DORA readiness | Firemind
DORA readiness

Five pillars, article by article.With the evidence and the gaps for each.

A technical readiness assessment for financial entities, read-only, mapped to the articles your competent authority will ask about.

Articles 5 to 45
RAG rating per control
Read-only, nothing changed
Maturity score per pillar
Recommendations by horizon
Run on our own Azure estate
The problem

DORA asks financial entities to prove operational resilience. Most of the technical evidence is in cloud configuration.

ICT risk management, incident reporting, resilience testing, third-party risk and intelligence sharing. Gathering the evidence for the first four by hand is slow and repetitive.

The IT Operations Engine gathers that evidence read-only, maps it to the relevant articles, scores each control, and tells you where the gaps are and in what order to close them.

What a readiness assessment has to give you

  • Evidence mapped to specific articles, not to a general sense of the regulation
  • A status and a RAG rating per control, with the gap named against the article
  • A maturity score per pillar, so the weakest is visible rather than averaged away
  • Recommendations grouped by horizon, so the immediate work is separable from the programme
  • An honest line between technical state and the documentary artefacts that remain yours
How we approach it

Enumerate the estate, then gather evidence pillar by pillar.

The engine enumerates every subscription or account in scope and inventories what is deployed. It then gathers evidence pillar by pillar: asset inventory and classification, identity and privileged access, encryption, network segmentation, backup and recovery, and governance under ICT risk management (Articles 5 to 16); detection, logging, classification and regulatory reporting readiness under incident management (Articles 17 to 23); vulnerability assessment, testing and failover evidence under resilience testing (Articles 24 to 27); provider register, contractual safeguards and concentration risk under third-party risk (Articles 28 to 44); and threat-intelligence arrangements under information sharing (Article 45).

Each control returns a status, a RAG rating, the evidence found and the gaps against the article. Pillars are scored, an overall maturity score is produced, and recommendations are grouped by horizon: immediate, short, medium and long term. Nothing is changed.

ICT risk management
Incident management
Resilience testing
Third-party risk
Information sharing

What the assessment produces

    • Evidence mapped to articles - Asset inventory and classification, identity and privileged access, encryption, network segmentation, backup and recovery, detection and logging, vulnerability assessment and failover evidence, provider register and concentration risk, and threat-intelligence arrangements, each mapped to the articles that ask for them.
    • A status, a rating and a gap - Each control returns a status, a RAG rating, the evidence found and the gaps against the article. Pillars are scored and an overall maturity score is produced, so the weakest pillar is visible rather than averaged away.
    • An order of work - Recommendations grouped by horizon — immediate, short, medium and long term — so the work that cannot wait is separable from the programme that follows it. Nothing in the estate is changed to produce any of it.

One regulated entity, read-only.

We have run this on our own Azure estate. On yours, one entity first, then a cadence.

Scope a pilot →
How it starts

One entity, read-only, and an hour with the people who own ICT risk.

We have run this assessment on our own Azure estate. On yours, we would run it read-only on one entity first, then agree what a repeatable cadence looks like.

  • One regulated entity

    Read-only access to the subscriptions or accounts of a single entity, and an hour with the people who own ICT risk.

    • Scoped to one entity to begin
    • An hour with your ICT risk owners
    • Nothing in the estate is changed
  • Evidence, article by article

    The engine enumerates what is deployed, then gathers evidence across the five pillars and maps each control to the articles that ask for it.

    • Articles 5 to 45 covered across the five pillars
    • Status, RAG rating, evidence and gap per control
    • Maturity score per pillar and overall
  • Then a cadence

    Recommendations arrive grouped by horizon. Once the first assessment has landed, we agree what repeating it looks like.

    • Immediate, short, medium and long term
    • The documentary artefacts named per control
    • Repeatable rather than a one-off exercise
What stays with you

The organisational evidence.

Policies, the register of information, contractual clauses, testing programmes and sharing arrangements. The engine shows the technical state and names the documentary artefact each control still needs.

You gain:

  • This is not a DORA compliance certification. It is a technical readiness assessment mapped to the articles.
  • Your compliance function and your competent authority own the determination.
  • We have run this assessment on our own Azure estate before proposing it for yours.

FAQ

Questions.

No. It is a technical readiness assessment mapped to the articles. Your compliance function and your competent authority own the determination.

Start with one regulated entity, read-only.

Read-only access to the subscriptions or accounts of one entity, and an hour with the people who own ICT risk.

Your benefits:

  • Article-mapped - evidence tied to the articles, not to a general sense of the regulation.
  • RAG per control - with the gap named against the article.
  • By horizon - immediate work separable from the programme.
  • Run on our own - Azure estate before we proposed it for yours.

What happens next?

Talk.

An hour with the people who own ICT risk in one regulated entity.

Assess.

Read-only across the five pillars, article by article.

Repeat.

Recommendations by horizon, then an agreed cadence.

No obligation. Just a focused discussion about your DORA position.

We'll only use your details to respond to your enquiry. No newsletters unless you ask for them.