Cybervize
For banks, insurers and regulated financial services

DORA applies. We make your resilience demonstrable.

DORA has required resilient ICT operations since January 2025, with documented third-party risk and concentration risk analysis. Our vCISO leads your DORA implementation and works with OdySecure, the security platform by Cybervize. The TPRM module is aligned with the EBA draft CP/2025/12 (not final); MaRisk and NIS-2 run in the same control set.

Book the DORA classification

What the vCISO runs for you with OdySecure

Four areas where your vCISO avoids duplicate work because OdySecure serves the requirements in parallel.

01

TPRM per EBA guidelines

Contract register with 19 EBA mandatory fields, subcontractor chains, AI-assisted contract analysis, concentration-risk heatmap, exit strategies. Outsourcing register on demand.

02

DORA resilience requirements

ICT risk management framework, incident classification, resilience testing, critical functions, supplier impact analysis. Covered through the ISMS and TPRM modules.

03

DORA, MaRisk and supervisory reporting

Templates for BaFin filings, documented board involvement, compliance status against DORA and MaRisk. Consolidated at group, subsidiary and tenant level.

04

Entity status per legal entity, also under DORA

From the financial sector, Annex 1 to the German BSIG covers credit institutions, trading venues and central counterparties, and these are as a rule also subject to DORA. § 28 Abs. 6 Nr. 1 BSIG exempts them from named duties, not from the status. § 33 BSIG is not on the exemption list: registration remains, provided the company counts as an essential or important entity under the BSIG. Insurers and payment institutions, conversely, do not become Annex 1 entities merely because DORA applies to them. The assessment runs per legal entity, not per group: a carved-out IT or SOC company carries its own classification. The platform serves both regimes from a single control mapping.

More on this topic

Why financial services choose Cybervize

Four arguments from the regulated financial context.

01

DORA practice

“Alexander Busse supported us with Cybervize as Interim CISO in the DORA implementation and the ISO 27001 audit. We achieved both.” (Lorenz Jüngling, Co-CEO & Managing Director, Moonfare; translated from the German original)

02

Audit-ready evidence from day one

Platform evidence is built for the audit situation: timestamp, owner and version on every entry.

03

TPRM along the EBA draft CP/2025/12

Contract register with 19 EBA mandatory fields, subcontractor chains, documented due diligence, concentration risk and exit strategies. Outsourcing register on demand.

04

AI-assisted, but sovereign

Local LLMs for contract analysis and measure generation. In Sovereign mode, the default, no data is shared with external model providers; BYOK and Managed are available as alternatives. GDPR-compliant, hosting in Germany.

Why Cybervize is credible in the financial sector

OdySecure has a TPRM module aligned with the EBA draft CP/2025/12 (not final) that captures the 19 mandatory fields in the outsourcing register.

CP/2025/12
TPRM register aligned with the EBA draft
DORA
ICT resilience coverage
BaFin
Supervisory reporting templates
Moonfare
Interim CISO, DORA, ISO 27001

Frequently asked questions from financial services

Not in substance. § 28 Abs. 6 Nr. 1 of the German BSIG exempts DORA financial entities from §§ 30, 31, 32, 35, 36, 38 and 39 BSIG: ICT risk management and incident reporting run under DORA via BaFin. That is statutory non-application, not mere overlap in substance, and it does not touch any status as an entity. What remains is registration under § 33 BSIG, provided your company counts as an essential or important entity under the BSIG; entity type and size thresholds decide that. DORA alone does not make a company an Annex 1 entity. Management responsibility does not fall away either: DORA assigns it to the management body itself, including regular ICT risk training. The platform maps both regimes from one control set, so reporting does not have to run in parallel.

Contract register with 19 EBA mandatory fields, subcontractor chains, AI-assisted contract analysis, concentration-risk heatmap, documented exit strategies. Outsourcing register on demand for the regulator.

Multi-entity architecture for group structures, subsidiaries and international sites. Consolidated supervisory report at group, subsidiary and tenant level.

AI models are self-operated in Sovereign mode, with no data sharing with external model providers; alternatively BYOK or Managed, where you define the data flow. Bring your own API keys (OpenAI, Azure, Anthropic, Ollama) or managed service with German data residency. GDPR-compliant with anonymisation and scheduled deletion.

API integration with existing GRC and reporting tools (RSA Archer, MetricStream, ServiceNow GRC). Three migration scenarios: co-existence, gradual replacement, full migration. Reports can be exported automatically into supervisory workflows.

Classify your DORA and NIS-2 position in an initial call

Free initial call with indicative classification on DORA scope, NIS-2 status, EBA outsourcing obligations and path recommendation. Ideally with IT risk management plus compliance present.

Book the DORA classification
50frameworks as a catalogue in the platform:standards and frameworks, regulatory requirements, requirement records per entry.See the full list

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT