;Compare RTS vs ITS without losing your mind&#8221;</h2><p>Prompt:</p><blockquote><p>&#8220;Compare the incident reporting RTS and ITS: what is normative vs what is template/procedure? Output differences and overlaps, and cite the exact sources.&#8221;</p></blockquote><p>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YmpF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YmpF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 424w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 848w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 1272w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YmpF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png" width="847" height="730" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:730,&quot;width&quot;:847,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152473,&quot;alt&quot;:&quot;Screenshot 8: Compare RTS vs ITS without losing your mind&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 8: Compare RTS vs ITS without losing your mind" title="Screenshot 8: Compare RTS vs ITS without losing your mind" srcset="https://substackcdn.com/image/fetch/$s_!YmpF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 424w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 848w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 1272w, https://substackcdn.com/image/fetch/$s_!YmpF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ad0686f-effe-4e7b-9a66-ea13c700f44c_847x730.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 8: Compare RTS vs ITS without losing your mind</figcaption></figure></div><h2>4) &#8220;Turn requirements into an execution plan&#8221;</h2><p>Prompt:</p><blockquote><p>&#8220;Create a 90-day implementation plan for a mid-sized fintech starting today. Prioritize by risk and dependency. Output: Week-by-week plan, deliverables, and which DORA documents justify each workstream.&#8221;</p></blockquote><p>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JmQv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JmQv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 424w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 848w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 1272w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JmQv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png" width="840" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:840,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185616,&quot;alt&quot;:&quot;Screenshot 9: Turn requirements into an execution plan&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 9: Turn requirements into an execution plan" title="Screenshot 9: Turn requirements into an execution plan" srcset="https://substackcdn.com/image/fetch/$s_!JmQv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 424w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 848w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 1272w, https://substackcdn.com/image/fetch/$s_!JmQv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e811c6b-062c-4d4e-98b0-21496131c6d1_840x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 9: Turn requirements into an execution plan</figcaption></figure></div><h2>5) &#8220;Prepare me for audit questions&#8221;</h2><p>Prompt:</p><blockquote><p>&#8220;Generate 25 audit-style questions a regulator/auditor might ask about our DORA operational resilience testing program, and for each question list what evidence we should show and which sources justify it.&#8221;</p></blockquote><p>Output:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z-pa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z-pa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 424w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 848w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 1272w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z-pa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png" width="838" height="846" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:846,&quot;width&quot;:838,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172884,&quot;alt&quot;:&quot;Screenshot 10: Prepare me for audit questions&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 10: Prepare me for audit questions" title="Screenshot 10: Prepare me for audit questions" srcset="https://substackcdn.com/image/fetch/$s_!Z-pa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 424w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 848w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 1272w, https://substackcdn.com/image/fetch/$s_!Z-pa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dcb7c1a-1da1-407f-a933-b8e3dcd7d7a8_838x846.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 10: Prepare me for audit questions</figcaption></figure></div><div><hr></div><h1>Studio: where NotebookLM becomes a &#8220;content engine&#8221; for your team</h1><p>NotebookLM&#8217;s <strong>Studio</strong> can produce different formats from the same source base&#8212;useful when you need alignment across Security, Engineering, Legal, Procurement, and the Board.</p><p>Studio outputs include <strong>Audio Overviews, Video Overviews, Mind Maps, and Reports</strong>, and you can store multiple outputs per notebook.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z-qG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z-qG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 424w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 848w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 1272w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z-qG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png" width="569" height="251" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:251,&quot;width&quot;:569,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33519,&quot;alt&quot;:&quot;Screenshot 11: NotebookLM&#8217;s Studio&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 11: NotebookLM&#8217;s Studio" title="Screenshot 11: NotebookLM&#8217;s Studio" srcset="https://substackcdn.com/image/fetch/$s_!z-qG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 424w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 848w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 1272w, https://substackcdn.com/image/fetch/$s_!z-qG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be26a6c-94e0-4b42-95be-59dd63d8c4c3_569x251.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 11: NotebookLM&#8217;s Studio</figcaption></figure></div><h2>Studio workflow ideas for DORA</h2><h3>A) Mind Map </h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KCFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KCFX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 424w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 848w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 1272w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KCFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png" width="728" height="1138.6406685236768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1123,&quot;width&quot;:718,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:116736,&quot;alt&quot;:&quot;Screenshot 12: Studio &#8594; Mind Map generated from DORA sources&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 12: Studio &#8594; Mind Map generated from DORA sources" title="Screenshot 12: Studio &#8594; Mind Map generated from DORA sources" srcset="https://substackcdn.com/image/fetch/$s_!KCFX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 424w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 848w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 1272w, https://substackcdn.com/image/fetch/$s_!KCFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa60e3226-98e4-437f-8f67-2814738ae1d6_718x1123.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Screenshot 12: Studio &#8594; Mind Map generated from DORA sources</em></figcaption></figure></div><h3>B) &#8220;Briefing pack&#8221; for leadership (CTO/CISO/Board)</h3><p>Use Studio to generate a role-specific report:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VnoU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VnoU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 424w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 848w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 1272w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VnoU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png" width="852" height="468" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:852,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82838,&quot;alt&quot;:&quot;Screenshot 13: Studio to generate a role-specific report&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 13: Studio to generate a role-specific report" title="Screenshot 13: Studio to generate a role-specific report" srcset="https://substackcdn.com/image/fetch/$s_!VnoU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 424w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 848w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 1272w, https://substackcdn.com/image/fetch/$s_!VnoU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877e46f0-3b39-4d6c-b2b7-76fd4114c2a3_852x468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 13: Studio to generate a role-specific report</figcaption></figure></div><ul><li><p>&#8220;Executive summary (Board-ready): what changed, what we must do, what risk remains&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qyf4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qyf4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 424w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 848w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 1272w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qyf4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png" width="965" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b72423fb-e735-4b98-9213-57e2bde3f350_965x851.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:965,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185786,&quot;alt&quot;:&quot;Screenshot 14: Executive Briefing: Navigating the Digital Operational Resilience Act (DORA)&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 14: Executive Briefing: Navigating the Digital Operational Resilience Act (DORA)" title="Screenshot 14: Executive Briefing: Navigating the Digital Operational Resilience Act (DORA)" srcset="https://substackcdn.com/image/fetch/$s_!Qyf4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 424w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 848w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 1272w, https://substackcdn.com/image/fetch/$s_!Qyf4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb72423fb-e735-4b98-9213-57e2bde3f350_965x851.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 14: Executive Briefing: Navigating the Digital Operational Resilience Act (DORA)</figcaption></figure></div></li><li><p>&#8220;Engineering summary: required capabilities and operational changes&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KuxL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KuxL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 424w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 848w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 1272w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KuxL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png" width="944" height="880" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:880,&quot;width&quot;:944,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:202265,&quot;alt&quot;:&quot;Screenshot 15: Engineering &amp; Operations Briefing: Implementing DORA Compliance&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 15: Engineering &amp; Operations Briefing: Implementing DORA Compliance" title="Screenshot 15: Engineering &amp; Operations Briefing: Implementing DORA Compliance" srcset="https://substackcdn.com/image/fetch/$s_!KuxL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 424w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 848w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 1272w, https://substackcdn.com/image/fetch/$s_!KuxL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7072a71-6c4a-41e3-9dde-6f8e608fce08_944x880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 15: Engineering &amp; Operations Briefing: Implementing DORA Compliance</figcaption></figure></div></li><li><p>&#8220;GRC summary: evidence and control mapping expectations&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dkB_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dkB_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 424w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 848w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 1272w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dkB_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png" width="953" height="952" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:952,&quot;width&quot;:953,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:236844,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dkB_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 424w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 848w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 1272w, https://substackcdn.com/image/fetch/$s_!dkB_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc30f2040-fcd8-48d9-b3b4-4ba8810fba01_953x952.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 16: DORA Compliance Framework: A GRC Guide to Evidence and Control Mapping</figcaption></figure></div></li></ul><p>(Studio supports creating multiple outputs per notebook, so you can keep variants for different audiences in one place.)</p><h3>C) Audio / video overview for fast absorption</h3><p>Audio is useful when you need a quick &#8220;deep dive&#8221; on a subset of sources. Video overviews add narrated slides and visuals for explaining complex concepts.</p><p>Remember: free plans have <strong>daily</strong> generation limits.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f9HR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f9HR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 424w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 848w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 1272w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f9HR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png" width="891" height="659" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:659,&quot;width&quot;:891,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100602,&quot;alt&quot;:&quot;Screenshot 17: Studio &#8594; Audio Overview&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 17: Studio &#8594; Audio Overview" title="Screenshot 17: Studio &#8594; Audio Overview" srcset="https://substackcdn.com/image/fetch/$s_!f9HR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 424w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 848w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 1272w, https://substackcdn.com/image/fetch/$s_!f9HR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c9e7801-2ff3-4e42-8ef1-4dcedb7065cc_891x659.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 17: Studio &#8594; Audio Overview</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eXkI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eXkI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 424w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 848w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 1272w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eXkI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png" width="897" height="859" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:859,&quot;width&quot;:897,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196184,&quot;alt&quot;:&quot;Screenshot 18: Studio &#8594; Video Overview&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 18: Studio &#8594; Video Overview" title="Screenshot 18: Studio &#8594; Video Overview" srcset="https://substackcdn.com/image/fetch/$s_!eXkI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 424w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 848w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 1272w, https://substackcdn.com/image/fetch/$s_!eXkI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79847ae4-b91c-4c03-b603-ae1cdc0a909e_897x859.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 18: Studio &#8594; Video Overview</figcaption></figure></div><h3>D) Infographic for fast communication</h3><p>Generate an infographic outline from the DORA sources: &#8220;what it means / what to do / what evidence to keep&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z6Av!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z6Av!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z6Av!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6100353,&quot;alt&quot;:&quot;Screenshot 19:Infographic for fast communication&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot 19:Infographic for fast communication" title="Screenshot 19:Infographic for fast communication" srcset="https://substackcdn.com/image/fetch/$s_!z6Av!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z6Av!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b917be-4524-44b7-8bcf-1758365e2eec_2752x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot 19:Infographic for fast communication</figcaption></figure></div><h3>E) Slide deck for workshops and exec updates</h3><p>Turn a DORA topic into a slide-by-slide deck: titles, 3 bullets per slide, plus speaker notes with citations. </p><p>Use it for kickoff sessions, steering committees, and audit-readiness alignment.</p><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail" src="https://substackcdn.com/image/fetch/$s_!by_v!,w_400,h_600,c_fill,f_auto,q_auto:best,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F799713ba-e40f-4ecf-a553-de04eeaa3ef5_1376x768.png"></image><div class="file-embed-details"><div class="file-embed-details-h1">Dora Operational Readiness Reporting And Testing</div><div class="file-embed-details-h2">13.2MB &#8729; PDF file</div></div><a class="file-embed-button wide" href="https://www.fromciso.com/api/v1/file/432b15b2-9276-46a0-88a9-ace50dc4c33b.pdf"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">Slide Deck created in Google NotebookLM</div><a class="file-embed-button narrow" href="https://www.fromciso.com/api/v1/file/432b15b2-9276-46a0-88a9-ace50dc4c33b.pdf"><span class="file-embed-button-text">Download</span></a></div></div><div><hr></div><h1>The honest part: limitations of a &#8220;DORA AI Assistant&#8221;</h1><p>This is not a compliance silver bullet. Treat it as a <strong>research acceleration layer</strong>.</p><h2>1) It&#8217;s only as current as your sources</h2><p>NotebookLM uses a static snapshot of what you uploaded. If a document changes, you need to re-sync (Drive) or re-upload (many other source types).</p><h2>2) It can be wrong</h2><p>Google explicitly notes NotebookLM can make mistakes, and you should consult qualified professionals for legal/financial advice.</p><p>For fintech compliance, this means: <strong>use it to draft and accelerate, then verify</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0IaX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0IaX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 424w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 848w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 1272w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0IaX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png" width="377" height="23" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:23,&quot;width&quot;:377,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/185040626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0IaX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 424w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 848w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 1272w, https://substackcdn.com/image/fetch/$s_!0IaX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b3fbf0-cbd0-420a-bb5c-501763a538d3_377x23.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>3) Privacy and confidentiality still matter</h2><p>Google&#8217;s documentation states your data is protected and is not used to train NotebookLM unless you provide feedback; Workspace users get additional protections (no human review; not used to train AI models).</p><p>That said, follow your internal policy. For this workflow, you can stay fully in the &#8220;public documents only&#8221; zone by using the DORA Library sources.<br>4) Source limits are real</p><p><strong>50 sources</strong> per notebook means you may need separate notebooks if you expand beyond the core 27 (for example: internal policies, procedures, incident postmortems, vendor contract packs).</p><div><hr></div><h1>How to get maximum value (without becoming an &#8220;AI prompt person&#8221;)</h1><p>Three practical rules (these also align with standard prompt-engineering best practices):</p><ol><li><p><strong>Be specific about output</strong> (tables, checklists, control catalogs).</p></li><li><p><strong>Use role + context</strong> (&#8220;act as fintech GRC lead&#8230;&#8221;) to steer tone and scope.</p></li><li><p><strong>Ask for citations, and name sources</strong> when you know where the answer should be.</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The DORA Library: All 27 Regulatory Documents in One Place]]></title><description><![CDATA[Stop drowning in EUR-Lex tabs. Bookmark the definitive, curated list of every Regulation, RTS, ITS, and Guideline for CTOs, CISOs, and GRC leads.]]></description><link>https://www.fromciso.com/p/the-dora-library-all-27-regulatory</link><guid isPermaLink="false">https://www.fromciso.com/p/the-dora-library-all-27-regulatory</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Fri, 16 Jan 2026 15:05:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4ac0894b-f498-480e-9cb0-56780150c1a6_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you are working in Fintech security or compliance right now, your browser history probably resembles a crime scene, with numerous PDF downloads and EUR-Lex tabs.</p><p>We are now deep into the operational phase of DORA (Digital Operational Resilience Act). The &#8220;preparation&#8221; phase is over; the <strong>&#8220;execution&#8221; phase is here</strong>. But DORA isn&#8217;t just one PDF. It&#8217;s a sprawling ecosystem of Level 1 legislation, Level 2 Technical Standards (RTS/ITS), and Level 3 Guidelines.</p><p>As a CISO helping financial entities and fintechs navigate this, I realised we all needed a <strong>single source of truth</strong>, not just a dump of links, but a structured library organised by operational pillar and context.</p><p>Below is the complete inventory of <strong>the 27 DORA documents</strong> defining the framework as of January 2026.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LXq7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LXq7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 424w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 848w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 1272w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LXq7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png" width="724" height="645.304347826087" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:492,&quot;width&quot;:552,&quot;resizeWidth&quot;:724,&quot;bytes&quot;:114130,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/184753138?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LXq7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 424w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 848w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 1272w, https://substackcdn.com/image/fetch/$s_!LXq7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06e13afe-029e-471a-8c63-4adbf387f7a7_552x492.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">DORA Regulatory Framework</figcaption></figure></div><div><hr></div><h2>The General Framework (3 Docs)</h2><p><em>The foundation. Before you implement the controls, you need to understand the mandate.</em></p><ol><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj">DORA Regulation &#8211; (EU) 2022/2554</a> </strong></p></li></ol><p>The core legislative act establishing the digital operational resilience framework for the EU financial sector.</p><ol start="2"><li><p><strong><a href="https://eur-lex.europa.eu/eli/dir/2022/2556/oj">DORA Amending Directive &#8211; (EU) 2022/2556</a> </strong></p></li></ol><p>Modifies existing financial directives to ensure consistency with DORA requirements.</p><ol start="3"><li><p><strong><a href="https://www.eiopa.europa.eu/tools-and-data/qa-regulation_en">ESAs Q&amp;A Tool on the DORA Regulation</a></strong></p></li></ol><p>A living supervisory Q&amp;A tool on DORA that is updated periodically.</p><h2>ICT Risk Management (2 Docs)</h2><ol start="4"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj">ICT Risk Management &#8211; RTS (EU) 2024/1774</a> </strong></p></li></ol><p>Mandatory technical standards for the ICT risk management framework and simplified requirements.</p><ol start="5"><li><p><strong><a href="https://www.esma.europa.eu/document/final-report-draft-rts-ict-risk-management-framework-and-simplified-ict-risk-management">Final Report on ICT Risk Management RTS (JC 2023 86)</a></strong></p></li></ol><p>Explanatory report providing the regulatory rationale behind the ICT Risk Management RTS and the simplified framework.</p><h2>Incident Management &amp; Reporting (7 Docs)</h2><ol start="6"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2024/1772/oj">Incident Classification &#8211; RTS (EU) 2024/1772</a> </strong></p></li></ol><p>Specific criteria used to determine if an ICT incident or cyber threat is classified as &#8220;major&#8221;.</p><ol start="7"><li><p><strong><a href="https://www.esma.europa.eu/document/final-report-draft-rts-classification-major-incidents-and-significant-cyber-threats">Final Report on Incident Classification RTS (JC 2023 83)</a></strong></p></li></ol><p>Final report explaining the incident classification criteria and thresholds for major incidents and significant cyber threats.</p><ol start="8"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/301/oj">Incident Reporting Content &#8211; RTS (EU) 2025/301</a> </strong></p></li></ol><p>Mandatory details and strict time limits are required when reporting major incidents and significant cyber threats to authorities.</p><ol start="9"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj">Incident Reporting Templates &#8211; ITS (EU) 2025/302</a> </strong></p></li></ol><p>Official standard forms, templates, and procedures used for filing incident reports and cyber threat notifications.</p><ol start="10"><li><p><strong><a href="https://www.esma.europa.eu/document/final-report-draft-rts-and-its-incident-reporting">Final Report on Incident Reporting RTS/ITS (JC 2024 33)</a></strong></p></li></ol><p>Final report explaining reporting triggers and timelines for major ICT incident notifications and how they map to the RTS/ITS requirements and templates.</p><ol start="11"><li><p><strong><a href="https://www.esma.europa.eu/document/joint-guidelines-estimation-aggregated-annual-costs-and-losses-caused-major-ict-related">Cost and Loss Estimation &#8211; Joint Guidelines (JC/GL/2024/34) </a></strong></p></li></ol><p>Guidelines on estimating aggregated annual costs and losses caused by major ICT-related incidents.</p><ol start="12"><li><p><strong><a href="https://www.esma.europa.eu/document/report-feasibility-further-centralisation-reporting-major-ict-related-incidents">ESAs Report on a Single EU Hub (JC 2024 108)</a></strong></p></li></ol><p>Joint ESAs report evaluating the feasibility, options, and implications of further centralising major ICT incident reporting under DORA.</p><h2>Operational Resilience Testing (3 Docs)</h2><ol start="13"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj">Threat-Led Penetration Testing (TLPT) &#8211; RTS (EU) 2025/1190</a> </strong></p></li></ol><p>Rules for advanced security testing (TLPT), including scope, methodology, and assessor criteria.</p><ol start="14"><li><p><strong>F<a href="https://www.esma.europa.eu/document/final-report-draft-rts-specifying-elements-related-threat-led-penetration-tests">inal Report on TLPT RTS (JC 2024 29)</a></strong></p></li></ol><p>Final report explaining the rationale, scope, methodology, and expectations underpinning the TLPT RTS.</p><ol start="15"><li><p><strong><a href="https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html">TIBER-EU Framework (Updated)</a></strong></p></li></ol><p>Eurosystem framework and guidance for threat intelligence-based ethical red teaming, updated to support consistent TLPT under DORA.</p><h2>ICT Third-Party Risk / TPRM (6 Docs)</h2><ol start="16"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2024/1773/oj">ICT Third-Party Policy &#8211; RTS (EU) 2024/1773</a> </strong></p></li></ol><p><strong>Description:</strong> Regulatory technical standards specifying the detailed content of the policy for contractual arrangements on ICT services supporting critical or important functions.</p><ol start="17"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj">Register of Information Templates &#8211; ITS (EU) 2024/2956</a> </strong></p></li></ol><p>Official data structure and templates for the mandatory register of ICT service contracts (Register of Information).</p><ol start="18"><li><p><strong><a href="https://www.esma.europa.eu/document/final-report-draft-its-register-information">Final Report on Register of Information ITS (JC 2023 85)</a></strong></p></li></ol><p>Final report explaining the design and completion guidance for the Register of Information templates.</p><ol start="19"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/532/oj">Sub-contracting &#8211; RTS (EU) 2025/532</a> </strong></p></li></ol><p>Specific rules for assessing and monitoring ICT services that involve subcontracting chains.</p><ol start="20"><li><p><strong><a href="https://www.eiopa.europa.eu/publications/esas-opinion-european-commissions-rejection-its-registers-information-under-dora_en">ESAs Opinion on RoI ITS (JC 2024 75)</a></strong></p></li></ol><p>Opinion responding to the European Commission&#8217;s changes to the draft ITS on the Registers of Information, including implications for data quality and identifiers.</p><ol start="21"><li><p><strong><a href="https://www.bankingsupervision.europa.eu/press/pr/date/2025/html/ssm.pr250716~c0401b1b6b.en.html">ECB Guide on Outsourcing Cloud Services</a></strong></p></li></ol><p>Non-binding ECB guide describing supervisory expectations and recommended good practices for banks outsourcing cloud services.</p><h2>The Oversight Framework (6 Docs)</h2><p><em>How the EU supervises Critical Third-Party Providers (CTPPs). </em></p><pre><code><code>Note: The first wave of CTPP designations landed in Nov 2025, meaning oversight audits are now imminent for major cloud providers.</code></code></pre><ol start="22"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2024/1502/oj">Critical ICT Providers Designation Criteria &#8211; (EU) 2024/1502</a> </strong></p></li></ol><p>Delegated act setting out the quantitative and qualitative criteria for designating ICT providers as critical for the EU financial sector.</p><ol start="23"><li><p><strong><a href="https://www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en">List of Designated Critical ICT Providers (CTPPs)</a></strong></p></li></ol><p>Published list of designated critical ICT third-party providers subject to EU-level oversight.</p><ol start="24"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2024/1505/oj">Oversight Fees &#8211; (EU) 2024/1505</a> </strong></p></li></ol><p>Delegated act determining how oversight fees are calculated and paid by designated critical ICT third-party providers.</p><ol start="25"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/295/oj">Oversight Harmonisation &#8211; RTS (EU) 2025/295</a> </strong></p></li></ol><p>Ensures uniform conditions for how authorities conduct oversight activities, including audits and inspections, over CTPPs.</p><ol start="26"><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/420/oj">Joint Examination Teams &#8211; RTS (EU) 2025/420</a> </strong></p></li></ol><p>Details the composition, tasks, and working arrangements of the Joint Examination Teams responsible for supervising critical providers.</p><ol start="27"><li><p><strong><a href="https://www.esma.europa.eu/document/joint-guidelines-oversight-cooperation-and-information-exchange-between-esas-and-competent">Oversight Cooperation &#8211; Joint Guidelines (JC/GL/2024/36) </a></strong></p></li></ol><p>Guidelines on cooperation and information exchange between ESAs and competent authorities for DORA oversight activities.</p><div><hr></div><h3><strong>Why This Library Matters Now (And How to Use It)</strong></h3><p>We are past the theoretical stage. Deadlines are active, and supervision is ramping up.</p><ul><li><p>If you&#8217;re <strong>auditing your incident response plan</strong>, you need <strong>RTS 2025/301</strong>.</p></li><li><p>If you&#8217;re <strong>calculating last quarter&#8217;s losses</strong>, you need the <strong>Cost and Loss Guidelines</strong>.</p></li><li><p>If you&#8217;re <strong>preparing for your first TLPT</strong>, you need <strong>RTS 2025/1190</strong>.</p></li></ul><p><strong>How to use this library:</strong></p><ol><li><p><strong>Bookmark this page.</strong> Save it as your DORA home base.</p></li><li><p><strong>Map it to your roadmap.</strong> Identify the key documents for your next audit or reporting cycle.</p></li><li><p><strong>Share with your team.</strong> Ensure Legal, Procurement, and Tech Leads work from the same source.</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">For deep dives into TLPT preparation, third-party risk strategies, and regulatory updates, <strong>subscribe to fromCISO.com</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[7 Resilience KPIs Every Fintech CTO Should Use under DORA]]></title><description><![CDATA[Discover 7 key Resilience KPIs for fintech CTOs to measure resilience and communicate progress to both technical and business leaders.]]></description><link>https://www.fromciso.com/p/resilience-kpis</link><guid isPermaLink="false">https://www.fromciso.com/p/resilience-kpis</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Fri, 01 Aug 2025 07:12:19 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/51eb3238-e970-42d8-b359-4dd5fb4262ed_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Effective management of resilience is a strategic priority for fintech organisations operating under increasing regulatory scrutiny. The following seven resilience Key Performance Indicators (KPIs) are specifically designed for CTOs to measure, communicate, and drive operational improvements while aligning with EU security regulations, including the <a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en">Digital Operational Resilience Act (DORA)</a>, <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng">GDPR</a>, and current European Union cybersecurity laws.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/subscribe?"><span>Subscribe now</span></a></p><h2><strong>1. Third-Party Risk Exposure Score</strong></h2><p>Managing third-party risk remains a core challenge under evolving EU security regulations. CTOs require a KPI that aggregates and quantifies vendor-related exposures while demonstrating ongoing compliance with laws such as DORA and other related frameworks.</p><p><strong>Definition and Components:</strong></p><ul><li><p><strong>Vendor Assessment Coverage</strong> measures the percentage of all third-party suppliers, especially critical ICT and cloud providers, that have passed documented risk assessments within the past twelve months. DORA and associated compliance guidelines require full inclusion of any critical service providers.</p></li><li><p><strong>Risk Tier Classification</strong> organises vendors according to business impact:</p><ul><li><p><em>Tier 1 (Critical):</em> Directly support essential business functions or handle sensitive financial data.</p></li><li><p><em>Tier 2 (High):</em> Strongly influence operational continuity but are less integral than Tier 1.</p></li><li><p><em>Tiers 3&#8211;4 (Medium/Low):</em> Limited immediate impact on operations. Typically, only Tiers 1 and 2 undergo the most detailed controls required under DORA, the NIS2 Directive, and sector norms.</p></li></ul></li><li><p><strong>DORA-Compliant Contract Status</strong> tracks the proportion of Tier 1 and Tier 2 vendors with up-to-date contracts containing mandatory ICT risk, audit, and incident-reporting clauses. According to recent industry surveys, contract modernisation delays are consistently cited as a major obstacle during DORA implementation.</p></li></ul><p><strong>Composite Score Calculation:</strong></p><pre><code><code>Third-Party Risk Exposure Score = &#931; (Domain Weight &#215; Risk Tier Score &#215; Compliance Status)</code></code></pre><p>Domains include ICT and cybersecurity risk, regulatory compliance, service criticality, financial resilience, and contractual completeness. Assign scores (1&#8211;5) and weights reflecting organisational priorities, typically giving precedence to cybersecurity and current contracts.</p><p><strong>Application and Reporting:</strong></p><p>Dashboards often present:</p><ul><li><p>Per cent of Tier 1 vendors with current assessments and DORA-compliant contracts.</p></li><li><p>Proportion of critical vendor agreements that specify audit rights and incident reporting.</p></li><li><p>Aggregated risk exposure scores for all essential suppliers are reviewed quarterly.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PFC-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PFC-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 424w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 848w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 1272w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PFC-!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png" width="1200" height="641.9753086419753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:650,&quot;width&quot;:1215,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:106516,&quot;alt&quot;:&quot;Third-party risk dashboard&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Third-party risk dashboard" title="Third-party risk dashboard" srcset="https://substackcdn.com/image/fetch/$s_!PFC-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 424w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 848w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 1272w, https://substackcdn.com/image/fetch/$s_!PFC-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9026910b-3e7b-40e6-ae0a-38ad8d423500_1215x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Third-party risk dashboard</figcaption></figure></div><p>Adopting this metric directly supports audit preparation and provides evidence of ongoing oversight as required by regulators. Configurable scoring makes this KPI both adaptable and actionable, highlighting both compliance gaps and risk management progress.</p><p><strong>The</strong> <strong>Third-Party Risk Exposure Score</strong> enables CTOs to present vendor management performance in a format accessible to both technical teams and executives, strengthening transparency and accelerating both compliance and operational improvement initiatives.</p><h2><strong>2. Incident Detection &amp; Response Time</strong></h2><p>DORA sets strict timelines for notifying competent authorities of significant ICT&#8209;related incidents. MTTD and MTTR are recommended KPIs to help ensure those timelines are met.</p><p><strong>Key Metrics:</strong></p><ul><li><p><strong>Mean Time to Detect (MTTD)</strong> records the elapsed time from incident occurrence to initial detection.</p></li><li><p><strong>Mean Time to Respond (MTTR)</strong> measures the interval from detection through to remediation and return to standard operations.</p></li></ul><p><strong>Regulatory Alignment:</strong></p><p>DORA mandates notification of significant ICT&#8209;related incidents per the European Supervisory Authorities&#8217; incident&#8209;reporting technical standards: within four hours of classification and, in all cases, within 24 hours of detection, with an update at 72 hours and a final report within one month.</p><p><strong>Improvement Strategies:</strong></p><ul><li><p>Establish real-time observability across payment and core business systems, leveraging solutions for traceability.</p></li><li><p>Integrate <a href="https://en.wikipedia.org/wiki/Security_information_and_event_management">Security Information and Event Management (SIEM)</a> and <a href="https://en.wikipedia.org/wiki/Security_orchestration">Security Orchestration, Automation and Response (SOAR)</a> platforms to centralise alerts and automate triage. These tools can reduce MTTR by automating triage and response; actual impact varies by implementation. If you cite a percentage, include a verifiable source and context (e.g., study scope and methodology).</p></li><li><p>Maintain well-tested Incident Response Plans (IRPs) with explicit roles and decision points. Conduct regular simulations and reviews, in line with DORA and <a href="https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html">TIBER-EU</a> guidance.</p></li><li><p>Schedule frequent threat-led drills involving red, purple, and blue teams, which ENISA recommends and many firms adopt; quantify your effect with internal MTTD data or cite a specific study rather than ENISA generically.</p></li><li><p>Brief board members through accessible dashboards and clear progress visualisations.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Iail!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Iail!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 424w, https://substackcdn.com/image/fetch/$s_!Iail!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 848w, https://substackcdn.com/image/fetch/$s_!Iail!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 1272w, https://substackcdn.com/image/fetch/$s_!Iail!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Iail!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png" width="1200" height="814.4578313253012" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:676,&quot;width&quot;:996,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:100341,&quot;alt&quot;:&quot;Dashboard with MTTD/MTTR trends&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Dashboard with MTTD/MTTR trends" title="Dashboard with MTTD/MTTR trends" srcset="https://substackcdn.com/image/fetch/$s_!Iail!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 424w, https://substackcdn.com/image/fetch/$s_!Iail!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 848w, https://substackcdn.com/image/fetch/$s_!Iail!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 1272w, https://substackcdn.com/image/fetch/$s_!Iail!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53bbee7-aa09-4165-aa79-3ad42edf826a_996x676.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dashboard with MTTD/MTTR trends</figcaption></figure></div><p>Presenting these metric trends in leadership meetings encourages evidence-based investment in tooling and team development, directly supporting audit obligations and risk governance for fintechs.</p><h2><strong>3. Regulatory Compliance Coverage</strong></h2><p>Regulatory requirements governing operational resilience are dynamic, and CTOs face the challenge of aligning technology, process, and contractual obligations to meet DORA and other EU security regulations.</p><p><strong>Structuring the KPI:</strong></p><p>Regulatory compliance coverage is visualised through a regularly updated gap analysis heatmap. This tool benchmarks organisational controls, policies, and vendor contracts against the latest requirements of DORA and related European frameworks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uo3I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uo3I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 424w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 848w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 1272w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uo3I!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png" width="1200" height="1057.0469798657718" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1050,&quot;width&quot;:1192,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:205570,&quot;alt&quot;:&quot;Regulatory compliance gap heatmap&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Regulatory compliance gap heatmap" title="Regulatory compliance gap heatmap" srcset="https://substackcdn.com/image/fetch/$s_!uo3I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 424w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 848w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 1272w, https://substackcdn.com/image/fetch/$s_!uo3I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644621d5-e722-4517-8078-fca77d3083e1_1192x1050.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Regulatory compliance gap heatmap</figcaption></figure></div><p><strong>Assessment Methodology:</strong></p><ul><li><p>Map current ICT controls, policies, and vendor engagements against all DORA principles.</p></li><li><p>Identify and prioritise any deficiencies through detailed document review and stakeholder interviews, focusing on technical controls, contractual completeness, and operational readiness.</p></li><li><p>Display results through a colour-coded heatmap highlighting compliant (green), partially compliant (amber), and urgent remediation (red) areas.</p></li></ul><p>Effective reporting breaks down compliance status by key domains, such as incident management, third-party oversight, and operational risk and tracks completion percentages (e.g., &#8220;62% of DORA requirements met, with vendor contract revisions and technology asset inventory remaining&#8221;).</p><p><strong>Best-Practice Implementation:</strong></p><ul><li><p>Update the gap analysis monthly to account for regulatory updates and organisational changes.</p></li><li><p>Automate metric collection and dashboarding to reduce manual oversight and error.</p></li><li><p>Assign clear ownership for all outstanding actions, ensuring board and regulator visibility of progress and accountability.</p></li></ul><p>Comprehensive and ongoing gap analysis reporting enables CTOs to demonstrate how resilience and risk management underpin compliance, building trust with stakeholders at every organisational level.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/p/resilience-kpis?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/p/resilience-kpis?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2><strong>4. Threat-led Penetration Testing Score</strong></h2><p>Threat-led penetration testing is required under DORA for entities selected by competent authorities; NIS2 requires regular testing of cybersecurity risk&#8209;management measures but does not mandate TLPT. It is an advanced control for operational resilience, providing actionable insights beyond traditional vulnerability scanning.</p><p><strong>Core Metrics:</strong></p><ul><li><p><strong>On-Schedule Completion Rate</strong><br>Percentage of scheduled threat-led penetration testing (TLPT) exercises completed within planned timeframes. This reflects program discipline and regulatory consistency.</p></li><li><p><strong>Average Remediation Time</strong><br>Calculated as the mean number of days between vulnerability discovery and resolution. This quantifies the agility of security teams in closing risk windows.</p></li><li><p><strong>Test Types:</strong></p><ul><li><p><em>Red Teaming</em>: Simulate adversarial attacks.</p></li><li><p><em>Purple Teaming</em>: Cooperative offence and defence evaluations.</p></li><li><p><em>Blue Teaming</em>: Focused internal detection and response sprints.</p></li></ul></li></ul><p>Comprehensive coverage supports DORA and other EU data protection standards.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E-Tp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E-Tp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 424w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 848w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 1272w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E-Tp!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png" width="1200" height="868.9984101748807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9550a75d-3eae-44b7-8500-88788306322b_1258x911.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:911,&quot;width&quot;:1258,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:186102,&quot;alt&quot;:&quot;Threat-led Penetration Testing Score Dashboard&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Threat-led Penetration Testing Score Dashboard" title="Threat-led Penetration Testing Score Dashboard" srcset="https://substackcdn.com/image/fetch/$s_!E-Tp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 424w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 848w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 1272w, https://substackcdn.com/image/fetch/$s_!E-Tp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9550a75d-3eae-44b7-8500-88788306322b_1258x911.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Threat-led Penetration Testing Score Dashboard</figcaption></figure></div><p><strong>Reporting Practice:</strong> Incorporate test progress (on-time completion, risk severity, and remediation velocity) within monthly executive dashboards. Balanced reporting bridges technical operations with business and compliance objectives.</p><p>Integrating these KPIs validates penetration testing as both a compliance requirement and an indicator of continuous risk mitigation.</p><h2><strong>5. ICT Change Management Effectiveness</strong></h2><p>ICT change management effectiveness directly influences operational resilience and is scrutinised by EU regulators under DORA and related laws.</p><p><strong>Primary Metrics:</strong></p><ul><li><p><strong>Percentage of Major ICT Changes Reviewed for Operational Risk</strong><br>Identifies how thoroughly significant changes are vetted for threats, compliance, and operational impacts. For instance, reviewing 18 of 20 major changes reflects a 90% review rate.</p></li><li><p><strong>Percentage of ICT Changes Resulting in Post-Implementation Incidents</strong><br>Tracks change-induced issues, such as outages or compliance failures. Set a clear internal target for post&#8209;change incident rates (e.g., &lt;3%).</p></li></ul><p>Reviews should evaluate:</p><ul><li><p>Vulnerability and risk exposures,</p></li><li><p>Compliance with all regulatory obligations under DORA and GDPR,</p></li><li><p>Impact on both internal and vendor operations,</p></li><li><p>Rollback and incident response planning.</p></li></ul><p><strong>Illustrative Example:</strong> A mid-sized fintech previously experienced a 7% incident rate after accelerating core API updates without adequate review, triggering a major payment system outage. Subsequently, by introducing automated risk assessments and post-deployment validation, the firm achieved uninterrupted upgrades and lowered its incident metric to below 3%.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EjFs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EjFs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 424w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 848w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 1272w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EjFs!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png" width="1200" height="1247.4445515911282" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1078,&quot;width&quot;:1037,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:159468,&quot;alt&quot;:&quot;ICT Change Management Effectiveness Dashboard&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="ICT Change Management Effectiveness Dashboard" title="ICT Change Management Effectiveness Dashboard" srcset="https://substackcdn.com/image/fetch/$s_!EjFs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 424w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 848w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 1272w, https://substackcdn.com/image/fetch/$s_!EjFs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198a791a-cb15-4eab-ac52-f4e1dcbbbaaa_1037x1078.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">ICT Change Management Effectiveness Dashboard</figcaption></figure></div><p><strong>Board Reporting and Action:</strong> Convey results using trend lines, annotated with significant changes or incident spikes, and supplement with brief narratives that make risks and progress clear for executive oversight. Align improvement and training programs with updated regulatory standards to ensure ongoing compliance.</p><p>Effective change management measurement ensures both operational integrity and sustained regulatory compliance, even as expectations continue to evolve.</p><h2><strong>6. Cyber Resilience Maturity Index</strong></h2><p>The Cyber Resilience Maturity Index (CRMI) offers a single, comprehensive score summarising a fintech&#8217;s readiness across all DORA competencies. By consolidating progress in risk management, incident response, testing, information sharing, third-party risk, and governance, this KPI supports strategic decisions and meets regulatory expectations.</p><p><strong>Structure and Assessment:</strong></p><p>Each domain is rated 1&#8211;5:</p><p><strong>ScoreDescription</strong></p><p><strong>1 Initial</strong>: Unstructured, ad hoc responses</p><p><strong>2 Developing</strong>: Basic controls, inconsistent</p><p><strong>3 Established</strong>: Documented routines, reviewed</p><p><strong>4 Advanced</strong>: Continuous, proactive refinements</p><p><strong>5 Optimised:</strong> Integrated, automated, audit-ready</p><p>This approach, advocated by KPMG and Wavestone in recent sector guidance, ensures consistent interpretation and eases benchmarking. </p><p><strong>Visualisation:</strong></p><p>A radar chart displays each domain&#8217;s score, revealing strengths and highlighting areas needing strategic investment. Comparing current and target positions provides actionable direction for resource allocation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FYxZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FYxZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 424w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 848w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 1272w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FYxZ!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png" width="1200" height="1195.5265610438025" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1069,&quot;width&quot;:1073,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:177537,&quot;alt&quot;:&quot;Cyber Resilience Maturity Index Dashboard&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="Cyber Resilience Maturity Index Dashboard" title="Cyber Resilience Maturity Index Dashboard" srcset="https://substackcdn.com/image/fetch/$s_!FYxZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 424w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 848w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 1272w, https://substackcdn.com/image/fetch/$s_!FYxZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7730e96-5181-49c2-aff7-2a3828d9086a_1073x1069.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cyber Resilience Maturity Index Dashboard</figcaption></figure></div><p><strong>Practical Benchmarking:</strong> Aggregate the six domain scores (e.g., [2, 3, 2, 1, 3, 2]) and average for a sector-comparable maturity index.</p><p>Industry data helps CTOs determine if current maturity meets, lags, or exceeds both peer organisations and evolving EU regulatory expectations.</p><p><strong>Executive Value:</strong> Consolidating resilience measurement into a single KPI streamlines board reporting and provides a direct reference for compliance investment discussions, supported by recognised industry data.</p><h2><strong>7. Cost and Resource Allocation Efficiency</strong></h2><p>Proactive management of cost and resource allocation is integral to meeting EU security regulation demands and delivering sustained value from resilience investments.</p><p><strong>Measurement Components:</strong></p><ul><li><p><strong>Resilience Proportion of Operational Budget:</strong> Identifies the share of total ICT expenditures dedicated to resilience activities&#8212;such as risk management, incident response, and compliance&#8212;that are essential for EU readiness.</p></li><li><p><strong>Resource Headcount and Specialisation:</strong> Tracks the number and expertise of Full-Time Equivalents (FTEs) supporting resilience objectives, including compliance leads, cyber risk analysts, and incident responders.</p></li><li><p><strong>Budgetary Trends:</strong> Monitors year-on-year changes in spend, aligned to regulatory priorities. External consultancies underscore that sustained increases, such as raising resilience spend from 7% to 10% of total IT budget, signal active compliance management and competitive positioning.</p></li><li><p><strong>Resource Impact Reporting:</strong> Links budget or staff reallocations to tangible improvements (e.g., faster incident resolution, increased risk transparency, or demonstrable progress along regulatory milestones).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-85-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-85-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 424w, https://substackcdn.com/image/fetch/$s_!-85-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 848w, https://substackcdn.com/image/fetch/$s_!-85-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 1272w, https://substackcdn.com/image/fetch/$s_!-85-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-85-!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png" width="1200" height="1155.5555555555557" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1170,&quot;width&quot;:1215,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:260675,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/169475024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-85-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 424w, https://substackcdn.com/image/fetch/$s_!-85-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 848w, https://substackcdn.com/image/fetch/$s_!-85-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 1272w, https://substackcdn.com/image/fetch/$s_!-85-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb9082e-82ba-4135-a4d7-5058168ecb74_1215x1170.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Effective Practices:</strong></p><p>Quarterly <a href="https://www.fromciso.com/p/board-accountability-in-dora">board reporting</a> should include budget splits and headcount tables, emphasising the business value of resilience compliance. Dashboards clarify alignment between investments and risk reduction, supporting executive decision-making.</p><p>Consistent cost and resource allocation monitoring positions fintech CTOs to demonstrate efficiency, regulatory leadership, and long-term growth potential.</p><h2><strong>Executive Summary and Next Steps</strong></h2><p>Fintech CTOs navigating the demands of EU security regulations establish operational resilience as both a compliance imperative and a strategic asset by deploying focused, quantifiable KPIs. The seven resilience KPIs presented, spanning third-party risk, incident response, regulatory compliance, threat-led testing, change management, resilience maturity, and cost efficiency, offer practical, actionable measurement systems.</p><p>These frameworks enable CTOs to:</p><ul><li><p>Transparently communicate progress to technical and non-technical stakeholders,</p></li><li><p>Prioritise investments by data-driven assessment of risk and readiness,</p></li><li><p>Satisfy evolving DORA and EU audit standards with evidence-backed reporting.</p></li></ul><p>The adoption and continual refinement of resilience KPIs will support fintechs in quantifying achievements, identifying actionable gaps, and future-proofing both compliance programs and overall business strategy. CTOs are encouraged to select one or more of the outlined KPIs for immediate implementation, ensuring cross-functional collaboration, automated metric tracking, and alignment with regulatory and organisational goals. This approach establishes a clear path towards mature, defensible, and value-driven operational resilience.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[11 Practical Steps to Master Your DORA Compliance Audit]]></title><description><![CDATA[Take control of your DORA compliance audit with these clear, actionable tactics designed specifically for fintech CTOs aiming to eliminate audit anxiety.]]></description><link>https://www.fromciso.com/p/dora-compliance-audit</link><guid isPermaLink="false">https://www.fromciso.com/p/dora-compliance-audit</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Wed, 02 Jul 2025 06:47:12 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4e9f9ea7-fbfd-45aa-89f7-5b1344c51a6e_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>As a fintech CTO, you're no stranger to regulatory scrutiny. With the <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554">Digital Operational Resilience Act (DORA)</a> enforcement now in full swing, the stakes have never been higher. But here's the good news: mastering DORA compliance doesn't have to be daunting. In fact, by following these 11 practical tactics, you'll transform your next DORA Compliance Audit from a stressful event into a smooth, predictable process.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/subscribe?"><span>Subscribe now</span></a></p><h2>1. Start With a Blunt Gap Analysis</h2><h3>Why the "Blunt" Approach Works Best</h3><p>Before you dive into new controls, find out exactly where you stand. A brutally honest gap analysis reveals hidden weaknesses faster than any polished presentation. For you, this means fewer surprises during audits and a clear roadmap for spending.</p><h3>Your Four-Step Playbook</h3><p><strong>1. Gather Existing Documents</strong></p><p>Collect policies, runbooks, vendor contracts, and penetration-test reports into one central folder. Don't forget parallel frameworks like ISO 27001 and SOC 2, you can reuse this evidence later.</p><p><strong>2. Map Artefacts to DORA&#8217;s Five Pillars</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jGsv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jGsv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 424w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 848w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 1272w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jGsv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png" width="1152" height="492" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:492,&quot;width&quot;:1152,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71059,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166992238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jGsv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 424w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 848w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 1272w, https://substackcdn.com/image/fetch/$s_!jGsv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ad2942e-d7c8-4a87-a39d-a80dcb769b5c_1152x492.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>- ICT risk management</p><p>- Incident reporting</p><p>- Digital operational resilience testing</p><p>- ICT third-party risk</p><p>- Information-sharing arrangements</p><p>Create a spreadsheet with DORA articles as rows and artefacts as columns. Mark each as direct, partial, or missing coverage.</p><p><strong>3. Score and Visualise Gaps</strong></p><p>Assign scores from 0 (Not Compliant) to 3 (Compliant). Generate a heatmap so executives instantly see weak spots. Validate your scoring with <a href="https://www.fromciso.com/i/165426889/fivestep-playbook-for-fintech-ctos">a free checklist fromCISO</a>.</p><p><strong>4. Turn Gaps Into Two-Week Sprints</strong></p><p>Prioritise critical "red" controls that carry fines or customer impact. Assign each action to Jira with clear owners, definitions of done, and expected evidence. Re-score monthly and watch your heatmap shift from red to green.</p><p><strong>Mini-case: </strong>Payment scale-up <em>OneCompanyPay</em> boosted its ICT third-party coverage from 43% to 88% in just six weeks using this method. The blunt gap analysis clearly demonstrated ROI, making it easy to secure board approval.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/p/dora-compliance-audit?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! This post is public, so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/p/dora-compliance-audit?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.fromciso.com/p/dora-compliance-audit?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>2. Map a Federated Controls Library</h2><h3>Why Consolidation Beats Silos</h3><p>Running SOX, ISO 27001, PCI-DSS, and DORA separately leads to duplicate testing and audit fatigue. A federated controls library eliminates overlap, letting one piece of evidence satisfy multiple frameworks.</p><h3>Five Steps to Build Your Matrix</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f_97!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f_97!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 424w, https://substackcdn.com/image/fetch/$s_!f_97!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 848w, https://substackcdn.com/image/fetch/$s_!f_97!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 1272w, https://substackcdn.com/image/fetch/$s_!f_97!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f_97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png" width="672" height="660" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:660,&quot;width&quot;:672,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75513,&quot;alt&quot;:&quot;DORA Compliance Audit:Five Steps to Build Your Matrix&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166992238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA Compliance Audit:Five Steps to Build Your Matrix" title="DORA Compliance Audit:Five Steps to Build Your Matrix" srcset="https://substackcdn.com/image/fetch/$s_!f_97!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 424w, https://substackcdn.com/image/fetch/$s_!f_97!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 848w, https://substackcdn.com/image/fetch/$s_!f_97!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 1272w, https://substackcdn.com/image/fetch/$s_!f_97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a831ed-fa0c-431b-9e42-9552f60101d3_672x660.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>1. Pull Source Material</strong></p><p>Export controls from SOX, ISO 27001 Annex A, PCI-DSS v4, and DORA Articles 9-15. Standardise wording into "action + object + purpose."</p><p><strong>2. De-duplicate by Intent</strong></p><p>Group controls with the same outcome. Keep the strictest requirement as master, referencing others as aliases.</p><p><strong>3. Assign Universal IDs</strong></p><p>Prefix IDs with framework codes (e.g., SOX-SD-01). Add a DORA cross-reference column for easy sorting.</p><p><strong>4. Tag Supporting Evidence</strong></p><p>Link controls to Jira tickets, AWS Config rules, or SOC 2 reports. Aim for "one-click proof" during audits.</p><p><strong>5. Store in a Living Repository</strong></p><p>Use a version-controlled GRC platform like LeanIX Continuous Controls Catalogue. Set up peer-reviewed pull-request workflows.</p><h3>Quick Wins for Next DORA Compliance Audit</h3><p>- Replace multiple auditor lists with one export from your matrix.</p><p>- Auto-populate evidence packets using DORA filters.</p><p>- Track control ownership centrally, ending "who owns this?" email chains.</p><h3>Red Flags to Avoid</h3><p>- Mapping only at clause level&#8212;always drill down to control statements.</p><p>- Letting the library go stale&#8212;schedule quarterly reviews aligned with sprint retrospectives.</p><p>Adopt this matrix now, and your next DORA review will feel like reusing code instead of rewriting it.</p><h2>3. Refresh Your DORA Compliance Audit Charter for DORA</h2><h3>Why a Charter Update Matters</h3><p>DORA makes ICT risk a board-level liability. Your audit charter must clearly show the internal audit&#8217;s ability to independently assure all five pillars without conflicts of interest. fromCISO&#8217;s <a href="https://www.fromciso.com/i/164955675/your-step-checklist-for-a-clear-actionable-dora-charter">guide on the five pillars</a> is a solid reference.</p><h3>Step-by-Step Rewrite</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dkGY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dkGY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 424w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 848w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 1272w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dkGY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png" width="925" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:925,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78512,&quot;alt&quot;:&quot;DORA Compliance Audit: Step-by-Step Rewrite&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166992238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA Compliance Audit: Step-by-Step Rewrite" title="DORA Compliance Audit: Step-by-Step Rewrite" srcset="https://substackcdn.com/image/fetch/$s_!dkGY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 424w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 848w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 1272w, https://substackcdn.com/image/fetch/$s_!dkGY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf3b7737-26f9-4785-b4d5-25c8d1a146f7_925x480.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>1. Expand the Mandate</strong></p><p>Include ICT third-party risk, incident response, and resilience testing explicitly in your annual DORA Compliance Audit plan.</p><p><strong>2. Define Clear Roles</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qt4Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 424w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 848w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 1272w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png" width="784" height="205" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:205,&quot;width&quot;:784,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30591,&quot;alt&quot;:&quot;DORA Compliance Audit: Define Clear Roles&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166992238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA Compliance Audit: Define Clear Roles" title="DORA Compliance Audit: Define Clear Roles" srcset="https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 424w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 848w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 1272w, https://substackcdn.com/image/fetch/$s_!Qt4Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14bf6eb-3d9c-4ec0-b143-a1ea7a8d83f2_784x205.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>3. Hard-Code Escalation Paths</strong></p><p>Material findings must reach the Audit Committee within five business days. Legal non-compliance issues go straight to the board chair.</p><p><strong>4. Continuous Assurance</strong></p><p>Authorise auditors to use continuous monitoring dashboards. Schedule quarterly mini-reviews.</p><p><strong>5. Resilience Testing Rights</strong></p><p>Grant audit observer status during resilience tests. Require post-exercise reports within ten days.</p><p>A well-crafted charter arms your team with clear authority, satisfies regulators, and lets you focus on innovation, not firefighting.</p><h2>4. Automate Your Vendor Register</h2><h3>Why Spreadsheets Won&#8217;t Cut It</h3><p>DORA views critical ICT suppliers as extensions of your risk surface. A static spreadsheet can't capture daily changes. Automating your vendor register ensures real-time accuracy.</p><h3>Four Moves to Automation</h3><p>- Embed vendor creation in your procurement portal.</p><p>- Enrich data nightly with Bitsight or SecurityScorecard risk scores.</p><p>- Tie updates to CI/CD pipelines to block shadow IT.