DORA · Financial services

Four Hours to Tell the Regulator by Kai London

DORA's reporting regime asks a financial entity to classify an incident and notify quickly, then sustain a staged account as understanding develops. The difficulty is doing that while the incident is still live and the facts are moving. This book turns the requirement into an operable internal process.

Coming soonAll books

What the book covers

Classification in practice

Applying the major-incident criteria consistently, including borderline cases and reclassification as facts emerge.

The staged reports

Initial, intermediate and final reporting as one continuous process with clear internal ownership.

Detection to decision

The internal path that gets an event in front of the right decision-maker fast enough to matter.

Third-party incidents

Reporting when the failure sits with an ICT provider, and the contractual information rights that make it possible.

Overlapping regimes

Coordinating DORA reporting with data protection, sectoral supervisory and market disclosure duties.

Testing the process

Exercising the reporting chain, including out of hours, and evidencing that it works.

General guidance, not legal advice; take qualified advice on the obligations applying to your entity. Independent, with no endorsement by or affiliation with any regulator or supervisory authority.

DORANIS2ISO 27035Operational resilience

Who it is for

Banks, insurers, investment firms and other financial entities in scope of DORA — their CISOs, operational resilience leads, incident managers, compliance officers and legal teams.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.