ADVISORI Logo
BlogCase StudiesAbout Us
info@advisori.de+49 69 913 113-01
  1. Home/
  2. Services/
  3. Regulatory Compliance Management/
  4. DORA Digital Operational Resilience Act/
  5. Ezb Aktionsplan KI Cyberrisiken

Subscribe to Newsletter

Stay up to date with the latest trends and developments

By subscribing, you agree to our privacy policy.

A
ADVISORI FTC GmbH

Transformation. Innovation. Security.

Office Address

Kaiserstraße 44

60329 Frankfurt am Main

Germany

View on map

Contact

info@advisori.de+49 69 913 113-01

Mon-Fri: 9:00 AM - 6:00 PM

Products

  • Synthara AI Studio
  • Local AI & Language Models
  • AI Invoice Verification

Company

Services

Social Media

Follow us and stay up to date.

  • /
  • /

© 2026 ADVISORI FTC GmbH. All rights reserved. · 07/2026

Your browser does not support the video tag.
Letter SSM-2026-0301: the clock is running.

ECB Action Plan on AI Cyber Threats

ECB Banking Supervision requires all significant institutions to submit a concrete action plan addressing AI-enabled cyber threats to their Joint Supervisory Team by 31 October 2026. We deliver your action plan in four weeks: a gap assessment against the six ECB focus areas, prioritised measures with timelines and responsibilities, aligned with your existing cyber risk strategy and DORA programmes. Documented to supervisory standards, JST-ready.

  • ✓Gap assessment against all six ECB focus areas in two to three weeks
  • ✓JST-ready action plan: measures, resources, roles, timelines
  • ✓Integrated with open DORA findings, on-site inspections and the 2024 cyber stress test
  • ✓Accelerated vulnerability and patch management designed as an immediate measure
  • ✓Support in the JST dialogue and the ECB horizontal analysis

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

info@advisori.de+49 69 913 113-01

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What the ECB requires and how the action plan is built

Why ADVISORI for the ECB action plan

  • Inspection experience on both sides of the table: our consultants have supported BaFin and Section 44 inspections and know how supervisors read action plans
  • DORA practice, not theory: we have implemented all five pillars in financial institutions, from ICT risk management to the register of information and TLPT
  • The six ECB focus areas are operationalised: ready-made assessment grids, metrics and measure catalogues instead of empty templates
  • ISO 27001 certified: our own information security meets the standards we implement for clients
  • Deadline realism: institutions starting in September submit a plan without a credible baseline. We deliver a result in four weeks that stands up to the JST dialogue
⚠

Deadline: 31 October 2026

The action plan must be submitted to the responsible Joint Supervisory Team by 31 October 2026. The ECB analyses all submitted plans horizontally and feeds the results back to institutions; a weak plan is therefore also a signal to your supervisors. In return, the ECB postpones the IT Risk Questionnaire to February 2027.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We work in a fixed four-week rhythm that builds on your existing cyber risk strategy and your open DORA measures. Every phase delivers an audit-proof interim result.

Our Approach:

Phase 1, gap assessment (weeks 1 to 2): structured baseline against the six ECB focus areas based on evidence, not self-assessment. Reconciliation with open findings from on-site inspections, targeted reviews and the 2024 cyber stress test. Output: maturity scoring per focus area and a prioritised measure list.

Phase 2, prioritisation and resourcing (week 2): evaluation by risk, effort and supervisory visibility. Alignment of budget, staffing and responsibilities with IT, information security and risk control. Output: an agreed roadmap with milestones.

Phase 3, plan drafting (week 3): writing the action plan in the structure Joint Supervisory Teams expect: concrete measures, timelines, roles, resources and a governance chapter with reporting lines and escalation logic.

Phase 4, governance sign-off and submission (week 4): review with the management body, incorporation of feedback, finalisation and timely submission to the JST before 31 October 2026.

Phase 5, implementation and JST dialogue (ongoing): measure tracking with progress evidence, preparation for questions from the ECB horizontal analysis, and support for immediate measures from accelerated patch management to legacy hardening.

Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

LinkedIn Profile

DORA Audit Packages

Our DORA audit packages offer a structured assessment of your ICT risk management – aligned with regulatory requirements according to DORA. Get an overview here:

View DORA Audit Packages

Our Services

We offer you tailored solutions for your digital transformation

Gap assessment against the six ECB focus areas

Structured baseline in two to three weeks: attack surfaces, vulnerability and patch management, detection, governance and supply chain, defence-in-depth, response and recovery.

  • Maturity rating per focus area based on evidence, not self-assessment
  • Reconciliation with open DORA findings and inspection results
  • Prioritisation by risk, effort and supervisory visibility

Action plan drafting for the JST

We write the submission-ready plan: concrete measures, timelines, responsibilities and resource needs, built on your cyber risk strategy.

  • Structure and language Joint Supervisory Teams expect
  • Milestones with measurable outcomes per focus area
  • Governance chapter: reporting lines, escalation, board involvement

Immediate measures: vulnerability and patch management at scale

The ECB names it as the first short-term priority: prioritised scanning, accelerated patch cycles and emergency changes, anchored contractually with ICT service providers.

  • Risk-based prioritisation with EPSS and CISA KEV instead of raw CVSS lists
  • Emergency patch processes, SLAs per risk class
  • Adjustment of contracts and SLAs with ICT third-party providers

Implementation support and JST dialogue

After submission the work begins: we steer implementation, provide progress evidence for your JST and prepare you for questions from the ECB horizontal analysis.

  • Measure tracking with audit-proof documentation
  • Preparation for JST meetings and follow-up requests
  • Escalation-ready status reporting for board and supervisory board

Defence-in-depth & legacy modernisation

Structural hardening in line with ECB expectations: segmentation up to micro-segmentation, zero-trust principles with continuous verification, and replacement or ring-fencing of legacy and end-of-life systems.

  • Zero-trust roadmap: users, devices, APIs and service accounts continuously verified
  • Segmentation concept with prioritised critical zones
  • Legacy inventory with replacement path or compensating controls per system

Response, recovery & information sharing

Tested crisis management, backup and recovery arrangements aligned with DORA, including exercises for high-speed scenarios and legally sound arrangements for sharing cyber threat information.

  • Exercise scenarios: mass zero-day exploitation, ransomware, cloud and supply chain disruption
  • Failover and restoration tests with documented evidence
  • Connection to established financial sector sharing communities (Art. 45 DORA)

Our Competencies in DORA - Digital Operational Resilience Act

Choose the area that fits your requirements

DORA Anwendungsbereich (Scope)

The DORA scope of application covers 20 types of financial entities, from credit institutions and insurers to crypto-asset service providers and ICT third-party providers. We help you precisely determine your entity classification, assess third-party obligations, and build a proportionate compliance strategy.

DORA Audit & Prüfung

DORA requires financial institutions to conduct regular internal ICT audits and prepares them for external supervisory reviews by BaFin and statutory auditors. We guide you through the full DORA audit cycle - from internal audit programs to supervisory examination readiness.

DORA Certification - Professional Certification & Audit Services

Successful DORA compliance verification requires systematic preparation, documented evidence, and, for identified financial entities, TIBER-EU-aligned Threat-Led Penetration Tests (TLPT). We guide you through every phase: from gap assessment and audit readiness to BaFin/ECB-compliant TLPT execution.

DORA Compliance

From gap analysis to audit support. DORA has been mandatory since 17 January 2025, and BaFin is acting: over 600 reported ICT incidents, ongoing §44 special audits, and in Q3 2025 the first DORA fine proceedings due to inadequate ICT third-party documentation. The new IDW audit standard EPS 528 defines how statutory auditors will assess your DORA compliance. We make your organization audit-ready, across all five DORA pillars, based on our ISO 27001-certified methodology and years of BAIT/MaRisk experience in the financial sector.

