Risk concentration Payment flows, API keys and privileged access are the whole attack surface — and the whole business.
Compliance pressure SOC 2 for enterprise buyers, GDPR for the regulator, and operational resilience expectations arriving behind both.
Where we help Control design that survives due diligence, plus the reporting line your investors and partners expect to see.
Raising, or landing your first enterprise client? Both come with a security review. Knowing the answer before the questionnaire arrives is the cheapest version of this project. Book a consult
WHAT WE DO
Working with a fintech team
1 DORA gap assessment. Your ICT risk framework, incident classification and resilience testing measured against what the regulation actually asks of an entity your size — not a tier-one bank.
2 Register of information. The third-party ICT register a supervisor can ask to see, built once and kept current, including the contractual terms your cloud and payment providers are expected to carry.
3 Controls around the money path. Privileged access, key management and segregation of duties designed so that an auditor, an investor or a partner bank can follow them without a guided tour.
4 Incident reporting that meets the clock. Thresholds, decision trees and templates agreed in advance, so a major incident is classified and reported inside the window rather than debated during one.
5 Diligence and questionnaires. Investor and enterprise security reviews answered with evidence you already hold, instead of a fortnight of scrambling per request.
Most fintech engagements start with one of two triggers: a supervisory deadline, or a partner bank asking a question nobody can answer yet. Both are easier to handle before the date is fixed.
THE OBLIGATIONS
What actually reaches a company your size
DORA ICT risk management, incident reporting, third-party oversight and resilience testing — now supervised, not advisory.
PSD2 & SCA Strong customer authentication, secure communication, and the operational security duties that travel with payment services.
GDPR Financial and personal data together, breach notification inside 72 hours, and the transfer questions your infrastructure choices create.
NIS2 Where fintech infrastructure falls in scope, and the management-liability provisions that arrive with it.
COMMON QUESTIONS
Fintech, in short
Does DORA apply to a company our size?
DORA scales to the entity. Your ICT risk framework, incident classification and resilience testing are measured against what the regulation actually asks of a firm your size — not against a tier-one bank. What is the register of information?
It is the third-party ICT register a supervisor can simply ask to see. It is built once and kept current, and it includes the contractual terms your cloud and payment providers are expected to carry. How quickly does a breach have to be reported?
Under GDPR, breach notification falls inside 72 hours. DORA adds its own incident reporting clock, so thresholds, decision trees and templates are agreed in advance rather than debated during an incident. INSIGHTS · FINTECH Writing for this sector
All insights →