ECB Banking Supervision requires all significant institutions to submit a concrete action plan addressing AI-enabled cyber threats to their Joint Supervisory Team by 31 October 2026. We deliver your action plan in four weeks: a gap assessment against the six ECB focus areas, prioritised measures with timelines and responsibilities, aligned with your existing cyber risk strategy and DORA programmes. Documented to supervisory standards, JST-ready.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










The action plan must be submitted to the responsible Joint Supervisory Team by 31 October 2026. The ECB analyses all submitted plans horizontally and feeds the results back to institutions; a weak plan is therefore also a signal to your supervisors. In return, the ECB postpones the IT Risk Questionnaire to February 2027.
Years of Experience
Employees
Projects
We work in a fixed four-week rhythm that builds on your existing cyber risk strategy and your open DORA measures. Every phase delivers an audit-proof interim result.
Phase 1, gap assessment (weeks 1 to 2): structured baseline against the six ECB focus areas based on evidence, not self-assessment. Reconciliation with open findings from on-site inspections, targeted reviews and the 2024 cyber stress test. Output: maturity scoring per focus area and a prioritised measure list.
Phase 2, prioritisation and resourcing (week 2): evaluation by risk, effort and supervisory visibility. Alignment of budget, staffing and responsibilities with IT, information security and risk control. Output: an agreed roadmap with milestones.
Phase 3, plan drafting (week 3): writing the action plan in the structure Joint Supervisory Teams expect: concrete measures, timelines, roles, resources and a governance chapter with reporting lines and escalation logic.
Phase 4, governance sign-off and submission (week 4): review with the management body, incorporation of feedback, finalisation and timely submission to the JST before 31 October 2026.
Phase 5, implementation and JST dialogue (ongoing): measure tracking with progress evidence, preparation for questions from the ECB horizontal analysis, and support for immediate measures from accelerated patch management to legacy hardening.

Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our DORA audit packages offer a structured assessment of your ICT risk management – aligned with regulatory requirements according to DORA. Get an overview here:
View DORA Audit PackagesWe offer you tailored solutions for your digital transformation
Structured baseline in two to three weeks: attack surfaces, vulnerability and patch management, detection, governance and supply chain, defence-in-depth, response and recovery.
We write the submission-ready plan: concrete measures, timelines, responsibilities and resource needs, built on your cyber risk strategy.
The ECB names it as the first short-term priority: prioritised scanning, accelerated patch cycles and emergency changes, anchored contractually with ICT service providers.
After submission the work begins: we steer implementation, provide progress evidence for your JST and prepare you for questions from the ECB horizontal analysis.
Structural hardening in line with ECB expectations: segmentation up to micro-segmentation, zero-trust principles with continuous verification, and replacement or ring-fencing of legacy and end-of-life systems.
Tested crisis management, backup and recovery arrangements aligned with DORA, including exercises for high-speed scenarios and legally sound arrangements for sharing cyber threat information.
Choose the area that fits your requirements
The DORA scope of application covers 20 types of financial entities, from credit institutions and insurers to crypto-asset service providers and ICT third-party providers. We help you precisely determine your entity classification, assess third-party obligations, and build a proportionate compliance strategy.
DORA requires financial institutions to conduct regular internal ICT audits and prepares them for external supervisory reviews by BaFin and statutory auditors. We guide you through the full DORA audit cycle - from internal audit programs to supervisory examination readiness.
Successful DORA compliance verification requires systematic preparation, documented evidence, and, for identified financial entities, TIBER-EU-aligned Threat-Led Penetration Tests (TLPT). We guide you through every phase: from gap assessment and audit readiness to BaFin/ECB-compliant TLPT execution.
