Cybersecurity
Cybersecurity and operational resilience are integral to the regulation of modern payment services. DORA establishes a demanding EU-wide framework for ICT risk, incident management, resilience testing and the oversight of critical technology providers.
We help clients translate these requirements into workable governance, contracts and operational processes, while navigating their interaction with payments regulation and fraud prevention.
What we do
- DORA advice on ICT risk management, governance and internal control frameworks.
- Incident classification, reporting and coordination across regulatory regimes.
- Digital operational resilience testing, including threat-led penetration testing requirements.
- ICT third-party risk, contractual arrangements and oversight of technology providers.
- Advice on cybersecurity and fraud-related regulatory requirements across the payments lifecycle.
- Support in supervisory dialogue on cybersecurity, outsourcing and operational resilience.
Key instruments
DORA · DORA delegated and implementing acts · NIS2 · PSD2/PSD3 and PSR security requirements · SCA regulatory technical standards
Related insights
SCA on the acceptance side under PSD3/PSR: analysis of the final texts
Agentic Commerce and SCA Compliance
Agentic Commerce and SCA Compliance