Penetration testing under a regulatory deadline
Scope, pricing and schedule for application and infrastructure testing prepared within 48 hours of first contact. Report in board-level language.
Case study · Audit
More than 460 hours of audit work covering all five pillars of the DORA Regulation — from the plan, through interviews and evidence review, to the final report for the management board and the regulator.
An institution of national importance operating in critical infrastructure and providing services to the financial sector. As a service provider to entities subject to DORA, it had to demonstrate the compliance of its own operational resilience — ahead of an external audit and questions from its financial-sector clients.
The challenge was scale: dozens of ICT systems, many third-party providers, scattered documentation and a confidentiality regime that restricted access to the environment. The client needed a partner who would run the audit from plan to report with a single team, without handing knowledge off between firms.
The management board received a single document answering the question "where do we stand and what should we do first," and the technical teams received a concrete task list. The client can now answer any financial client's questionnaire with evidence rather than assurances. The register of ICT information and contractual clauses were standardized to the level required by Art. 28–30.
One team from plan to final report. We didn't have to explain our organization three times to three different firms.
Chief Security Officer, critical infrastructure institution — reference available after signing an NDA
After the audit, the client continued working with us in IT Security (resilience testing program) and Cloud Computing (maintaining the environment in line with DORA requirements). This is the typical path: the audit reveals the gaps, and the other two areas close and maintain them.
Other projects
Scope, pricing and schedule for application and infrastructure testing prepared within 48 hours of first contact. Report in board-level language.
A complete set of answers and evidence for the ICT vendor questionnaire: policies, procedures and records required under banking outsourcing rules.
Maintenance of the production ERP, B2B platform, KSeF (Polish National e-Invoicing System) e-invoicing, workstations, network and backup. One SLA contract instead of five vendors.