SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
All articles

DORA Pillar 1: ICT Risk Management, What Financial Entities Need

DORA's first pillar (Articles 5–16) requires a board-owned ICT risk-management framework. Here's what that means in practice for banks, insurers, investment firms and their critical functions.

Denis Sota · · 2 min read

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025, and its first and largest pillar, ICT risk management (Articles 5–16), is the backbone everything else hangs from. For financial entities, it raises ICT risk from an IT concern to a board-level obligation.

General guidance, not legal advice. Confirm your specific obligations with your competent authority and the applicable Regulatory Technical Standards (RTS).

A framework the board owns

The defining feature of DORA Pillar 1 is governance. The management body is explicitly responsible for the ICT risk-management framework, they must approve it, oversee it, and remain accountable. That framework has to be documented and reviewed at least annually, and it must cover the full lifecycle:

  • Identify, map your ICT assets, dependencies, and the business functions they support, including which are critical or important.
  • Protect & prevent, security policies, access control, encryption, change management.
  • Detect, monitoring and anomaly detection with defined thresholds.
  • Respond & recover, backup, restoration, and business-continuity arrangements tied to the incident and testing pillars.
  • Learn & evolve, post-incident reviews feeding back into the framework.

Where most of the work is

Two areas tend to absorb the effort: asset and dependency mapping (you can’t manage risk to functions you haven’t linked to the systems behind them), and the protective controls, particularly keeping ICT systems current against known vulnerabilities. DORA expects you to identify sources of ICT risk on a continuous basis, and unpatched, exploited vulnerabilities in your estate are one of the most concrete and measurable of those sources.

That continuous, evidence-backed view of technical exposure is the honest, narrow place SentriKat fits a DORA programme: exploited-first vulnerability management mapped to your real ICT inventory, with signed evidence you can fold into your Pillar-1 documentation and your reporting to management.

Start here

If you’re building toward Pillar 1: get the management body to formally own the framework, complete the inventory of ICT assets and their links to critical/important functions, and stand up a continuous process for identifying and remediating known exploited vulnerabilities. Those three move you from ad-hoc IT risk to a defensible DORA framework.

Want an indicative read on all five DORA pillars? The free, anonymous NIS2/DORA readiness check gives you a per-pillar gap analysis in about five minutes.

Ready to automate your vulnerability management?

Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.

Request a Demo