Regulatory-compliant information exchange for enhanced security

DORA Information Sharing: Collective Cyber Defence

DORA Article 45 enables and promotes the voluntary exchange of cyber threat intelligence between financial institutions.

  • 01Regulatory compliance with DORA information sharing requirements
  • 02Early detection of cyber threats through collective intelligence
  • 03Secure exchange of confidential threat information
  • 04Strengthening cross-organizational cyber resilience
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA Information Sharing under Article 45

The Digital Operational Resilience Act (DORA) strengthens collective protection of the financial sector through Article 45, enabling coordinated sharing of cyber threat information and vulnerability data. We help you build and operationalise a legally sound information sharing programme.

We offer you a comprehensive range of services for implementing a DORA-compliant information sharing program, tailored to your specific requirements and creating sustainable value for your organization.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Information Sharing Strategy & Framework

We develop a tailored information sharing strategy and framework that considers your specific requirements and ensures DORA compliance.

  • Development of vision and strategic objectives
  • Definition of scope, depth, and boundaries of information exchange
  • Identification of relevant stakeholders and partners
  • Development of implementation plan and roadmap
02

Information Sharing Governance & Compliance

We support you in developing and implementing governance structures and compliance mechanisms for legally compliant information sharing.

  • Development of information sharing policies and procedures
  • Establishment of classification and release mechanisms
  • Integration into existing governance structures
  • Development of mechanisms for regulatory reporting

5 phases

Our Approach

We develop a tailored information sharing program with you that ensures DORA compliance while creating genuine strategic value for your organization.

  1. Analysis of status quo and regulatory requirements

  2. Development of an information sharing strategy and roadmap

  3. Design of governance, processes, and policies

  4. Implementation of technical solutions and integration

  5. Cultural transformation and change management

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Information Sharing is a central element of DORA regulation and a strategic success factor for collective cyber resilience in the financial sector. Our clients benefit from our comprehensive approach that equally considers technical, organizational, and legal aspects while fostering a sustainable culture of information exchange.

Our Strengths

  • 01Comprehensive expertise in DORA regulation and regulatory information sharing
  • 02Comprehensive implementation approach considering legal, technical, and cultural aspects
  • 03Extensive experience in implementing threat intelligence and information sharing solutions
  • 04Strong network with relevant information sharing communities in the financial sector

Expert Tip

Information Sharing under DORA is more than a technical solution. It requires a strategic approach that equally considers technical, organizational, and legal aspects while fostering a sustainable culture of information exchange.

5 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Information Sharing

What does Article 45 DORA provide for cyber threat information sharing?

Article 45 enables and encourages voluntary sharing of cyber threat information among financial entities, such as attack indicators, tactics, and vulnerabilities. The goal is a collective improvement of defensive capability across the financial sector, since individual companies often only see a partial picture of the actual threat landscape.

Is participation in information sharing mandatory or voluntary?

Participation itself is voluntary; DORA doesn't mandate a specific arrangement or platform. In practice, though, active participation is increasingly viewed as a sign of proactive ICT risk management, since it shows a company contributing to sector-wide resilience beyond the bare minimum of compliance.

What kind of information is typically shared?

Shared information mainly covers technical indicators such as suspicious IP addresses or attack patterns, descriptions of new attack tactics, and warnings about actively exploited vulnerabilities. Sensitive internal details, such as the specific impact of an entity's own incident, are usually shared in anonymized or aggregated form.

What channels or platforms does this sharing happen through in practice?

Common channels include sector-specific information-sharing communities and CERT structures that provide structured formats for exchange, as well as bilateral arrangements between individual companies. The specific choice often depends on which communities are already established in the relevant national financial sector.

What confidentiality and competition considerations apply to information sharing?

Before participating, it's worth clarifying which information can be shared without antitrust concerns; pure threat indicators are generally unproblematic, while company-specific detail should be handled more carefully. Contractual confidentiality agreements within the relevant sharing community typically govern how shared information may be reused.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance