DORA: operational resilience, from the engineering side
By Cédric Barme · Founder of NSY
The European DORA regulation (Digital Operational Resilience Act), applicable since January 2025, requires financial entities to demonstrate their digital resilience — not merely declare it. Legal documentation abounds; what is usually missing is the engineering side. That is the part NSY takes on.
What DORA concretely demands from technical teams
- Mapping ICT risks — inventory of assets, flows and dependencies (internal and providers), criticality of each function: impossible to do seriously without understanding the real architecture, not the slideware version.
- Testing resilience — not paper plans: executed failure scenarios (loss of a site, of a messaging broker, of a cloud provider), with recovery times measured against commitments.
- Controlling ICT providers — reversibility, data portability, testable exit strategies: requirements that translate into architecture choices (see private and hybrid cloud), not just contract clauses.
- Reporting major incidents — which presupposes detecting them, qualifying them and reconstructing their timeline: observability is no longer a comfort, it is an obligation.
The NSY approach
NSY starts where the legal work stops: translating requirements into prioritised engineering work. A technical diagnosis first — a real map of the system, gaps against the requirements, costed remediations. Then execution: hardening the identified weak points (often messaging, ageing application platforms — see Java EE migration — and observability), resilience test scenarios, and documentation that stands up to an inspection.
Why an independent outside eye
The costliest DORA gaps are the ones you no longer see from inside: the "temporary" dependency that became structural, the recovery plan never replayed, the de-facto irreplaceable provider. An independent consultant, working in ACPR/AMF environments since 2018 and with no ties to your suppliers, has no incentive to minimise a gap — nor to invent one. The FAQ details the engagement framework.
Where to start
A short diagnosis targets the critical functions first: a few weeks to obtain the technical risk map and a remediation plan prioritised by impact. Describe your scope through the form — reply within 48 business hours, with an honest read of what is urgent and what can wait.
Describe your context — honest read within 48 business hours
Technical diagnosis, prioritised remediation plan, delivery if you wish.