Updated 2026-07-22
What are the five DORA pillars teams organise around?
DORA conversations often cluster into five themes. Our questionnaire uses the same framing so scores map to topics boards already recognise. Pillar names here are indicative planning language — not a legal checklist and not legal advice.
What is ICT risk management under DORA framing?
ICT risk management asks who owns ICT risk at management-body level, whether a living risk register and policies exist, and whether controls are reviewed in practice — not only written once.
Gaps here usually show up as unclear accountability, stale documentation, or risk metrics that never reach a standing agenda.
What does ICT incident management cover?
Incident management covers detecting, classifying, escalating, communicating, and learning from ICT incidents with enough structure to meet major-incident expectations when they apply.
Common weak spots: severity criteria that live in someone’s head, no consolidated incident log, and post-incident actions that never get tracked.
What is digital operational resilience testing?
Resilience testing proves that resilience claims survive contact with reality — from scenario exercises to more advanced testing where required for your entity type.
Teams often under-invest in scheduling, scoping, and feeding test findings back into remediation ownership.
Why does ICT third-party risk matter?
Cloud, SaaS, and subcontracting chains concentrate risk. Programs typically need a provider inventory, criticality classification, and operational levers for incident notification, audit support, and exit.
Concentration risk and missing contractual rights are frequent findings even in otherwise mature organisations.
What is information sharing in this context?
Information sharing improves resilience when trusted threat and vulnerability information can flow within the organisation and, where appropriate, across the sector.
Even a lightweight participation in relevant channels beats relying solely on your own incident history.