Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
DORA

Digital Operational Resilience for Financial Services

DORA requires financial entities to ensure digital operational resilience through ICT risk management, incident handling, and third-party risk governance. Control provides the physical enforcement layer that demonstrates resilience beyond software controls.

Back to Control
Control by Firevault product icon

DORA

DORA requires financial entities to not merely survive ICT disruptions, but to demonstrate they have the resilience measures in place to continue operating through them.

Ch. II

ICT risk management framework coverage

100%

Third-party ICT path governance

Ch. V

Third-party risk management evidence

Full

Automated regulatory evidence generation

The Resilience Challenge

Financial services face stringent resilience requirements.

ICT Risk Management

DORA Chapter II requires comprehensive ICT risk management frameworks with demonstrable technical controls that go beyond policy documentation.

Third-Party Concentration

Financial entities increasingly depend on third-party ICT providers, creating concentration risks that DORA Chapter V specifically addresses.

Recovery Testing

DORA requires regular resilience testing including threat-led penetration testing. Organisations must demonstrate that recovery capabilities work under realistic conditions.

The Scenario

Scenario: DORA Resilience Assessment

A financial entity undergoes its first DORA resilience assessment. The regulator examines third-party ICT risk management and discovers that 14 vendor connections maintain persistent network access to production payment systems. The entity cannot demonstrate that these connections are actively governed or that access can be revoked in a defined timeframe. The regulator also finds that backup systems share network infrastructure with production, meaning a ransomware attack could compromise both simultaneously. With Control, all vendor connections are physically governed with time-limited access windows. Control-plane baselines are held on infrastructure with no live network path to production. The entity demonstrates continuous evidence of ICT risk management and third-party governance that exceeds DORA requirements.

"The regulator asked us how quickly we could sever a compromised vendor connection. Honestly, it would have taken us days to identify all the paths, update firewall rules, and verify the changes. With physical path governance, the answer is seconds."

DORA mapping

Where DORA articles meet Control modules.

DORA puts ICT resilience at the heart of financial services regulation. Control provides the physical containment and recovery layer DORA assumes is in place.

Reference: Regulation (EU) 2022/2554 (DORA), Articles 5 to 14 (ICT risk management) and Articles 28 to 30 (third-party risk).

SEC 01

ICT risk management framework (Art. 5-8)

  • Art. 6

    ICT risk management framework

    Boundary enforcement is physical and continuously evidenced.

    FV-Firebreak module iconFirebreakFV-Validate module iconValidate
  • Art. 8

    Identification of ICT-supported business functions

    Crown-jewel functions sit behind a named, severed conduit by default.

    FV-Isolate module iconIsolateFV-Lock module iconLock
SEC 02

Protection and prevention (Art. 9)

  • Art. 9(2)

    ICT security measures

    Privileged actions require explicit approval and produce signed evidence.

    FV-Execute module iconExecuteFV-Validate module iconValidate
  • Art. 9(4)

    Network and infrastructure security

    Zone boundaries are physically severed and reachable only via governed conduits.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
SEC 03

Detection and response (Art. 10-11)

  • Art. 11(2)

    Response and recovery

    Recovery copies remain in an offline vault, disconnected from the live network.

    FV-Archive module iconArchiveFV-Transfer module iconTransfer
  • Art. 11(4)

    ICT business continuity policy

    Restoration is an authorised Execute event with quorum approval and recorded intent.

    FV-Execute module iconExecuteFV-Validate module iconValidate
SEC 04

Third-party risk (Art. 28-30)

  • Art. 28

    General principles for ICT third-party risk

    Vendor reach is default-severed; engagements run as time-bound Relay sessions.

    FV-Firebreak module iconFirebreakFV-Relay module iconRelayFV-Lock module iconLock
  • Art. 30

    Contractual provisions on use of ICT services

    Vendor sessions are named, scoped and revocable at the boundary.

    FV-Lock module iconLockFV-Unlink module iconUnlink

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Validate module iconValidateIntegrity check
FV-Isolate module iconIsolateZone boundary
FV-Lock module iconLockNamed access
FV-Execute module iconExecuteApproved action
FV-Archive module iconArchiveDisconnected copy
FV-Transfer module iconTransferControlled move
FV-Relay module iconRelayTime-bound path
FV-Unlink module iconUnlinkRemove trust
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Financial Data Sovereignty

All financial system data and configurations remain within the agreed jurisdiction in secured Firevault Bunkers, supporting data localisation requirements.

Third-Party Access Governance

Every vendor and third-party ICT access session is multi-party authorised, time-limited, and fully logged for regulatory review.

Regulatory Evidence

Automated logging generates continuous evidence for DORA, FCA, PRA, and EBA requirements across all ICT risk management domains.

Resilience Testing Support

Physical isolation capabilities support threat-led penetration testing (TLPT) by providing demonstrable containment boundaries for test scenarios.

Audit Trail

Tamper-proof logs record every ICT system access, third-party connection, and incident response action for regulatory audit.

Recovery Assurance

Verified control-plane baselines demonstrate operational resilience that withstands even total network compromise scenarios.

Demo to Live

Adoption Guide

Step 1

DORA Gap Assessment

Map your current ICT risk management measures against DORA chapter requirements to identify where physical enforcement strengthens compliance.

Step 2

Resilience Architecture Design

Design physical ICT system boundaries and third-party governance models that satisfy DORA requirements across all applicable chapters.

Step 3

Resilience Validation

Deploy Control and conduct threat-led testing to validate physical containment capabilities before your regulatory assessment.

Step 4

Full DORA Deployment

Organisation-wide deployment with continuous regulatory evidence, third-party governance, and verified control-plane baseline assurance.

Step 1

DORA Gap Assessment

Map your current ICT risk management measures against DORA chapter requirements to identify where physical enforcement strengthens compliance.

Step 2

Resilience Architecture Design

Design physical ICT system boundaries and third-party governance models that satisfy DORA requirements across all applicable chapters.

Step 3

Resilience Validation

Deploy Control and conduct threat-led testing to validate physical containment capabilities before your regulatory assessment.

Step 4

Full DORA Deployment

Organisation-wide deployment with continuous regulatory evidence, third-party governance, and verified control-plane baseline assurance.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy