Four Hours to Tell the Regulator by Kai London
DORA's reporting regime asks a financial entity to classify an incident and notify quickly, then sustain a staged account as understanding develops. The difficulty is doing that while the incident is still live and the facts are moving. This book turns the requirement into an operable internal process.
What the book covers
Classification in practice
Applying the major-incident criteria consistently, including borderline cases and reclassification as facts emerge.
The staged reports
Initial, intermediate and final reporting as one continuous process with clear internal ownership.
Detection to decision
The internal path that gets an event in front of the right decision-maker fast enough to matter.
Third-party incidents
Reporting when the failure sits with an ICT provider, and the contractual information rights that make it possible.
Overlapping regimes
Coordinating DORA reporting with data protection, sectoral supervisory and market disclosure duties.
Testing the process
Exercising the reporting chain, including out of hours, and evidencing that it works.
General guidance, not legal advice; take qualified advice on the obligations applying to your entity. Independent, with no endorsement by or affiliation with any regulator or supervisory authority.
Who it is for
Banks, insurers, investment firms and other financial entities in scope of DORA — their CISOs, operational resilience leads, incident managers, compliance officers and legal teams.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.