DORA Compliance · Financial Sector

Digital operational resilience — implemented in technology

DORA has been binding since 17 January 2025. The regulation demands verifiable ICT security from the financial sector across five pillars. KAEMI implements the technical requirements — as a managed service, built on Cloudflare One and Illumio.

17 Jan 2025 binding across the EU
5 pillars covered technically
from 4 h initial report for major incidents

What DORA demands — and who it applies to

The Digital Operational Resilience Act (Regulation EU 2022/2554) has applied directly in every EU member state since 17 January 2025. It obliges financial entities to prove their digital resilience against ICT disruptions — and for the first time also pulls their ICT third-party providers into responsibility.

In scope are banks, insurers, investment firms, payment and e-money institutions, crypto service providers, and the IT and cloud vendors that supply them. The core of the regulation is five pillars. Compliance here does not mean paper — it means verifiable technology in day-to-day operations. That is exactly where we start.

The five pillars

From regulation to architecture

01 Articles 5–16

ICT risk management

A documented framework of governance, protection and prevention. You must know which systems are business-critical and how they are protected.

KAEMI: We make the actual data flows visible, enforce Zero Trust access and contain critical workloads through microsegmentation.

02 Articles 17–23

ICT incident handling & reporting

Incidents must be detected, classified and reported to the supervisor on time — with initial, intermediate and final reports.

KAEMI: Our continuous monitoring detects anomalies, classifies them and delivers the evidence for the reporting chain within the deadlines.

03 Articles 24–27

Digital operational resilience testing

Regular resilience testing, for certain institutions up to threat-led penetration testing (TLPT).

KAEMI: We validate the segmentation, check reachability and uncover paths an attack could spread over — before someone else does.

04 Articles 28–44

ICT third-party risk management

Outsourcing to ICT providers requires a register, clear contractual content and an eye on concentration risks.

KAEMI: As a managed provider we deliver DORA-compliant contract modules, transparency about our service and the entries for your information register.

05 Article 45

Information sharing

Voluntary exchange of threat intelligence within trusted circles strengthens everyone’s defence.

KAEMI: Through the Cloudflare One platform, threat intelligence feeds into your policies in real time — your protection benefits from the view of the global network.

Reporting deadlines for major incidents

The clock starts at the first sign

T + 0 Detection The incident is noticed and assessed.
from T + 4 h Initial report Major incidents reported after classification.
T + 72 h Intermediate report Updated status to the competent supervisor.
T + 1 month Final report Root-cause analysis and measures taken.

Without continuous monitoring, the starting point of that clock stays unclear. Our managed service ensures detection, classification and evidence are in place when the deadlines are running.

How KAEMI takes on the implementation

At the centre is Cloudflare One — the SASE/SSE platform on which we implement the required controls: Zero Trust access instead of VPN, Secure Web Gateway, WAF, CASB and data loss prevention, plus continuous detection. For containment in the data centre we add microsegmentation with Illumio. What matters is how it comes together: not as a toolbox, but as one continuous managed service.

As a Cloudflare Authorized Service Delivery Partner we have a direct line into Cloudflare engineering; Illumio has named us EMEA Partner of the Year. Management and support work from Germany, contracts follow German law, and we supply all entries for your ICT third-party register — we deliberately do not promise an ISO 27001 certification, but verifiable technology.

Cloudflare Authorized Service Delivery Partner Illumio EMEA Partner of the Year Operations & contracts from Germany

As a managed service

How we deliver — managed service on Cloudflare One

Analysis

Establish visibility

We map applications, data flows and access — the basis for every policy and every piece of evidence.

Rollout

Set up Cloudflare One

Zero Trust Access, Secure Web Gateway, WAF, CASB and DLP on the Cloudflare platform, complemented by microsegmentation with Illumio — phased, with validation at every step.

Operations

Managed service

We monitor, configure and enforce policies — with reporting instead of a black box.

Support

Direct line to Cloudflare

As an Authorized Service Delivery Partner we escalate straight into Cloudflare engineering when needed.

Incident

Incident response

If an incident occurs, we react fast and deliver the evidence for the reporting obligation.

Assess your DORA readiness together

In a no-obligation conversation we map your current state along the five pillars and show which technical gaps can be closed with what effort.

Book a conversation