Financial sector · ICT & cyber risk management (DORA Pillar 1 + FINMA)

ICT & cyber risk management for financial institutions, set up audit-ready

Banks, insurers, securities firms, FinTechs and asset managers must steer their ICT and cyber risks like a core operational risk. DORA Pillar 1 requires a complete ICT risk-management framework, and FINMA expects operational resilience. We build that framework on an ISO 27001 base, with an asset and risk register, BCM and board-ready reporting. We verify the scope per institution.

DORA Pillar 1 · FINMA Circ. 2023/01 ISO 27001 base DE · FR · EN
ICT and cyber risk management for financial institutions

For risk, ICT and compliance leads at banks, insurers and FinTechs

DORA Pillar 1 ICT risk framework
FINMA Circ. 2023/01 operational resilience
ISO 27001 ISMS as the base
Asset & risk register audit-ready
CH · EU multilingual DE/FR/EN
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.

LinkedIn

ICT risk management has become a supervisory duty

DORA Pillar 1 requires a complete, documented ICT risk-management framework, and FINMA expects ICT and cyber risks to be steered like core operational risks. What applies directly or indirectly in your case, we verify per institution.

FINMA Circular 2023/01 on operational risks and resilience for banks is in force and applies to FINMA-supervised institutions. It expects ICT and cyber risks to be identified, assessed, mitigated and monitored, embedded in governance that reaches up to the board. So a lived ICT risk management is no longer optional, it is part of the supervisory expectation.

DORA, the EU Digital Operational Resilience Act, applies in the EU since 17 January 2025 and, in Pillar 1, requires an ICT risk-management framework across the full lifecycle: governance and responsibilities, identification of ICT assets and risks, protection and prevention, detection, response and recovery, plus structured learning from incidents. For Swiss institutions DORA usually applies indirectly, through EU branches or subsidiaries or through contracts with EU-regulated financial entities. Whether DORA applies directly or indirectly, we clarify per institution.

A solid framework does not stand on its own. It needs a maintained ICT asset and risk register as its foundation, a link to business continuity management with defined recovery times, and reporting that gives the board a clear picture of the ICT risk position. These are exactly the building blocks we make audit-ready.

  • A documented ICT risk-management framework with governance, roles and responsibilities under DORA Pillar 1
  • Identification and classification of ICT assets and risks in a maintained register
  • Protection and prevention measures aligned to the risk position and FINMA expectations
  • Detection, response and recovery linked to BCM with defined recovery time objectives (RTO)
  • Structured learning from incidents and regular updating of the framework
  • Board-ready ICT risk reporting to executive management and the board

How we build your ICT risk-management framework

We anchor ICT risk management on an ISO 27001 base. That avoids a parallel DORA silo and creates an integrated framework that serves FINMA expectations and DORA Pillar 1 with the same evidence.

We start from an ISO 27001 base as a shared foundation. An information security management system provides the governance, the risk methodology and the control catalogue, onto which the specific DORA and FINMA requirements dock cleanly. Where an ISMS already exists, we close the gaps to the ICT risk framework rather than starting from scratch.

At the core sits an ICT asset and risk register. We capture your ICT assets, map them to critical business functions and assess the risks with a consistent methodology. From this we derive the control selection and close the gaps in priority order, from protection and prevention through detection to response and recovery. We maintain the register, risks and measures in the Priverion Platform, the Swiss compliance management software, so the evidence is always maintained and exportable.

We align the framework with business continuity management. Critical ICT assets receive defined recovery time objectives aligned to the business requirements, and the detection and recovery processes interlock. Operational building blocks such as vulnerability scans and penetration tests are established SIDD services and feed directly into the protection and detection layer. Ongoing 24/7 monitoring and managed incident response we coordinate with specialised partners when needed, which keeps our advice independent.

The framework closes with board-ready ICT risk reporting. We give executive management and the board a clear, consistent picture of the ICT risk position, the open measures and the residual risk, in the language the body understands. So the supervisory expectation on governance and accountability is demonstrably met. We work throughout in German, French and English.

Why SIDD for your ICT risk management

An ICT risk framework joins supervisory requirements with lived technical security. We cover exactly that combination from one partner, legally led and technically grounded.

Legal and security from one partner

The supervisory classification of DORA and FINMA is led by doctorate-level lawyers, the ICT framework and the technical measures by an in-house technical team under an ISO 27001 Lead Auditor. So the regulatory interpretation and the technical implementation fit together.

