IT Advisory for Financial Services & Banking
For banks, insurers, asset managers and payment institutions, DORA has applied directly as EU law since 17 January 2025 and, as sector-specific regulation, displaces the NIS2 obligations.
IT in Finance
BaFin has withdrawn its earlier circulars: VAIT, KAIT and ZAIT ceased to apply on 16 January 2025, while BAIT stopped applying to institutions in DORA scope on 17 January 2025 and phases out entirely by the end of 2026. The yardstick today is DORA itself, its regulatory technical standards and MaRisk. Four continuous duties follow: a complete register of information covering every ICT service contract, filed with the supervisor annually — BaFin accepted the 2026 registers between 9 and 30 March and forwards them to the European Supervisory Authorities by 31 March; reporting of major ICT-related incidents, with an initial notification within four hours of classifying the incident as major and no later than 24 hours after becoming aware of it; threat-led penetration testing (TLPT) at least every three years for designated institutions; and outsourcing contracts carrying audit rights and a workable exit strategy.
For IT this means every outsourced service needs a documented and tested recovery path, not just a backup. Privileged access must be recertified and fully logged, because the four-hour deadline cannot be met without a clean event base. And concentration risk on a single provider needs assessing before the supervisor asks. Alendris works on precisely these points.
At a financial services client we rolled out Microsoft 365 Copilot enterprise-wide — but only after sensitive data had been classified with Microsoft Purview, sensitivity labels applied and excessive SharePoint permissions cleaned up: governance before activation rather than clean-up afterwards. Alongside that we deliver zero-trust and identity projects with Entra ID, Conditional Access and passwordless sign-in, threat detection built on Microsoft Sentinel and Microsoft Defender XDR, backup and disaster recovery architectures with immutable storage and rehearsed failover, and Azure Virtual Desktop for workplaces that need performance and traceability at the same time.
Typical pain points
- BaFin MaRisk and DORA require comprehensive operational resilience evidence
- Cloud outsourcing contracts need regulatory review — missing standards
- Banking trojans and APTs require detection capabilities beyond standard AV
- Trader workplaces need high performance and compliance logging simultaneously
- M&A in finance: PE-driven consolidation requires IT carve-outs under regulatory law