</p><p>- Stream evidence into the audit via weekly snapshots.</p><p><strong>Mini-case:</strong> <em>OneCompanyPay</em> caught shadow IT instantly when their CI/CD pipeline flagged an unregistered SaaS. Procurement completed due diligence within 48 hours, impressing auditors with rapid control effectiveness.</p><h2>5. Monitor ICT Risk in Real Time</h2><h3>Why Continuous Monitoring Matters</h3><p><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_9">DORA Article 9</a> demands the timely identification of anomalous activities. Continuous control-monitoring (CCM) dashboards replace quarterly PDFs with live risk scores, eliminating blind spots.</p><h3>Build a CCM Dashboard in Three Sprints</h3><p>- Pipe data from SIEM, ticketing, and cloud posture tools.</p><p>- Map metrics to DORA articles.</p><p>- Set visual alerts that trigger Slack and Jira notifications.</p><p>Daily metrics like mean time to patch and backup success rates impress auditors and demonstrate proactive oversight.</p><h2>6. Drill Incident Response &amp; Reporting</h2><h3>Why Drills Are Essential</h3><p>DORA gives just 24 hours to report material incidents. Regular tabletop and live-fire exercises ensure your team meets this tight deadline.</p><p>Internal DORA Compliance Audit observes drills, capturing timestamps and artefacts to prove control effectiveness.</p><h2>7. Stress-Test Operational Continuity</h2><h3>Why Advanced Testing Counts</h3><p>Scenario-based resilience tests (e.g., power loss, cloud outages) provide hard evidence that your recovery targets actually work. Automate metric collection for audit-ready documentation.</p><h2>8. Elevate Board-Level Oversight</h2><h3>Why Regular Updates Matter</h3><p>Make DORA readiness a standing board agenda item. Present a concise heatmap and clear budget motions quarterly to keep directors informed and accountable.</p><h2>9. Industrialise Evidence Capture</h2><h3>Why Automation Beats Manual Gathering</h3><p>Automate evidence capture into a secure data lake, tagging artefacts for rapid retrieval. Regular "evidence health checks" ensure continuous compliance.</p><h2>10. Stage Mock Supervisory Reviews</h2><h3>Why Practice Makes Perfect</h3><p>Run mock ESMA/EBA inspections every six months. Identify gaps early and build muscle memory, turning real inspections into routine events.</p><h2>11. Close the Loop With Continuous Improvement</h2><h3>Why Iteration Is Key</h3><p>Turn DORA Compliance Audit findings into an agile backlog. Assign clear owners, bake KPIs into operational metrics, and re-run gap analyses semi-annually. Continuous improvement becomes routine engineering work.</p><h2>Quick Win: Download the 1-Page DORA Compliance Audit Sprint Planner</h2><p>Grab a free XLSX that slots all 11 tactics into six two-week sprints. Drop it into Google Sheets or Jira, assign owners in minutes, and start turning red gaps green. No calls, no commitments&#8212;just a practical worksheet you can use today.</p><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail" src="https://substackcdn.com/image/fetch/$s_!Tetp!,w_400,h_600,c_fill,f_auto,q_auto:best,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca4b25cf-db39-4265-a376-2efc02802602_1000x1500.png"></image><div class="file-embed-details"><div class="file-embed-details-h1">DORA Sprint Planner &#8211; Detailed (EN)</div><div class="file-embed-details-h2">7.04KB &#8729; XLSX file</div></div><a class="file-embed-button wide" href="https://www.fromciso.com/api/v1/file/52040c62-9984-45e8-b330-a99fd8d0f0d0.xlsx"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">One-page XLSX template covering all 11 DORA tactics, broken into 22 granular tasks across six two-week sprints. Includes columns for Owner, Due Date, Status, and Evidence Link&#8212;ready to import into Google Sheets or Jira.</div><a class="file-embed-button narrow" href="https://www.fromciso.com/api/v1/file/52040c62-9984-45e8-b330-a99fd8d0f0d0.xlsx"><span class="file-embed-button-text">Download</span></a></div></div><p>Good luck&#8212;your next audit just got easier.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[DORA Proportionality: Right-Sizing Compliance for FinTechs]]></title><description><![CDATA[DORA Proportionality made practical: CTO roadmap to tailor ICT risk controls, automate incident reporting, and streamline third-party oversight for audits.]]></description><link>https://www.fromciso.com/p/dora-proportionality</link><guid isPermaLink="false">https://www.fromciso.com/p/dora-proportionality</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Thu, 26 Jun 2025 17:50:30 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/80e43852-0b0f-43a3-822b-435c0dddd31c_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>How to Master DORA Proportionality: A CTO&#8217;s Practical Guide</h1><h2>1. Know the Legal Bedrock</h2><h3>Recital 36 &#8212; The Intent</h3><p>&#8220;Financial entities shall put in place and maintain resilient ICT systems <strong>taking into account the nature, scale and complexity of their services, activities and operations, as well as their overall risk profile</strong>.&#8221;<br>Share this exact wording whenever someone treats DORA as a one-size-fits-all rulebook.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_4">Article 4</a> &#8212; The Mandate</h3><p>Supervisors must assess compliance &#8220;in a proportionate manner,&#8221; weighing:</p><ul><li><p>nature, scale and complexity of services</p></li><li><p>overall risk profile</p></li><li><p>potential impact on customers and markets</p></li></ul><h3><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_16">Article 16</a> &#8212; The Safety Valve for Micro &amp; Small Firms</h3><p>Entities with fewer than 10 staff and an annual turnover below &#8364;2 million may use a <strong>simplified ICT-Risk Management Framework (ICT-RMF)</strong>. They are exempt from Articles 5&#8211;15 (including TLPT) provided they maintain basic security-by-design controls and an incident log.</p><h3>Quick Win &#8212; Circulate the Excerpts</h3><p>Create a two-page brief containing Recital 36, <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_4">Article 4</a> and <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_16">Article 16</a>; highlight key phrases and send it to executives and legal counsel before budget talks.</p><p><strong>Mini-Checklist for CTOs</strong></p><ul><li><p>Recital 36 archived in the policy wiki</p></li><li><p>Articles <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_4">4</a> and <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_16">16</a> linked from every DORA project charter</p></li><li><p>Excerpts included in the next board deck</p></li><li><p>Internal FAQ entry: &#8220;Proportionality is built into DORA&#8212;see Recital 36, Art. 4 &amp; 16&#8221;</p></li></ul><div><hr></div><h2>2. Profile Your Size-Risk Matrix</h2><h3>Why Start Here?</h3><p>Regulators expect an up-front self-assessment. Skipping it invites over-engineering&#8212;or blind spots.</p><h3>Step-by-Step Mapping</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BIvA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BIvA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 424w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 848w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 1272w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BIvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png" width="1020" height="552" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:552,&quot;width&quot;:1020,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:59817,&quot;alt&quot;:&quot;DORA Proportionality Step-by-Step Mapping&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA Proportionality Step-by-Step Mapping" title="DORA Proportionality Step-by-Step Mapping" srcset="https://substackcdn.com/image/fetch/$s_!BIvA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 424w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 848w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 1272w, https://substackcdn.com/image/fetch/$s_!BIvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe05129f1-978c-4e1e-a09a-83c430ba72bd_1020x552.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong>List core assets</strong> &#8212; systems, code repos, on-prem hardware, SaaS.</p></li><li><p><strong>Capture transaction volumes</strong> &#8212; daily payments, peak API calls.</p></li><li><p><strong>Mark geographic scope</strong> &#8212; customer countries, data-centre locations.</p></li><li><p><strong>Identify critical functions</strong> &#8212; activities whose failure halts payments, trading or onboarding.</p></li></ol><h3>Classify Impact Tiers</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_t9a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_t9a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 424w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 848w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 1272w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_t9a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png" width="783" height="166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:783,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25244,&quot;alt&quot;:&quot;Classify Impact Tiers&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Classify Impact Tiers" title="Classify Impact Tiers" srcset="https://substackcdn.com/image/fetch/$s_!_t9a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 424w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 848w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 1272w, https://substackcdn.com/image/fetch/$s_!_t9a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb573263-2ec9-4ecf-ba83-6a41934463ec_783x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Mini-Checklist</strong></p><ul><li><p>Matrix covers 100 % of production assets</p></li><li><p>Impact tier agreed by two + stakeholders</p></li><li><p>Reviewed quarterly or after material changes</p></li></ul><p></p><div><hr></div><h2>3. Governance Guard-Rails (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_5">Article 5</a>)</h2><p>The board remains ultimately accountable for ICT risk:</p><ul><li><p>An accountable executive (CTO, CIO or COO) is formally appointed.</p></li><li><p>The three lines of defence model is respected: operations, risk-control, and internal audit.</p></li><li><p>The board approves and publishes the underlying assumptions of the size-risk matrix every year.</p></li></ul><p><strong>Mini-Checklist</strong></p><ul><li><p>Board minutes reflect an annual ICT-risk review</p></li><li><p>First- and second-line roles separated by policy or contract</p></li></ul><div><hr></div><h2>4. Tailor Your ICT-RMF (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_16">Article 6</a>)</h2><p>Article 6 demands an ICT-Risk Management Framework but explicitly allows scalability based on &#8220;size, risk profile and business complexity.&#8221; You can extend existing cyber- or operational-risk processes instead of starting from scratch.</p><blockquote><p><strong>Reminder:</strong> If you qualify for Article 16, the entire framework can often be compressed into a single 10&#8211;15-page integrated policy.</p></blockquote><h3>Minimum Viable Controls Every CTO Must Evidence</h3><p>Even the leanest ICT-RMF must demonstrably cover the six NIST-style functions:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mt3F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mt3F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 424w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 848w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 1272w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mt3F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png" width="783" height="294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:294,&quot;width&quot;:783,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39537,&quot;alt&quot;:&quot;Minimum Viable Controls Every CTO Must Evidence&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Minimum Viable Controls Every CTO Must Evidence" title="Minimum Viable Controls Every CTO Must Evidence" srcset="https://substackcdn.com/image/fetch/$s_!Mt3F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 424w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 848w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 1272w, https://substackcdn.com/image/fetch/$s_!Mt3F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F073e90dd-1919-4d99-a82d-446c4b6ec1e9_783x294.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>5. Scale Incident Reporting (Articles 19&#8211;20)</h2><h3>Match the Clock to Your Size</h3><p>The final RTS (17 July 2024) sets strict windows:</p><ul><li><p><strong>4 hours</strong> after designating an incident as <em>major</em> &#8212; initial notification</p></li><li><p><strong>24 hours</strong> after detection &#8212; if classification is still pending</p></li><li><p>If a deadline falls on a non-business day, most entities (except significant/systemic ones) may report by <strong>12:00 on the next working day</strong></p></li></ul><h3>Automate Severity Mapping</h3><p>A rules engine that weighs service impact, customer reach, and data loss can instantly tag incidents as <em>major</em> or <em>significant</em>, ensuring only genuinely major events trigger the 4-hour clock.</p><h3>Keep One Taxonomy &#8212; DORA, GDPR, NIS2</h3><p>Align labels so one incident equals one record. The Commission explicitly encourages converged taxonomies.</p><div><hr></div><h2>6. Calibrate TLPT &amp; Testing (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_26">Article 26</a>)</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ORgN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ORgN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 424w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 848w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 1272w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ORgN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png" width="783" height="220" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:220,&quot;width&quot;:783,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31613,&quot;alt&quot;:&quot;TLPT &amp; Testing (Article 26)&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="TLPT &amp; Testing (Article 26)" title="TLPT &amp; Testing (Article 26)" srcset="https://substackcdn.com/image/fetch/$s_!ORgN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 424w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 848w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 1272w, https://substackcdn.com/image/fetch/$s_!ORgN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2a19632-49e5-4a2f-9612-749e3ff0fa76_783x220.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Document your rationale and keep evidence for auditors.</p><div><hr></div><h2>7. Streamline Third-Party Oversight (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_28">Articles 28&#8211;31</a>)</h2><h3>Quick Risk Triage</h3><ol><li><p>List all external ICT services.</p></li><li><p>Score criticality: <em>core</em>, <em>important</em> or <em>supporting</em>.</p></li><li><p>Scale due diligence accordingly.</p></li></ol><h3>Risk-Based Due Diligence</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!75cz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!75cz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 424w, https://substackcdn.com/image/fetch/$s_!75cz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 848w, https://substackcdn.com/image/fetch/$s_!75cz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 1272w, https://substackcdn.com/image/fetch/$s_!75cz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!75cz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png" width="782" height="171" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84e30711-c365-494f-90ff-0176f758c37b_782x171.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:171,&quot;width&quot;:782,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23287,&quot;alt&quot;:&quot;Risk-Based Due Diligence&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Risk-Based Due Diligence" title="Risk-Based Due Diligence" srcset="https://substackcdn.com/image/fetch/$s_!75cz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 424w, https://substackcdn.com/image/fetch/$s_!75cz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 848w, https://substackcdn.com/image/fetch/$s_!75cz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 1272w, https://substackcdn.com/image/fetch/$s_!75cz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84e30711-c365-494f-90ff-0176f758c37b_782x171.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Mandatory Contract Clauses (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_30">Article 30 &#167; 2</a>)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XgD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XgD3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 424w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 848w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 1272w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XgD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png" width="918" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:918,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82367,&quot;alt&quot;:&quot;DORA proportionality Mandatory Contract Clauses (Article 30 &#167; 2)&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA proportionality Mandatory Contract Clauses (Article 30 &#167; 2)" title="DORA proportionality Mandatory Contract Clauses (Article 30 &#167; 2)" srcset="https://substackcdn.com/image/fetch/$s_!XgD3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 424w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 848w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 1272w, https://substackcdn.com/image/fetch/$s_!XgD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41f00c73-7d2e-43c5-a718-e886dbc3fa84_918x690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Every contract covering a critical or important service must include:</p><ul><li><p>audit and inspection rights</p></li><li><p>conditions for sub-outsourcing</p></li><li><p>data location and portability requirements</p></li><li><p>incident-notification timelines</p></li><li><p>exit and transition plan</p></li></ul><div><hr></div><h2>8. Evidence Your Decisions</h2><p>Regulators want the logic behind scaled controls. Annotate each control with its link to the size-risk matrix and refresh documentation quarterly. All controls must be fully in force or explicitly scheduled.