CYBER COLLECTIVE LAB · Edition 5
Compliance: NIS2, DORA and CRA - round table and field feedback
DORA and NIS2 as the round table framed them: where the two regimes overlap for a financial group, and what field teams had already reconciled.
Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm. Grimaldi Forum, a ten-minute pitch.
Book the workshopOur Assises workshopBY INDUSTRY · BANKING & INSURANCE
Your supervisor reads the register of information against the incident reports and the list of critical functions, and expects them to agree. Mindlapse keeps the three on one living data set, with the management body’s accountability evidenced from it.
DORA · NIS2 · Register of information · Concentration risk · ACPR and AMF
ICT third-party providers · Trust Grade
Initiatives
Register of information refresh
In progress
Concentration analysis (Art. 29)
Started
TLPT scoping from the value chain
Validated
Frameworks · critical or important function
Critical or important function
Payment processing
The register of information is this graph, kept alive, not a spreadsheet exported in spring.
THE SITUATION
Exported once, four subcontracting levels deep, and inconsistent with the list of critical functions by summer.
Three critical functions on one cloud provider, and nobody added it up for Article 29.
ISO controls in security, the operational risk register in risk, the DORA gap analysis in compliance; the board pack reconciles them by hand.
The DORA clock on a major incident starts before the incident cell has met.
WHO IS IN SCOPE
In France the financial entities DORA names are supervised by the ACPR (banks, payment institutions, insurers and mutuals) and the AMF (asset managers and market infrastructures), which collect the register of information. For those entities DORA takes precedence over the NIS2 measures and incident duties, while group entities outside DORA stay under NIS2. ICT third-party providers to financial entities carry the contractual flow-down of Articles 28 to 30. The DORA page lists who the regulation applies to, article by article.
Written for
WHAT MINDLAPSE CHANGES
Surface: Supplier Hub
Contracts, criticality and dependencies held as living data on the providers themselves, refreshed by expiring attestations and rating moves rather than by a campaign.
Learn more
Surface: Control Atlas
DORA and its technical standards, NIS2 and ISO/IEC 27001 relate to one control set; each control carries dated, reviewed evidence that answers all three at once.
Learn more
Surface: Cyber Incidents
An incident is classified against the criteria with the functions, providers and controls already attached; the cascade prepares the file, your team files it.
Learn more
Surface: Value Chain Map
Each function mapped to the activities, systems and providers that run it, so a provider under several functions is flagged before the supervisor asks.
Learn more
Surface: Mindlapse Trust Grade
SecurityScorecard, Bitsight and Scovery feed the Trust Grade beside your own assessment and the business impact, with the weights in the open.
Learn more
THE OBLIGATIONS MAP
EU rows first, the French specific tagged; every "verifies" cell is a product claim at ledger level, and no cell carries a date.
| Regulation | Obligation | What Mindlapse verifies | Surface |
|---|---|---|---|
| DORA | Art. 5 · the management body owns ICT risk | Resilience state, concentration and open decisions in board-grade views, each figure opening on its evidence | Cyber Cockpit |
| DORA | Art. 6 · an ICT risk framework reviewed yearly | DORA and its RTS mapped to your control set; each control carries dated, reviewed evidence | Control Atlas |
| DORA | Art. 28(3) · the register of information | The ICT third-party register as living data (contracts, criticality, dependencies), exportable in supervisory formats | Supplier Hub |
| DORA | Art. 29 · ICT concentration risk | Concentration read on the activities each provider operates, flagged on the chain | Concentration risk |
| DORA | Art. 19 · major ICT incident reporting | Classification against the criteria, then the cascade: assessment, draft, notification file, log | Cyber Incidents |
| Arrêté contrôle interne FR | Essential outsourced services (PSEE) under ACPR supervision | The outsourcer assessed in the context of the service it runs; remediation as a joint action plan both sides accept, reject or counter-propose | Supplier Hub |
A QUARTER, THEN THE DAY THE SUPERVISOR ASKS
Four moments of an ordinary quarter in a financial entity, and what the platform had already done; then the day the ACPR asks, in three steps.
A normal quarter
WEEK 1
The register needs refreshing.
The refresh fired on an expiring attestation, not on a campaign; the providers it concerned were listed with what changed.
Surface: Supplier Hub
alert: WEEK 5
Concentration review.
One provider under four critical functions had been flagged on the chain, with the functions named.
Surface: Concentration risk
WEEK 9
The TLPT findings arrive.
Entered as risks and controls with owners, on the functions the test had been scoped from.
Surface: TLPT engagements
verified: WEEK 12
The pack for the management body.
Resilience state, concentration and the open decisions, exported from the live register.
Surface: Cyber Cockpit
The day the supervisor asks
THE REQUEST
The ACPR asks for the register, the list of critical functions and last quarter’s incident reports, consistent with each other.
All three were read from one data set, so they already agreed.
Surface: Supplier Hub
WHAT OPENS
The register as living data, the functions on the chain, the incident records.
Each incident record carried its cascade log: classification, assessment, draft, notification file.
Surface: Cyber Incidents
WHAT IS EXPORTED
The register, the reports, the evidence.
The register in supervisory formats, the supervisory reports produced from the module, the controls’ evidence from Audit mode.
Surface: Reports
Illustrative quarter: the moments are fictional, the surfaces are the product’s.
FROM THE FIELD
CYBER COLLECTIVE LAB · Edition 5
DORA and NIS2 as the round table framed them: where the two regimes overlap for a financial group, and what field teams had already reconciled.
Measured with our design-partner CISOs, figures under continuous validation.
UNDER THE HOOD
FAQ
Not in the ITS template today. The register is living data, contracts, criticality and dependencies on the providers themselves, exported when you need it; the supervisory template is worked through on your scope during the session.
Qualified testers test. Mindlapse manages the programme around them: scoping from your value chain, findings entered as risks and controls with owners, remediation tracked to verified closure, and the evidence trail the supervisor expects.
Yes. Access is scoped by organization, each entity runs its own register and its own reviews, and the group reads a sub-consolidated view without touching the entity’s records.
For the financial entities DORA names, yes: its ICT risk and incident-reporting requirements take precedence over the NIS2 measures and notification duties. Group entities outside DORA stay under NIS2, so the same control set has to answer both; the DORA and NIS2 pages carry the detail.
SecurityScorecard, Bitsight and Scovery, beside your own assessment of the provider and the business impact of the service it runs. The weights are in the open and the grade is recomputed overnight.
Read it next
Cyber scored like the other lines: method, appetite, owners, reviews.
Learn more
Map every framework to one control set; prove it any day; run the incident cascade on one record.
Learn more
The cyber slot as a pack of decisions: accept, fund, defer or transfer, each one click from its evidence.
Learn more
Also by outcome
RESILIENCE, EVIDENCED
A live session on your ICT third parties: register, concentration, TLPT programme, the board view.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy