Italiano: această pagină nu e încă tradusă. Textul de mai jos e în English.
Central bank and financial supervisory authority regulations look very different from one country to another, but the underlying structure repeats: governance and oversight at management level, risk management, third-party risk and outsourcing, incident reporting and operational resilience. A serious audit starts from the specific regime that applies to you, not from a universal checklist — and increasingly includes a component institutions didn’t have a few years ago: threat-led testing.
How we work
Supervisors have learned that a policy file doesn’t tell you whether a bank can withstand a real attack. That is why they test resilience the way an attacker would — using threat intelligence, against live systems, judging whether critical functions remain operational. The model is TIBER-EU, which also underpins the threat-led penetration testing (TLPT) required by DORA.
We align the institution to the specific regime — the central bank regulations you operate under, TIBER-EU, DORA or the applicable national scheme — and, where required, run:
- Identification of critical economic functions
- Scenarios built from sector-relevant threat intelligence
- A controlled red team exercise against production
- Detection and response assessment (blue team), with a joint debrief (purple team)
We also work with institutions in the Republic of Moldova, aligned to the requirements of the National Bank of Moldova — for example, Executive Committee decisions HCE no. 29, 281 and 289.
What you get
- Report aligned to the regulator’s requirements, suitable for submission
- Red team and blue team findings, with the attack-path narrative
- Remediation roadmap and compliance evidence