</p><div><hr></div><h2>9. Tap Guidance &amp; Peers</h2><p>Reg-Tech sandboxes, industry round-tables and peer benchmarks are excellent ways to pressure-test proportionality decisions before audits.</p><div><hr></div><h2>10. Build a Three-Year Maturity Roadmap</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wnCN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wnCN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 424w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 848w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 1272w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wnCN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png" width="788" height="176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/887093c8-7533-436d-b0fb-c8528197e689_788x176.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:176,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26702,&quot;alt&quot;:&quot;Build a Three-Year Maturity Roadmap&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/166837411?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Build a Three-Year Maturity Roadmap" title="Build a Three-Year Maturity Roadmap" srcset="https://substackcdn.com/image/fetch/$s_!wnCN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 424w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 848w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 1272w, https://substackcdn.com/image/fetch/$s_!wnCN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887093c8-7533-436d-b0fb-c8528197e689_788x176.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>KPIs should track <em>impact</em> (e.g., MTTR on critical services) rather than headcount.</p><p></p><div><hr></div><h2>Final Tip &#8212; One-Control Sprint (4 Weeks)</h2><p>Pick a single high-impact control, map it to DORA&#8217;s proportionality wording, right-size it and document your rationale. Repeat quarterly; proportionality will soon become muscle memory.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[DORA Compliance Roadmap for Fintech CTOs]]></title><description><![CDATA[Six months past DORA&#8217;s Jan 17, 2025 deadline, a 5-step roadmap for fintech CTOs to close compliance gaps and build true digital resilience.]]></description><link>https://www.fromciso.com/p/dora-compliance-roadmap</link><guid isPermaLink="false">https://www.fromciso.com/p/dora-compliance-roadmap</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Mon, 09 Jun 2025 06:15:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2cdc0ace-d731-4568-bf61-2cb75c09f355_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>As of <strong>June 2025</strong>, DORA has been applicable since 17 January 2025. Many fintechs have yet to fully meet their requirements. This roadmap is designed for CTOs of firms that are not yet DORA&#8209;compliant and need a clear plan of action.</p><div><hr></div><h2>Assign Clear Ownership in Your DORA Compliance Roadmap</h2><h3>Why Ownership is Your First Step</h3><p>DORA (<a href="https://eur-lex.europa.eu/eli/reg/2022/2554">Digital Operational Resilience Act</a>) places direct responsibility for ICT risk management squarely on your board (<a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_4">Article 4</a>). Without formal accountability, remediation stalls, audits drag, and regulators quickly lose patience. By formally assigning board-level responsibility and naming a single <strong>DORA Programme Lead</strong>, you eliminate confusion and empower teams to focus on delivery rather than debating decision-making authority.</p><h3>Four Actions Your Fintech Can Complete This Month</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4WyU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4WyU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 424w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 848w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 1272w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4WyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png" width="1092" height="588" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:588,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66676,&quot;alt&quot;:&quot;Four Actions Your Fintech Can Complete This Month&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/165426889?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Four Actions Your Fintech Can Complete This Month" title="Four Actions Your Fintech Can Complete This Month" srcset="https://substackcdn.com/image/fetch/$s_!4WyU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 424w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 848w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 1272w, https://substackcdn.com/image/fetch/$s_!4WyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59ee4fd3-6a6e-4db4-a07d-53a6a4aa4502_1092x588.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Four Actions Your Fintech Can Complete This Month</figcaption></figure></div><ol><li><p><strong>Board Resolution</strong></p><ul><li><p>Add DORA compliance explicitly to your risk appetite statement.</p></li><li><p>Officially appoint a DORA Programme Lead (often your CTO or COO).</p></li></ul></li><li><p><strong>Draft a RACI Matrix</strong></p><ul><li><p>Map each Delegated/Implementing Regulation requirement to roles:</p><ul><li><p>Board (<a href="https://www.fromciso.com/p/board-accountability-in-dora">Accountable</a>)</p></li><li><p>Programme Lead (Responsible)</p></li><li><p>Control Owners (Consulted)</p></li><li><p>Audit (Informed)</p></li></ul></li><li><p>Keep it concise&#8212;one page&#8212;for daily reference.</p></li></ul></li><li><p><strong>Launch an Operational Resilience Council</strong></p><ul><li><p>Members: CTO (Chair), CISO, Head of DevOps, Legal, Risk, and a business-line lead.</p></li><li><p>Schedule bi&#8209;weekly 30&#8209;minute meetings focused on blockers and metrics, not slide decks.</p></li></ul></li><li><p><strong>Publish a Two&#8209;Tier Escalation Path</strong></p><ul><li><p>Tier 1: Medium&#8209;severity incidents handled by Control Owners.</p></li><li><p>Tier 2: Major ICT incidents escalate internally within 15 minutes; regulators must be notified by the end of the next business day (per <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_9">DORA Article 9</a>), with a detailed report within one month.</p></li></ul></li></ol><blockquote><p>Clear ownership accelerates compliance and reduces regulatory friction.</p></blockquote><h3>Mini&#8209;Case: How One 120&#8209;Person Payments Firm Did It</h3><p>Previously, five separate teams managed security, causing vendor assessments to take 90 days. After appointing a DORA Programme Lead and launching their Operational Resilience Council:</p><ul><li><p>Vendor review cycles dropped to 25 days.</p></li><li><p>Completed a cross&#8209;service gap analysis in three weeks.</p></li><li><p>Reduced regulator follow&#8209;up questions by 40%.</p></li></ul><p>Think of ownership as a product feature: design it once, test it regularly, and iterate when people or processes change.</p><div><hr></div><h2>Map Your Critical Business Services</h2><h3>Why This Matters</h3><p>Under DORA, your board is accountable for critical functions. A glitch in payments or onboarding can trigger regulatory intervention and fines. Clearly defining critical services&#8212;those whose failure would harm customers, impact capital, or breach licence conditions&#8212;is essential.</p><h3>Four&#8209;Step Mapping Playbook for Fintech CTOs</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C7Ao!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C7Ao!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 424w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 848w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 1272w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C7Ao!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png" width="611" height="668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49433,&quot;alt&quot;:&quot;Four&#8209;Step Mapping Playbook for Fintech CTOs&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/165426889?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9499d17b-2351-4678-acdf-d2ff1610d3e6_613x670.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Four&#8209;Step Mapping Playbook for Fintech CTOs" title="Four&#8209;Step Mapping Playbook for Fintech CTOs" srcset="https://substackcdn.com/image/fetch/$s_!C7Ao!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 424w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 848w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 1272w, https://substackcdn.com/image/fetch/$s_!C7Ao!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba1d361-100b-4292-9fb8-92a639aa9bc0_611x668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Four&#8209;Step Mapping Playbook for Fintech CTOs</figcaption></figure></div><ol><li><p><strong>List Candidate Services</strong></p><ul><li><p>Identify top&#8209;level customer journeys from your product roadmap and incident logs.</p></li><li><p>Stress&#8209;test each against DORA criteria: customer impact, market integrity, and financial stability.</p></li><li><p>Typical critical services: payments execution, digital lending, KYC/AML screening, core ledger.</p></li></ul></li><li><p><strong>Decompose Each Service</strong></p><ul><li><p>Break down into people, processes, technology, facilities, and data.</p></li><li><p>Identify hidden dependencies (shared SRE teams, single secrets vaults).</p></li><li><p>Tip: Run a half&#8209;day workshop with engineering, ops, and compliance.</p></li></ul></li><li><p><strong>Visualise with Service Blueprints</strong></p><ul><li><p>Plot customer activities, internal assets, and external providers.</p></li><li><p>Label components with RTO/RPO targets defined in your ICT risk management framework (per <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554#art_7">DORA Article 7</a>) and aligned with ESAs guidance.</p></li><li><p>Identify single points of failure&#8212;input for gap analysis.</p></li></ul></li><li><p><strong>Validate and Assign Ownership</strong></p><ul><li><p>Assign an accountable executive (often the product owner) for each blueprint.</p></li><li><p>Store blueprints in your GRC/wiki, updating quarterly to track drift.</p></li></ul></li></ol><p><strong>Quick Win: Two&#8209;Week Dependency Map</strong></p><ul><li><p><strong>Week 1:</strong> Daily 60&#8209;minute workshops to draft blueprints in <a href="https://miro.com/">Miro</a> or <a href="https://www.lucidchart.com/">Lucidchart</a>.</p></li><li><p><strong>Week 2:</strong> Circulate for feedback, finalise RTO/RPO tags, and present a one&#8209;page heat map to your board.</p></li></ul><p>Outcome: A regulator&#8209;ready register of critical services by month&#8209;end&#8212;no new tooling required.</p><div><hr></div><h2>Run a Structured DORA Gap Analysis</h2><h3>Why a Structured Approach Matters</h3><p>DORA&#8217;s Articles set objectives; the RTS/ITS Regulations (e.g., <a href="https://eur-lex.europa.eu/eli/reg_del/2024/1773/oj/eng">Delegated Reg 2024/1773</a>, <a href="https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng">Implementing Reg 2024/2956</a>, <a href="https://www.eba.europa.eu/risk-and-data-analysis/reporting-frameworks/reporting-framework-40">ESA v4.0 Reporting Package</a>) specify controls. A systematic gap analysis shows compliant controls, tweaks needed, and missing elements.</p><h3>Five&#8209;Step Playbook for Fintech CTOs</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3LKK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3LKK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 424w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 848w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 1272w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3LKK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png" width="780" height="712" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:712,&quot;width&quot;:780,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84887,&quot;alt&quot;:&quot;Five&#8209;Step Playbook for Fintech CTOs Diagram&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/165426889?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Five&#8209;Step Playbook for Fintech CTOs Diagram" title="Five&#8209;Step Playbook for Fintech CTOs Diagram" srcset="https://substackcdn.com/image/fetch/$s_!3LKK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 424w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 848w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 1272w, https://substackcdn.com/image/fetch/$s_!3LKK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa97587ea-f9fb-4a7c-8e23-606fe8debae9_780x712.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Five&#8209;Step Playbook for Fintech CTOs</figcaption></figure></div><ol><li><p><strong>Scope the Assessment</strong></p><ul><li><p>Entities: parent, regulated subsidiaries, and relevant cloud regions.</p></li><li><p>Include all applicable Delegated/Implementing texts currently in force.</p></li></ul></li><li><p><strong>Map Existing Controls</strong></p><ul><li><p>Leverage SOX, ISO 27001, and PCI evidence where relevant.</p></li><li><p>Document control owners, artefacts, and frequency.</p></li></ul></li><li><p><strong>Score Each Clause</strong></p><ul><li><p>Status: Compliant (&#10003;), Partially Compliant (~), Not Compliant (&#10007;).</p></li><li><p>Impact: High if it affects critical services; else Medium/Low.</p></li><li><p>Effort: High for new tooling; else Medium/Low.</p></li></ul></li><li><p><strong>Visualize Results</strong></p><ul><li><p>Create a heat&#8209;map spreadsheet (red for urgent gaps).</p></li><li><p>Import into your GRC platform for remediation tracking.</p></li></ul></li><li><p><strong>Prioritize Fixes</strong></p><ul><li><p>Address High&#8209;Impact/Low&#8209;Effort first; schedule Low&#8209;Impact/High&#8209;Effort later.</p></li><li><p>Set deadlines.</p></li></ul></li></ol><blockquote><p><strong>Mini&#8209;Checklist:</strong></p><ul><li><p>Board approval of scope.</p></li><li><p>Cross&#8209;reference table linking Delegated/Implementing clauses to controls.</p></li><li><p>Action log with owners, budgets, target dates.</p></li><li><p>Time&#8209;stamped audit trails from your GRC.</p></li></ul></blockquote><div><hr></div><h2>Build a Modular Control Library</h2><h3>Why This Matters</h3><p>DORA demands consistent, comprehensive ICT controls. A modular library lets you define each control once, reuse across services, and automate updates, cutting maintenance and audit pain.</p><h3>Four Steps to Your &#8220;Golden Sources&#8221;</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y0QF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y0QF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 424w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 848w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 1272w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y0QF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png" width="744" height="509" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:509,&quot;width&quot;:744,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50050,&quot;alt&quot;:&quot;Four Steps to Your &#8220;Golden Sources&#8221; Diagram&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/165426889?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Four Steps to Your &#8220;Golden Sources&#8221; Diagram" title="Four Steps to Your &#8220;Golden Sources&#8221; Diagram" srcset="https://substackcdn.com/image/fetch/$s_!Y0QF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 424w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 848w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 1272w, https://substackcdn.com/image/fetch/$s_!Y0QF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b8048e-b911-4d16-8287-9410cfc638e5_744x509.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Four Steps to Your &#8220;Golden Sources&#8221;</figcaption></figure></div><ol><li><p><strong>Define a Control Taxonomy</strong></p><ul><li><p>Group by domain (access management, change control, backup &amp; recovery).</p></li><li><p>Include metadata: objective, owner, frequency, KPIs, and evidence source.</p></li></ul></li><li><p><strong>Single Source of Truth</strong></p><ul><li><p>Store controls in version&#8209;controlled Markdown/YAML in Git.</p></li><li><p>Link to your GRC for synchronisation.</p></li></ul></li><li><p><strong>Parameterise for Variation</strong></p><ul><li><p>Use variables for RTO/RPO targets, environments, and jurisdictions.</p></li></ul></li><li><p><strong>Automate Distribution</strong></p><ul><li><p>GitOps pipelines push changes to runbooks, IaC templates, and policy portals.</p></li><li><p>Nightly, jobs update KPI dashboards and flag orphaned controls.</p></li></ul></li></ol><p><strong>Core Controls to Cover First</strong></p><ul><li><p>Access management (MFA, orphan account sweeps)</p></li><li><p>Change control (code reviews, rollback plans)</p></li><li><p>Backup &amp; recovery (immutable snapshots, quarterly tests)</p></li></ul><div><hr></div><h2>Harden Incident Reporting Procedures</h2><h3>Why It Matters</h3><p>DORA Article 9 requires notification of major ICT incidents to authorities by the end of the next business day, with a detailed report within one month and a summary within three months. Internal SLAs can be tighter to ensure readiness.</p><p><strong>Implementation in Four Sprints</strong></p><ul><li><p><strong>Sprint 1:</strong> Map current incident flows.</p></li><li><p><strong>Sprint 2:</strong> Create pre-authorised report templates.</p></li><li><p><strong>Sprint 3:</strong> Automate submission via serverless functions.</p></li><li><p><strong>Sprint 4:</strong> Conduct tabletop exercises.</p></li></ul><div><hr></div><h2>Launch Threat&#8209;Led Penetration Testing (TLPT)</h2><p><strong>Note:</strong> <a href="https://eur-lex.europa.eu/eli/reg_del/2025/855/oj/eng">Delegated Regulation C(2025) 885</a> (13 Feb 2025) mandates annual TLPT only for systemic financial entities and designated Critical ICT Third&#8209;Party Providers (CTPPs). Tailor your TLPT approach accordingly.</p><div><hr></div><h2>Industrialise Third&#8209;Party Risk Management</h2><p>Align vendor tiering with the 18 Feb 2025 ESA CTPP Roadmap, and submit registry data using <a href="https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng">ITS 2024/2956</a> templates.</p><div><hr></div><h2>Retrofit Contracts for Resilience</h2><p>Update SLAs with RTOs, incident&#8209;sharing clauses, audit rights, data portability, exit strategies, and sub&#8209;outsourcing notifications.</p><div><hr></div><h2>Embed a Resilience Culture</h2><p>Use secure&#8209;by&#8209;design checklists, micro&#8209;learning, quarterly drills, and reward proactive behaviours.</p><div><hr></div><h2>Set Up Continuous Assurance</h2><p>Automate evidence collection via central logs, config&#8209;drift detection, and attestation workflows.</p><div><hr></div><p><strong>Final Tip:</strong> Start your 30&#8209;day sprint now: secure executive ownership, run a focused gap analysis using the Delegated/Implementing Acts in force, and build an actionable backlog. Acting now makes compliance a competitive advantage well before regulators arrive.</p>]]></content:encoded></item><item><title><![CDATA[DORA Compliance: Structuring CTO–CISO Roles for Resilience]]></title><description><![CDATA[Discover how to clearly define CTO and CISO roles for smooth DORA compliance, minimise leadership friction, and strengthen fintech resilience proactively.]]></description><link>https://www.fromciso.com/p/dora-cto-ciso-resilience</link><guid isPermaLink="false">https://www.fromciso.com/p/dora-cto-ciso-resilience</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Tue, 03 Jun 2025 17:30:11 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7c364df2-c62e-4394-8649-746aa2a3a34a_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Why Your Board-Sanctioned DORA Charter Matters</h2><p>Let me guess&#8212;when you hear "DORA regulation," you might think it's just another tedious compliance checkbox, right? But here's the kicker: ignoring DORA could put you and your leadership team personally at risk.</p><p><a href="https://www.int-comp.org/insight/digital-operational-resilience-nis2-and-dora-lessons-for-senior-management/">Digital Operational Resilience: Lessons from NIS2 and DORA for Senior Management</a> explains it clearly: DORA elevates digital operational resilience from a "tech-only" task to a board-level <em>obligation</em>. Without a formal charter, executives like you face serious personal exposure.</p><p>To protect your firm&#8212;and yourself&#8212;you need a spelt-out DORA Charter. And guess what? Setting this up doesn't have to be a headache. Let&#8217;s dive in.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Your 5-Step Checklist for a Clear, Actionable DORA Charter</h2><ol><li><p>Digital-Resilience Objectives</p></li></ol><p>Clearly defined, measurable targets like <em>"Critical APIs must recover within 2 hours with 99.95% availability."</em></p><ol start="2"><li><p>Scope and Ultimate Accountability</p></li></ol><ul><li><p>Explicitly assert that the board holds final accountability.</p></li><li><p>Assign the CTO to lead tech delivery and the CISO to manage controls.</p></li></ul><ol start="3"><li><p>Governance Cadence</p></li></ol><p>Commit to quarterly board reviews using a unified Risk &amp; Resilience Dashboard, keeping accountability fresh, not buried in paperwork.</p><ol start="4"><li><p>Escalation Thresholds</p></li></ol><ul><li><p>Predefined &#8220;break-glass&#8221; triggers (e.g., cumulative downtime &gt;15 minutes, data loss &#8805;1 GB).</p></li><li><p>Assign duty officers and explicit communication channels (e.g., dedicated Signal channel) to ensure quick board visibility.</p></li></ul><ol start="5"><li><p>Delegated Authorities</p></li></ol><p>Clearly outline who can make decisions independently (like CTO&#8211;CISO teams selecting tools) and when board ratification is unavoidable (e.g., payment processor outsourcing).</p><h3>An Example Charter Excerpt (Simple and Clear):</h3><pre><code>Charter Clause 4: Ultimate Accountability 
The Board retains full accountability for all ICT risk decisions (DORA Article 5) 
The CTO owns the technology strategy 
The CISO oversees risk management. 
Both must jointly approve deviations from established thresholds</code></pre><h4>Tips for a Smooth Board Sign-Off:</h4><ul><li><p>Start each clause with a plain-English summary&#8212;no jargon first!</p></li><li><p>Attach a simple RACI matrix showing roles clearly at a glance.</p></li><li><p>Rehearse the pitch with your Company Secretary to iron out any wording confusion upfront.</p></li></ul><div class="pullquote"><p>A clearly worded charter protects board members personally from DORA-related penalties.</p></div><p>Now that your foundational charter is set, every decision&#8212;dashboards, testing, vendors&#8212;rests on firm, mutual authority.</p><h2>Mastering the Complementary Leadership Archetypes Under DORA</h2><p>Think about this for a moment: <em>Why do compliance discussions sometimes feel like battles?</em> Often, it's not missing controls&#8212;it's clashing leadership styles. Mapping how each leader naturally drives decisions can smooth friction and ease compliance.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OlnG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OlnG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 424w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 848w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 1272w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OlnG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png" width="630" height="190" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:190,&quot;width&quot;:630,&quot;resizeWidth&quot;:630,&quot;bytes&quot;:38385,&quot;alt&quot;:&quot;Table comparing three CISO leadership styles&#8212;Authoritative, Collaborative and Servant Leader&#8212;alongside their typical behaviors and the recommended CTO counterbalance&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/164955675?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="Table comparing three CISO leadership styles&#8212;Authoritative, Collaborative and Servant Leader&#8212;alongside their typical behaviors and the recommended CTO counterbalance" title="Table comparing three CISO leadership styles&#8212;Authoritative, Collaborative and Servant Leader&#8212;alongside their typical behaviors and the recommended CTO counterbalance" srcset="https://substackcdn.com/image/fetch/$s_!OlnG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 424w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 848w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 1272w, https://substackcdn.com/image/fetch/$s_!OlnG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e2fc217-3a24-4236-bc2f-a74839cdc230_630x190.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Table 1. Matching each CISO's style with an ideal CTO counterpart to create balanced, DORA-ready governance.</figcaption></figure></div><p><a href="https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/understanding-ciso-management-styles">Understanding CISO Management Styles, ISACA</a></p><h3>Quick Self-Audit:</h3><ol><li><p>Identify your leadership style (<a href="https://www.discprofile.com/what-is-disc">DISC</a>, <a href="https://www.themyersbriggs.com/en-US/Connect-With-Us/Blog/myers-briggs-personality-types-and-leadership">MBTI</a>, or plain English).</p></li><li><p>Exchange style notes with your CISO over a 15-minute coffee huddle.</p></li><li><p>Highlight conflicting approaches (e.g., rapid iteration vs. strict control) and agree on a decision-making rule, usually defaulting to board-defined risk tolerance.</p></li></ol><p>Want the secret sauce? <strong>Choose the right leader for the right forum:</strong></p><ul><li><p><strong>CTO chairs Architecture Boards</strong>; authoritative CISOs co-pilot with checks.</p></li><li><p><strong>CISO leads Risk Committee</strong>; collaborative CTOs provide smart evidence.</p></li><li><p>Ensure servant-leader CISOs facilitate post-incident learning while SRE leads the technical portions.</p></li></ul><h3>Checklist for Next Quarter:</h3><p>&#9744; Identify each leader&#8217;s two strengths and one blind spot.</p><p>&#9744; Document forum leadership clearly in your DORA charter.</p><p>&#9744; Quarterly review to adapt as needed.</p><p>Think of leadership archetypes as technical dependencies within your governance architecture&#8212;map, version-control, and refactor regularly. But wait&#8212;there's more!</p><h2>DORA Articles to Roles: Using a Crystal-Clear RACI Matrix</h2><p>DORA regulations read like they're written for regulators, not your org chart. A clear RACI matrix converts dense legal text into four clear verbs&#8212;Responsible, Accountable, Consulted, and Informed. No more guessing games.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nczB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nczB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 424w, https://substackcdn.com/image/fetch/$s_!nczB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 848w, https://substackcdn.com/image/fetch/$s_!nczB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 1272w, https://substackcdn.com/image/fetch/$s_!nczB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nczB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png" width="722" height="606" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:606,&quot;width&quot;:722,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49656,&quot;alt&quot;:&quot;Inverted funnel infographic showing the path from DORA regulations to clear roles and responsibilities. Four stacked layers&#8212;Identify Key Articles, Break Down Responsibilities, Assign Roles, Visualize Matrix&#8212;each marked with an icon and arrowed captions explaining the step toward a RACI framework.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/164955675?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Inverted funnel infographic showing the path from DORA regulations to clear roles and responsibilities. Four stacked layers&#8212;Identify Key Articles, Break Down Responsibilities, Assign Roles, Visualize Matrix&#8212;each marked with an icon and arrowed captions explaining the step toward a RACI framework." title="Inverted funnel infographic showing the path from DORA regulations to clear roles and responsibilities. Four stacked layers&#8212;Identify Key Articles, Break Down Responsibilities, Assign Roles, Visualize Matrix&#8212;each marked with an icon and arrowed captions explaining the step toward a RACI framework." srcset="https://substackcdn.com/image/fetch/$s_!nczB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 424w, https://substackcdn.com/image/fetch/$s_!nczB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 848w, https://substackcdn.com/image/fetch/$s_!nczB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 1272w, https://substackcdn.com/image/fetch/$s_!nczB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f040cc1-f6f7-463b-8036-fcbab74b2bd6_722x606.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Your Rapid-Fire 5-Step Workshop:</h3><ol><li><p>List DORA workstreams (ICT risk, incident response, resilience tests, vendor oversight).</p></li><li><p>Map workstreams directly to key DORA articles (e.g., Incident reporting &#8594; Art. 15&#8211;20).</p></li><li><p>Define critical roles clearly (CTO, CISO, DevOps, Risk Lead, Procurement, Board Audit).</p></li><li><p>Build your RACI matrix as a team using simple tags&#8212;R, A, C, I.</p></li><li><p>Stress-test for oversights&#8212;especially incident Root Cause Analysis (RCA).</p></li></ol><p>Gartner confirms effective RACIs cut audit headaches by 30% versus unwieldy charts (<a href="https://www.gartner.com/en/documents/4010028-building-effective-raci-matrix">Gartner, Building Effective RACI Matrices</a>).</p><h2>Hybrid Governance: COBIT Meets ISO 42001 for Effortless Oversight</h2><p>Ever felt torn between COBIT&#8217;s disciplined framework and ISO standards for AI? Here's the good news: <strong>you don&#8217;t have to choose</strong>. Blend COBIT 2019 with ISO 42001 for a simple, comprehensive library covering both legacy and AI-driven fintech services.</p><h3>Create Your One-Stop Control Framework in 3 Simple Steps:</h3><ol><li><p>Combine COBIT governance objectives with ISO controls on AI lifecycle, data drift, and bias testing.</p></li><li><p>Clearly assign roles to Tech (Process Owners) and Security (AI Risk Owners).</p></li><li><p>Automate evidence&#8212;connect CI/CD pipelines to compliance metrics.</p></li></ol><p>When regulators come knocking, your controls tell a consistent story, exactly what DORA expects.</p><h2>Imagine This: A Single Dashboard for Joint Visibility</h2><p>Here&#8217;s why two slide-decks&#8212;one tech-focused, one risk-focused&#8212;won't work anymore: Directors must stitch fragmented stories mentally. A single Joint Risk &amp; Resilience Dashboard clears that confusion instantly.</p><p>Your dashboard's essentials?</p><ul><li><p>Tech KPIs: MTTR and change fail rates</p></li><li><p>Risk KRIs: Inherent risk, DORA maturity rating</p></li></ul><p>Use plain language: &#8220;MTTR &#8593;30%&#8221; becomes &#8220;Customers faced an extra 18 mins downtime last quarter.&#8221; Directors get it instantly.</p><h2>Simplified DevSecOps Control Testing for Continuous Assurance</h2><p>DORA demands "continuous assurance"&#8212;daily management, not annual audits. Embedding security directly into your CI/CD pipelines cuts risk, drift and debugging nightmares.</p><p>Four Shift-left Essentials:</p><ul><li><p>Static Code Analysis</p></li><li><p>Automated Dependency Scans (e.g., high CVSS scores)</p></li><li><p>IaC Security Linting</p></li><li><p>Secrets Detection</p></li></ul><h2>Joint Crisis Drills: Rehearsals That Really Pay Off</h2><p>Tabletop and red-team drills expose CTO&#8211;CISO frictions before actual incidents do. Keep drills short (90 minutes) and feed identified issues straight into your sprint backlog. Simple. Effective.</p><p><a href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-84.pdf">NIST's SP 800-84</a> backs this proactive approach&#8212;why reinvent the wheel?</p><h2>Unified Vendor Risk: One Front Door, Fast Decisions</h2><p>Running parallel procurement, vendor risk, and security review streams? Guess what&#8212;you're wasting 30-40% time. Bundle questionnaires, assessments, and SLAs into a unified vendor intake pipeline.</p><h2>Personal Liability Isn&#8217;t Just an Abstract Threat</h2><p>It's your career on the line now. Three safeguards that protect you:</p><ul><li><p>Decision logs clearly timestamped</p></li><li><p>Updated D&amp;O Insurance</p></li><li><p>Collective board-minute approval for critical releases</p></li></ul><h2>Your Simple 30-60-90-Day CTO Roadmap Starts Today</h2><ul><li><p><strong>Days 0&#8211;30:</strong> Draft your DORA Charter.</p></li><li><p><strong>Days 31&#8211;60:</strong> Launch a quick-win Joint Dashboard.</p></li><li><p><strong>Days 61&#8211;90:</strong> Conduct your first joint CTO&#8211;CISO drill.</p></li></ul><p>Start now&#8212;before auditors ask tough questions you can&#8217;t answer.</p>]]></content:encoded></item><item><title><![CDATA[Board Accountability in DORA – Setting the Tone at the Top]]></title><description><![CDATA[How the EU&#8217;s DORA transforms cyber-resilience into board-level accountability&#8212;and a strategic edge.]]></description><link>https://www.fromciso.com/p/board-accountability-in-dora</link><guid isPermaLink="false">https://www.fromciso.com/p/board-accountability-in-dora</guid><dc:creator><![CDATA[Andrey Gubarev]]></dc:creator><pubDate>Wed, 30 Apr 2025 19:37:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dc176e41-80da-4cb8-bc48-e4ce1ed56dbd_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The EU&#8217;s Digital Operational Resilience Act (DORA) rewrites the rules of accountability for information and communication technology (ICT) risk. For the first time, individual directors and senior executives in financial entities face explicit civil, administrative, and&#8212;in some Member States&#8212;criminal exposure when operational outages or cyber-incidents reveal weak governance.</p><p>DORA, therefore, elevates &#8220;tone at the top&#8221; from a feel-good slogan to a statutory duty. Boards that embed digital resilience into culture, incentives, and decision-making can convert regulatory pressure into a competitive edge&#8212;protecting customer trust, lowering recovery costs and signalling robustness to investors, rating agencies and supervisors.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Key takeaways:</p><ol><li><p>Liability is personal; delegation does not absolve directors.</p></li><li><p>Digital literacy is now a board-composition issue.</p></li><li><p>Metrics such as mean-time-to-detect and patch latency will sit alongside capital ratios on dashboards.</p></li><li><p>Table-top exercises, clear escalation protocols and 24-hour notification playbooks separate resilient firms from merely compliant ones.</p></li><li><p>Culture is the multiplier: boards that value transparency and psychological safety encourage early escalation of weak controls&#8212;a hallmark of organisations that resist or recover quickly from attacks.</p></li></ol><p><em>Intended audience:</em> chairs, non-executive directors, CEOs, CTOs, CISOs and Audit &amp; Risk Committee members who need a concise roadmap for meeting DORA obligations while leveraging operational resilience as a source of long-term value.</p><h2>Why Tone at the Top Now Matters</h2><p><strong>Culture, governance and accountability.</strong> Digital tone at the top is the sum of explicit actions and implicit signals that tell employees, vendors and regulators how seriously the organisation takes operational resilience. Directors model cyber-hygiene, reward early escalation of bad news and refuse &#8220;executive exemptions.&#8221; Clear charters assign ownership of ICT risk, yet the full board approves the overarching framework and records why it accepted, mitigated or transferred each material risk. Finally, individual directors attest annually that controls are effective&#8212;signatures that now carry personal liability.</p><p><strong>Regulatory tail-winds.</strong> DORA lands in a dense thicket of overlapping rules&#8212;<a href="http://eur-lex.europa.eu/eli/dir/2022/2555">NIS2</a>, PSD3, GDPR, <a href="https://www.bis.org/bcbs/publ/d460.pdf">Basel&#8217;s operational-risk capital framework</a>, and sector guidelines from <a href="https://www.esma.europa.eu/">ESMA</a>, <a href="https://www.eba.europa.eu/homepage">EBA</a> and <a href="https://www.eiopa.europa.eu/index_en">EIOPA</a>&#8212;all converging on the same theme: explicit board accountability. Fail in one regime and investigations quickly spill into the others.</p><p><strong>Lessons from public failures.</strong> <a href="https://www.mishcon.com/news/following-a-joint-investigation-the-pra-and-fca-have-fined-tsb-bank-48m-following-its-2018-it-meltdown">TSB&#8217;s 2018 migration meltdown</a>, <a href="https://www.reuters.com/technology/worldline-says-payment-services-disruptions-italy-not-yet-resolved-2024-11-29/">Worldline&#8217;s 2021 payment outage</a>, and <a href="https://www.rte.ie/news/business/2024/0404/1441709-bank-of-ireland/">Bank of Ireland&#8217;s 2023 mobile-banking crash</a> share three threads: inadequate testing, poorly governed third-party dependencies and sluggish escalation to directors. Each episode underlines a simple truth&#8212;when boards fail to set a rigorous digital tone, regulators and investors are increasingly willing to set it for them.</p><h2>What DORA Demands from Boards</h2><p><strong>Statutory obligations and liability. </strong><a href="https://eur-lex.europa.eu/eli/reg/2022/2554">Article 5</a> requires directors to &#8220;approve, oversee and be accountable&#8221; for the entire ICT-risk framework. National authorities must impose &#8220;effective, proportionate and dissuasive&#8221; fines&#8212;many are setting ceilings at the higher of &#8364;10 million or 2 % of worldwide turnover. Supervisors may also re-assess fitness and propriety or refer gross negligence for criminal prosecution. Most daunting, the board must file an annual attestation that becomes discoverable evidence in future litigation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Et2Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Et2Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 424w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 848w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 1272w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Et2Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png" width="720" height="828" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64801,&quot;alt&quot;:&quot;DORA Board Duties&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/162526754?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="DORA Board Duties" title="DORA Board Duties" srcset="https://substackcdn.com/image/fetch/$s_!Et2Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 424w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 848w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 1272w, https://substackcdn.com/image/fetch/$s_!Et2Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6524d9d-2ac1-4322-abab-67b7e1f5a42a_720x828.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Governance wiring.</strong> Specialist committees may prepare and monitor, but ultimate accountability stays with the board. A simple decision-rights map clarifies boundaries:</p><p>Minutes must show genuine challenge; rubber-stamping violates DORA&#8217;s accountability principle.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G45a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G45a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 424w, https://substackcdn.com/image/fetch/$s_!G45a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 848w, https://substackcdn.com/image/fetch/$s_!G45a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 1272w, https://substackcdn.com/image/fetch/$s_!G45a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G45a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png" width="630" height="135" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:135,&quot;width&quot;:630,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28150,&quot;alt&quot;:&quot;Decision-rights map table with three columns: Columns: Activity | Committee Pre-Work | Board Decision Rows: &#8226; Define ICT risk appetite &#8212; Risk Committee drafts metrics &#8212; Board approves thresholds   &#8226; Select TLPT provider &#8212; Audit Committee shortlists &#8212; Board awards contract   &#8226; Accept residual risk &#8212; Risk Committee recommends &#8212; Board records acceptance&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/162526754?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Decision-rights map table with three columns: Columns: Activity | Committee Pre-Work | Board Decision Rows: &#8226; Define ICT risk appetite &#8212; Risk Committee drafts metrics &#8212; Board approves thresholds   &#8226; Select TLPT provider &#8212; Audit Committee shortlists &#8212; Board awards contract   &#8226; Accept residual risk &#8212; Risk Committee recommends &#8212; Board records acceptance" title="Decision-rights map table with three columns: Columns: Activity | Committee Pre-Work | Board Decision Rows: &#8226; Define ICT risk appetite &#8212; Risk Committee drafts metrics &#8212; Board approves thresholds   &#8226; Select TLPT provider &#8212; Audit Committee shortlists &#8212; Board awards contract   &#8226; Accept residual risk &#8212; Risk Committee recommends &#8212; Board records acceptance" srcset="https://substackcdn.com/image/fetch/$s_!G45a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 424w, https://substackcdn.com/image/fetch/$s_!G45a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 848w, https://substackcdn.com/image/fetch/$s_!G45a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 1272w, https://substackcdn.com/image/fetch/$s_!G45a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e18e7bf-75e5-4ea3-8ae0-4c92ddc30d8e_630x135.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Skills and composition.</strong> At least one director should have deep ICT or cyber-security expertise, while the rest must be able to interrogate dashboards on patch latency, TLPT findings and cloud concentration. Induction boot-camps, quarterly deep dives and external certifications close knowledge gaps and satisfy DORA&#8217;s &#8220;effectively informed&#8221; standard.</p><p><strong>Lifecycle oversight&#8212;identify, assess, test, respond.</strong></p><ul><li><p>Identify critical functions: approve criteria, demand living inventories and push for visibility of shadow IT.</p></li><li><p>Assess risk: sign off on extreme-but-plausible scenarios&#8212;heatwaves that knock out cooling, geopolitical sanctions that sever managed services.</p></li><li><p>Test controls: sanction TLPT scope at least every three years, track mean-time-to-fix as a standing KRI.</p></li><li><p>Respond to incidents: verify 24-hour notification capability, ensure CTO have a &#8220;red-phone&#8221; to the chair and review lessons-learned within 30 days.</p></li></ul><p><strong>Third-party and cloud risk.</strong> Boards must approve dependency maps, exit strategies and contractual clauses&#8212;on-site audit rights, encryption-key control, one-hour incident notice&#8212;because accountability does not stop at the firewall.</p><p><strong>Documentation and assurance.</strong> A defensible evidence trail is the board&#8217;s first shield: detailed minutes, decision logs, risk-acceptance records, incident dossiers and director-training registers. Internal Audit, operating under the Three Lines Model, provides independent assurance and maintains a combined-assurance map to avoid blind spots.</p><p><strong>Supervisory engagement.</strong> Expect data-driven, intrusive supervision: annual planning meetings, thematic reviews, short-notice inspections and public naming-and-shaming for serious breaches. Administrative fines can reach 2 % of global turnover; individuals may be suspended or disqualified.</p><h2>From Governance Wiring to Culture</h2><p><strong>Interlocking committees.</strong> Risk, Audit and Technology Committees should share dashboards, minutes and joint sessions so risk appetite, control assurance and tech forecasting reinforce each other. Rotating non-executive directors across committees spreads digital literacy and prevents single points of knowledge failure.</p><p><strong>Direct access for CTO.</strong> Officer needs independent reporting lines to the board and the right to escalate outside normal cycles. Escalation triggers include any incident that might hit DORA&#8217;s 24-hour clock, control failures affecting critical functions and breaches of risk appetite.</p><p><strong>Metrics that matter.</strong> A concise dashboard blends technical KRIs with culture indicators:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0mZp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0mZp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 424w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 848w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 1272w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0mZp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png" width="632" height="203" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:203,&quot;width&quot;:632,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30327,&quot;alt&quot;:&quot;Table titled &#8220;Metrics that matter&#8221; with three columns: Category, Indicator, Target. Rows are: 1. Detection &#8212; Mean-time-to-detect &#8212; < 15 min   2. Remediation &#8212; Critical patch latency &#8212; < 72 h   3. Control integrity &#8212; Control-break frequency &#8212; &#8804; 2 / qtr   4. Assurance &#8212; % red-team findings closed &#8212; 100 % in 90 days   5. Behaviour &#8212; &#8220;Speak-up&#8221; incidents &#8212; Upward trend&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/162526754?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table titled &#8220;Metrics that matter&#8221; with three columns: Category, Indicator, Target. Rows are: 1. Detection &#8212; Mean-time-to-detect &#8212; < 15 min   2. Remediation &#8212; Critical patch latency &#8212; < 72 h   3. Control integrity &#8212; Control-break frequency &#8212; &#8804; 2 / qtr   4. Assurance &#8212; % red-team findings closed &#8212; 100 % in 90 days   5. Behaviour &#8212; &#8220;Speak-up&#8221; incidents &#8212; Upward trend" title="Table titled &#8220;Metrics that matter&#8221; with three columns: Category, Indicator, Target. Rows are: 1. Detection &#8212; Mean-time-to-detect &#8212; < 15 min   2. Remediation &#8212; Critical patch latency &#8212; < 72 h   3. Control integrity &#8212; Control-break frequency &#8212; &#8804; 2 / qtr   4. Assurance &#8212; % red-team findings closed &#8212; 100 % in 90 days   5. Behaviour &#8212; &#8220;Speak-up&#8221; incidents &#8212; Upward trend" srcset="https://substackcdn.com/image/fetch/$s_!0mZp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 424w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 848w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 1272w, https://substackcdn.com/image/fetch/$s_!0mZp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3274ce95-a487-42d0-b5dd-d99d25e6bb6b_632x203.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Numbers must flow from independent sources, be tagged to accountable executives and be colour-coded against risk appetite.</p><p><strong>Training and simulations.</strong> Annual board-level crisis drills, quarterly micro-learning on new threats and joint tabletop exercises with critical cloud providers build muscle memory. After each exercise, assign directors as &#8220;guardians&#8221; for communications, legal or technology strands so lessons embed into normal governance cycles.</p><p><strong>Culture as the multiplier.</strong> Boards that link resilience to customer trust and career incentives, celebrate early escalation of near-misses and log the rationale for every risk decision outperform on crisis readiness. Insert culture goals into the chair&#8217;s annual letter, start each meeting with a five-minute incident-learning spotlight and ask, &#8220;What systemic assumption did we challenge this quarter?&#8221;</p><h2>Turning Compliance into Advantage</h2><p><strong>Investor and rating-agency lens.</strong> Moody&#8217;s can cap a rating by two notches when cyber governance is weak; S&amp;P bakes resilience into its Management &amp; Governance score; a 2023 MSCI study found that banks with top-quartile cyber scores enjoy a 17 bp lower five-year CDS spread. Post-breach bond issuances often carry a &#8220;cyber premium&#8221; until boards prove governance has improved.</p><p><strong>Customer trust and market share.</strong> Sub-60-minute recovery objectives, public status dashboards and 99.99 % availability SLAs translate directly into retention, price premium and net inflows when rivals stumble.</p><p><strong>ESG and sustainability narrative.</strong> Digital trust now sits squarely in the &#8220;G&#8221; of ESG. Boards that weave DORA compliance into sustainability reports attract Article 8/9 funds and strengthen their social licence to operate.</p><p><strong>Global convergence.</strong> The <a href="https://www.sec.gov/securities-topics/cybersecurity">SEC</a>, <a href="https://www.bankofengland.co.uk/explainers/what-is-the-prudential-regulation-authority-pra">PRA</a>/<a href="https://www.bankofengland.co.uk/">BoE</a>, <a href="https://www.mas.gov.sg/regulation">MAS</a> and <a href="https://www.apra.gov.au/">APRA</a> all echo DORA&#8217;s board-level expectations&#8212;explicit accountability, tight notification windows, scrutiny of third-party risk. Aligning with DORA, therefore, positions a firm for worldwide compliance, reducing duplication and eliminating safe harbours.</p><p><strong>Action roadmap.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VWGl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VWGl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 424w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 848w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 1272w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VWGl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png" width="641" height="277" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:277,&quot;width&quot;:641,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48623,&quot;alt&quot;:&quot;Table titled &#8220;Action roadmap&#8221; with three columns: Horizon, Key Actions, Outcome. Rows: &#8226; 0&#8211;90 days &#8212; Gap-analyse vs. DORA; deliver director training; appoint ICT-savvy NED &#8212; Clear priorities and informed board   &#8226; 6&#8211;12 months &#8212; Approve revised framework; launch resilience dashboard; run board-level crisis simulation &#8212; Data-driven oversight and &#8220;golden-hour&#8221; readiness   &#8226; 12&#8211;24 months &#8212; Embed resilience metrics in remuneration; commission TLPT; publish resilience statement &#8212; Incentive alignment, validated controls and investor confidence&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.fromciso.com/i/162526754?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Table titled &#8220;Action roadmap&#8221; with three columns: Horizon, Key Actions, Outcome. Rows: &#8226; 0&#8211;90 days &#8212; Gap-analyse vs. DORA; deliver director training; appoint ICT-savvy NED &#8212; Clear priorities and informed board   &#8226; 6&#8211;12 months &#8212; Approve revised framework; launch resilience dashboard; run board-level crisis simulation &#8212; Data-driven oversight and &#8220;golden-hour&#8221; readiness   &#8226; 12&#8211;24 months &#8212; Embed resilience metrics in remuneration; commission TLPT; publish resilience statement &#8212; Incentive alignment, validated controls and investor confidence" title="Table titled &#8220;Action roadmap&#8221; with three columns: Horizon, Key Actions, Outcome. Rows: &#8226; 0&#8211;90 days &#8212; Gap-analyse vs. DORA; deliver director training; appoint ICT-savvy NED &#8212; Clear priorities and informed board   &#8226; 6&#8211;12 months &#8212; Approve revised framework; launch resilience dashboard; run board-level crisis simulation &#8212; Data-driven oversight and &#8220;golden-hour&#8221; readiness   &#8226; 12&#8211;24 months &#8212; Embed resilience metrics in remuneration; commission TLPT; publish resilience statement &#8212; Incentive alignment, validated controls and investor confidence" srcset="https://substackcdn.com/image/fetch/$s_!VWGl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 424w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 848w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 1272w, https://substackcdn.com/image/fetch/$s_!VWGl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf90e6-9a87-4ed2-8d04-816c20ca329a_641x277.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Common pitfalls.</strong> Treating TLPT as a one-off tick-box, failing to document deliberations and allowing siloed committees to create blind spots.</p><p><strong>Success factors.</strong> Chair-level sponsorship, independent assurance and a living culture of psychological safety.</p><h2>In Short</h2><p>DORA makes &#8220;tone at the top&#8221; a legal requirement and a strategic opportunity. Directors who embed resilience into strategy, lead by example, insist on data-driven oversight and close the skills gap continuously will not only satisfy regulators but also strengthen market positioning, lower the cost of capital and reinforce the organisation&#8217;s social licence to operate.</p><p>Are you ready to turn compliance into a competitive advantage?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.fromciso.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading fromCISO! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>