From gap analysis to audit support. DORA has been mandatory since 17 January 2025, and BaFin is acting: over 600 reported ICT incidents, ongoing §44 special audits, and in Q3 2025 the first DORA fine proceedings due to inadequate ICT third-party documentation. The new IDW audit standard EPS 528 defines how statutory auditors will assess your DORA compliance. We make your organization audit-ready, across all five DORA pillars, based on our ISO 27001-certified methodology and years of BAIT/MaRisk experience in the financial sector.
Our DORA Compliance Checklist guides financial entities through all five DORA pillars, from initial gap analysis and self-assessment through to BaFin-aligned documentation and continuous monitoring.
Choosing the right DORA compliance software is critical for audit-proof implementation. We support financial institutions in evaluating, selecting, and integrating GRC platforms that cover all five DORA pillars, from the ICT register to incident reporting and third-party risk management.
DORA requires financial entities to maintain comprehensive documentation of their digital operational resilience. We support you in building a complete documentation system - from ICT risk management policies to the supervisory information register.
DORA Article 5 makes the management body personally accountable for the ICT risk management framework, digital resilience strategy, and governance structures. We help financial institutions build DORA-compliant governance, from board-level oversight to the three lines model.
An existing ISO 27001 certification covers approximately 85% of DORA requirements, but the remaining gaps are critical: TLPT resilience testing, ICT third-party contract management, and the Register of Information go beyond ISO 27001. We build precise control mappings, identify your specific DORA gaps, and design an integrated compliance framework that connects both standards efficiently.
Full DORA implementation requires more than documentation, it demands operational execution across all five pillars. We guide you from gap analysis through phased delivery to BaFin audit readiness.
The CEOs of all significant institutions under direct ECB supervision in the SSM. Less significant institutions should prepare as well: national supervisors such as BaFin typically adopt ECB expectations with a delay, and the underlying DORA obligations apply to all financial entities anyway.
Concrete measures to strengthen the relevant controls, allocated resources, clear roles and responsibilities, and implementation timelines. It must build on the existing cyber risk strategy and combine short-term priorities (attack surfaces, vulnerability and patch management, detection, third parties) with structural measures (defence-in-depth, legacy replacement, response and recovery).
The ECB is explicit: no new rules, DORA remains the binding framework. AI amplifies the speed and scale of known risks. Institutions with solid ICT risk management, a clean register of information and tested resilience arrangements can develop the plan largely from existing work. Gaps, however, now come with a hard deadline.
The JST discusses the plan with the institution and monitors progress. In addition, the ECB runs a horizontal analysis of all submitted plans, identifies trends and weaknesses and feeds the conclusions back to institutions. Depending on the results, workshops and further supervisory activities may follow.
The annual IT Risk Questionnaire is postponed from September
2026 to February 2027. Adjustments to other supervisory activities, such as on-site inspections or deep dives, are considered case by case in the dialogue between JST and institution.
Typically four weeks: two to three weeks of gap assessment against the six ECB focus areas including reconciliation with open DORA findings, followed by plan drafting in a JST-ready structure. Institutions starting in September risk submitting a plan without a credible baseline. Supervisors notice the difference.
The effort depends on institution size and maturity. The four-week core package (gap assessment against the six focus areas plus a submission-ready action plan) can be scoped as a fixed-price project; subsequent implementation support is billed by effort or as a monthly package. Institutions with a current DORA gap assessment start cheaper because phase
1 can be shortened. We scope transparently and state the price before the project starts.
Yes, and that is the normal case. The ECB does not expect a completed transformation by October but a credible plan: a solid baseline, prioritised measures, resources and timelines. Open DORA findings explicitly belong in the plan, with priority. It only becomes critical for institutions that can present neither a baseline nor a plan. That is exactly the gap our four-week approach closes.
Discover how we support companies in their digital transformation
Steel trading company from Germany
Digital Transformation in Steel Trading
Industrial group from Germany
Smart Manufacturing Solutions for Maximum Value Creation
Automation specialist from Germany
Intelligent Networking for Future-Proof Production Systems
Technology group from Germany
AI Process Optimization for Improved Production Efficiency
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance