Banking, Finance & Insurance: DORA, NIS2 and operational resilience.
In finance and insurance, resilience is not just a matter of having procedures. It has to produce evidence: incidents classified, changes traced, providers registered, tests documented, exit strategies and responsibilities clearly established.
Atlassian Platinum Solution Partner since 2008 · French consultancy · Paris and Lyon
DORA: producing evidence in the flow of work
Regulation (EU) 2022/2554, known as DORA, concerns the digital operational resilience of the financial sector. It covers European financial entities, credit institutions, insurance and reinsurance undertakings, payment service providers and the other categories listed in Article 2, together with their third-party ICT service providers.
DORA does not ask for an intention, it asks for a trace.
A record is produced in the service tool, at the moment of the action, not in a spreadsheet rebuilt the day before the audit. That is the point that changes life for an IT department.
NIS2: strengthening control of digital risk
Depending on the entity's activity and scope, NIS2 may also apply alongside DORA. It strengthens the requirements on cybersecurity, risk management, continuity and supplier control.
Our role is to make sure these requirements show up in everyday processes, responsibilities and tools, rather than in parallel arrangements that are hard to maintain.
What we build the tooling for
| Requirement | What the audit expects | What BleuLemon puts in place |
|---|---|---|
| ICT risk | Inventory of assets, services and dependencies | An asset and service repository, links with the service processes, explicit responsibilities. |
| Incidents | Consistent classification and a reliable history | Qualification grids, workflows, notification templates, timestamping and dashboards. |
| Changes | Approval and traceability | Change process, impact analysis, approvals, outcome and a history that can be consulted. |
| Third-party providers | Visibility and review of dependencies | Register of third parties, periodic reviews, responsibilities and links with the services concerned. |
| Resilience testing | Scenarios, results, remediation | Documented test sets, switchover exercises, remediation backlog and follow-up. |
| Exit strategies | Reversibility, demonstrated | Recovery tests on data, configurations, attachments and permissions in usable formats. |
Compliance does not depend on any one tool, but on the ability to produce reliable processes, clear responsibilities and usable records.


Two engagements carried out in this industry
We replaced GLPI with Jira Service Management and Assets. The first release came after 7 weeks. We migrated 500 tickets with no service interruption. The engagement continued as an application maintenance contract (TMA, third-party application maintenance).
We ran an audit, then a data anonymisation PoC, leading to a Cloud trajectory. The PoC validated the anonymisation of a complete production data set, with no functional discrepancy found in acceptance testing.
The full Opteven engagement is set out in our case studies.
Frequently asked questions
A question that finds no answer here is dealt with in a thirty-minute conversation, about your actual context rather than a general case.
Talk to an expertSince when has DORA applied?
Regulation (EU) 2022/2554 has applied since 17 January 2025. Published in the Official Journal of the European Union on 27 December 2022, it covers European financial entities and their third-party ICT service providers. A regulation applies directly, with no national transposing text.
What is the difference between DORA and NIS 2?
DORA is a sector regulation focused on the digital operational resilience of the financial sector. NIS2 is a broader cybersecurity directive. Depending on the entity and its scope, the two frameworks may need to be considered together.
Do you need to change ITSM tool to comply with these requirements?
Rarely. We start from the existing configuration and the processes actually used, then we fix the blind spots. The quality of the evidence matters more than the brand of the platform.
How do you handle supplier reversibility?
As a continuity matter: data, configurations, permissions and attachments must be recoverable in a usable format. The exit is documented and tested before you need it.
How long does it take to make a service platform auditable?
The pace depends on your history. Our reference path runs to 5 stages over 90 days: assessment and prioritised backlog, portal and knowledge base, automation in production, dashboards by role, review of service commitments. At Opteven, the first release came after 7 weeks.
Going further: IT service management (ITSM / ESM)·Support, application maintenance and managed services·Atlassian Cloud migration·Case studies