DORA Compliance Checkliste

Our DORA Compliance Checklist guides financial entities through all five DORA pillars, from initial gap analysis and self-assessment through to BaFin-aligned documentation and continuous monitoring.

DORA Compliance Software

Choosing the right DORA compliance software is critical for audit-proof implementation. We support financial institutions in evaluating, selecting, and integrating GRC platforms that cover all five DORA pillars, from the ICT register to incident reporting and third-party risk management.

DORA Dokumentationsanforderungen

DORA requires financial entities to maintain comprehensive documentation of their digital operational resilience. We support you in building a complete documentation system - from ICT risk management policies to the supervisory information register.

DORA Governance

DORA Article 5 makes the management body personally accountable for the ICT risk management framework, digital resilience strategy, and governance structures. We help financial institutions build DORA-compliant governance, from board-level oversight to the three lines model.

DORA ISO 27001 Mapping

An existing ISO 27001 certification covers approximately 85% of DORA requirements, but the remaining gaps are critical: TLPT resilience testing, ICT third-party contract management, and the Register of Information go beyond ISO 27001. We build precise control mappings, identify your specific DORA gaps, and design an integrated compliance framework that connects both standards efficiently.

DORA Implementation

Full DORA implementation requires more than documentation, it demands operational execution across all five pillars. We guide you from gap analysis through phased delivery to BaFin audit readiness.

Frequently Asked Questions about ECB Action Plan on AI Cyber Threats

Who is addressed by ECB letter SSM-2026-0301?

The CEOs of all significant institutions under direct ECB supervision in the SSM. Less significant institutions should prepare as well: national supervisors such as BaFin typically adopt ECB expectations with a delay, and the underlying DORA obligations apply to all financial entities anyway.

What must the action plan contain by 31 October 2026?

Concrete measures to strengthen the relevant controls, allocated resources, clear roles and responsibilities, and implementation timelines. It must build on the existing cyber risk strategy and combine short-term priorities (attack surfaces, vulnerability and patch management, detection, third parties) with structural measures (defence-in-depth, legacy replacement, response and recovery).

How does the ECB action plan relate to DORA?

The ECB is explicit: no new rules, DORA remains the binding framework. AI amplifies the speed and scale of known risks. Institutions with solid ICT risk management, a clean register of information and tested resilience arrangements can develop the plan largely from existing work. Gaps, however, now come with a hard deadline.

What happens after submission to the JST?

The JST discusses the plan with the institution and monitors progress. In addition, the ECB runs a horizontal analysis of all submitted plans, identifies trends and weaknesses and feeds the conclusions back to institutions. Depending on the results, workshops and further supervisory activities may follow.

What relief does the ECB grant in return?

The annual IT Risk Questionnaire is postponed from September

2026 to February 2027. Adjustments to other supervisory activities, such as on-site inspections or deep dives, are considered case by case in the dialogue between JST and institution.

How fast can ADVISORI deliver a submission-ready action plan?

Typically four weeks: two to three weeks of gap assessment against the six ECB focus areas including reconciliation with open DORA findings, followed by plan drafting in a JST-ready structure. Institutions starting in September risk submitting a plan without a credible baseline. Supervisors notice the difference.

What does the ECB action plan engagement cost?

The effort depends on institution size and maturity. The four-week core package (gap assessment against the six focus areas plus a submission-ready action plan) can be scoped as a fixed-price project; subsequent implementation support is billed by effort or as a monthly package. Institutions with a current DORA gap assessment start cheaper because phase

1 can be shortened. We scope transparently and state the price before the project starts.

Our DORA programme is not finished yet. Can we still submit the action plan on time?

Yes, and that is the normal case. The ECB does not expect a completed transformation by October but a credible plan: a solid baseline, prioritised measures, resources and timelines. Open DORA findings explicitly belong in the plan, with priority. It only becomes critical for institutions that can present neither a baseline nor a plan. That is exactly the gap our four-week approach closes.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance