The AI that protects you
Stop wasting hours decoding DORA, NIS2, and ISO 27001.
Ward-AI answers any compliance question in 30 seconds, with exact sources. Your GRC team finally moves from decoding to doing.
Essai gratuit — aucune carte bancaire requise
Under DORA (Digital Operational Resilience Act), financial entities must notify major ICT-related incidents:
| Notification | Timeframe | Ref. |
|---|---|---|
| Initial | Within 4 hours | Art. 19(2) |
| Intermediate | Within 1 week | Art. 19(4) |
| Final | Within 1 month | Art. 19(5) |
Gap Analysis — ICT_Policy_v3.pdf vs DORA Chapter II
Management body responsibilities clearly defined (Section 2.1). Risk appetite documented.
Partial. Framework exists but lacks annual review cycle and explicit mapping to business functions.
Missing. No asset inventory or classification schema found in the document.
Encryption policies, access controls, and patch management documented (Sections 4-5).
Partial. Incident response exists but no communication plan for external stakeholders.