Regulatory compliance · Financial services

DORA Compliance Handbook 2026 by Kai London

DORA is not a security regulation with a finance label on it. It is a demand that a financial entity can name its critical functions, evidence its ICT dependencies, and keep operating when a provider fails. This handbook builds that capability, clause by clause.

Available on Amazon. An independent practitioner guide — not legal advice, and not affiliated with or endorsed by any regulator or supervisory authority.

What is inside

ICT risk management framework

Governance, controls, asset and dependency mapping, and the board approval trail the regulation expects to see.

Incident classification and reporting

Deciding what counts as major, and running initial, intermediate and final reporting against an unforgiving clock.

Digital operational resilience testing

The testing programme, and when threat-led penetration testing applies and what it demands of the organisation.

Third-party risk and contracts

Contractual requirements, exit strategies, concentration risk and oversight of critical ICT service providers.

The register of information

Building and maintaining a register that reconciles to reality rather than to last year's procurement spreadsheet.

Board and management responsibility

What the management body must approve, review and understand — and how that is evidenced under supervision.

Who it is for: CISOs and operational resilience leads at banks, insurers, payment and investment firms; risk, compliance and procurement functions; and ICT providers serving regulated clients.

DORANIS2ISO/IEC 27001NIST CSF 2.0
“

Resilience is not how well you avoid failure. It is what you can still deliver during it.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.