ISO 27001 base instead of a DORA silo

We build ICT risk management on an ISMS rather than creating a parallel DORA construct. A shared foundation serves FINMA expectations, DORA Pillar 1 and a later ISO certification with the same evidence.

Audit-ready evidence in tooling

We maintain the ICT asset and risk register, controls, measures and reporting in the Priverion Platform. If FINMA, the auditor or internal audit asks, the evidence is available, maintained and exportable.

BCM and RTO built in

We connect ICT risk management with business continuity management and define recovery times for critical functions. So the risk framework feeds directly into the operational resilience that FINMA and DORA expect.

Tests included, independent advice

Vulnerability scans and penetration tests are part of our established services and feed directly into the protection and detection layer. Ongoing 24/7 monitoring and managed incident response we coordinate with specialised partners when needed, and because we do not sell an in-house SOC, our advice stays independent.

Multilingual & for the financial sector

We advise in German, French and English, fitting Swiss institutions and groups with an EU footprint. We bring the reporting into the language executive management and the board understand and align it to the supervisory expectation.

Two routes to audit-ready ICT risk management

vCISO / ongoing ICT risk operations

on request retainer, on request

The ongoing operation: someone who maintains the ICT risk register, produces the reporting and keeps the framework current in step with the supervisor.

  • vCISO as a fixed point of contact for ICT and cyber risk
  • Ongoing maintenance of the ICT asset and risk register, controls and measures in the Priverion Platform
  • Periodic ICT risk reporting to executive management and the board
  • Updating the framework for new FINMA and DORA requirements, scope verified case by case
  • Coordination of vulnerability scans and penetration tests and, where needed, of monitoring and incident response with specialised partners

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your ICT risk-management framework, concretely: LexCommand fills policies, the risk register and control evidence as tracked Word templates with sourced content, and mirrors your controls onto DORA, FINMA Circular 2023/01 and ISO 27001 at once, so overlapping requirements become visible together.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does DORA apply to us as a Swiss institution?

DORA applies in the EU since 17 January 2025. For Swiss institutions it usually applies indirectly, for example through an EU branch or subsidiary or through contracts with EU-regulated financial entities that pass DORA requirements down contractually. Whether DORA affects your institution directly or indirectly, we verify case by case and align the framework accordingly.

Do we need ISO 27001 to meet DORA and FINMA?

An ISO 27001 certification is not mandatory, but an ISMS to ISO 27001 is the most economical base. It provides governance, risk methodology and a control catalogue onto which DORA Pillar 1 and the FINMA expectations dock cleanly, rather than building a parallel silo. We set up the framework on this base and prepare a certification if you pursue one. The certificate itself is issued by an accredited certification body, we advise and prepare.

What distinguishes the ICT asset and risk register from a simple inventory list?

An inventory list tells you what you have. The ICT asset and risk register links every asset to the critical business functions it supports, assesses the associated risks with a consistent methodology and ties them to controls, measures and recovery times. That turns a list into a steering instrument that directly serves reporting and reviews. We maintain it in the Priverion Platform.

Do you also take on ongoing monitoring and incident response?

We build the framework, the ICT asset and risk register, the detection and recovery processes and the detection logic, and we run vulnerability scans and penetration tests as established services. We do not run ongoing 24/7 monitoring or a managed, live-led incident response ourselves. These operational building blocks we coordinate with specialised partners when needed, which keeps our advice independent.

How does ICT risk management relate to reporting cyber incidents to FINMA?

The framework provides the basis to detect and classify incidents early. According to its supervisory practice, FINMA expects cyber-attacks to be reported within about 24 hours of detection. For this to hold in a real case, detection, classification and reporting channels must be prepared. We cover that reporting process in depth on a dedicated page, and ICT risk management lays the foundation for it.

Do you work in French and English?

Yes. We build the framework and produce the reporting throughout in German, French and English, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and groups with an EU footprint.

Matching next steps

ICT risk management ties closely to the ISO 27001 base and ongoing governance operations:

Ready for audit-ready ICT risk management?

We build your ICT risk-management framework on an ISO 27001 base: asset and risk register, BCM alignment and board-ready reporting, audit-ready for FINMA and DORA. We verify the scope per institution.