DORA consulting
DORA 2025: New cybersecurity standards for the financial sector
Since January 2025, the Digital Operational Resilience Act (DORA) has introduced stricter regulations for the financial sector. The aim of the new EU regulation is to strengthen trust in the digital financial sector and minimize cyber risks.
In order to achieve DORA compliance, financial institutions must establish structured risk management, regularly monitor their ICT legacy systems and implement risk mitigation measures.
This is how we support you:
- Identify vulnerabilities & attack vectors of your legacy ICT system
- Evaluation & prioritization of threats based on the DORA protection goals
- Development of a concrete roadmap with risk mitigation measures
Crucial to the success of the project: the team did not try to bring security into the development teams from outside in a 'police role'. Instead, it empowered our teams themselves to systematically assess security.
Our references & projects
A reference is worth more than a thousand words. Luckily, we have dozens of them. Click through a selection of our most exciting projects and see for yourself!
-
To the BMW referenceVirtualization of software testing for control units in the AWS cloudCloudEmbedded Systems & RoboticsQuality EngineeringTo the BMW referenceDigital twin for control unit development & testing in cars
To the BMW referenceVirtualization of control units & AWS cloud integration
To the BMW referenceSetup of virtual cars & control units without expensive hardware setups, worldwide & distributed testing
-
To the STARTRAIFF referenceSTARTRAIFF: Business Intelligence for the sales forceCloudData/Data PlatformsAppsTo the STARTRAIFF referenceAggregation of internal customer data & external data in a single web application
To the STARTRAIFF referenceData bundling & analysis with Amazon Bedrock
To the STARTRAIFF referenceIntuitive user interface for sales, 88% reduced preparation time before customer visits
-
To the MAN referenceMAN - ATLAS L4. Control Center for the autonomous truckCloudData/Data PlatformsAppsTo the MAN referenceControl center for the technical monitoring of driverless trucks
To the MAN referenceUX design, product strategy, data structure, vehicle data visualization
To the MAN referenceMonitoring, remote support, mission management, reports for commercial autonomous transport solutions
-
To the NOW referenceNOW: National Organization for Change in Mobility: development of a data warehouse systemCloudData/Data PlatformsIT Consulting & StrategyTo the NOW referenceData foundation for nationwide charging infrastructure in Germany
To the NOW referenceCloud data warehouse for integration & analysis of many diverse data sources (AWS)
To the NOW referenceSolid architecture, single point of truth ensures data-based evaluation of charging station demand
-
To the NETZSCH referenceNETZSCH: Development of an IoT platformCloudData/Data PlatformsIoTTo the NETZSCH referenceUnified IoT platform for 3 business units, harmonization of existing IoT solutions
To the NETZSCH referenceIoT device connectivity, visualization software for data analysis, cloud infrastructure, operations
To the NETZSCH referenceQuick testing in the cloud infrastructure, fast integration of use cases such as predictive maintenance, process optimizations, etc.
-
To the OroraTech referenceOroraTech - Security & Compliance SupportCloudCybersecurityIT Consulting & StrategyTo the OroraTech referenceRisk threat analyses for satellite startup
To the OroraTech referenceSecurity process definition, IT security risk register, action plan
To the OroraTech referenceFuture-proof IT security for successful growth
-
To the TKE referenceTK Elevator: Health Check Connectivity for the IoT gateway of elevatorsCybersecurityIoTEmbedded Systems & RoboticsTo the TKE referenceIoT gateway (MAX Box) for data connection between elevator & IoT platform
To the TKE referenceExamination of code quality, architecture, operations & organization
To the TKE referenceOptimization of IoT gateway connectivity & digitalization of elevators
-
To inCTRL referenceinCTRL Solutions: Modernization of the IoT platform for water treatment plantsCloudIoTIT ModernizationTo inCTRL referenceIoT & software modernization, integration of new functions
To inCTRL referenceData warehouse setup, integration of microservices, automated quality assurance, Continuous Integration & Continuous Deployment (CI/CD)
To inCTRL referenceImproved resilience, maintainability & further development capability of the platform
-
To the Health.exe referenceHealth.exe: AI-supported platform creates training plans for patientsCloudData/Data PlatformsAppsTo the Health.exe referenceAI-supported service for orthopedic & sports medicine practices
To the Health.exe referenceCloud-based web application for doctors for the automated, evidence-based creation of individually tailored patient training plans
To the Health.exe referenceNew revenue source without fixed costs, higher patient retention, AI-supported & guideline-based
-
See MAN referenceMAN: Efficient threat analysis for control unitsCybersecurityIoTEmbedded Systems & RoboticsSee MAN referenceProtection of digitalized trucks against virtual attacks
See MAN referenceRisk analysis based on 4x6 methodology, ThreatSea, ISO21434
See MAN referenceQuick identification of relevant threats for immediately effective security measures
-
See Siemens referenceSiemens: AI demand prediction platform for industrial production planningCloudData/Data PlatformsIndustry 4.0See Siemens referenceMachine learning for time series forecasting
See Siemens referenceAutoML for automated adaptation of models to different data
See Siemens referenceUnified, scalable solution, optimized inventory costs, efficiency gains
-
See Miele referenceMiele domestic appliances are networked worldwideCloudIoTEmbedded Systems & RoboticsSee Miele referenceFurther development of the IoT platform for connected home appliances
See Miele referenceContainer-based architecture, open standards, modular design
See Miele referenceQuick availability & scalability of digital services, high added value for users
-
See STIHL referenceSTIHL: Control iMOW robotic mower via appCloudAppsIoTSee STIHL referenceControl and configuration of the robotic mower via smartphone
See STIHL referenceDevelopment of app, web, cloud platform and direct Bluetooth communication
See STIHL referenceDigital benefits for users, app controllability, remote software updates
-
See ifm services referenceifm services: Remote maintenance of systems and machinesCloudIoTEmbedded Systems & RoboticsSee ifm services referenceFully integrated remote access in the IoT platform
See ifm services referenceFull stack cloud application, RUST-based clients, UX design
See ifm services referenceAnalysis of sensor data from production as a basis for sustainable decisions for customers
-
See DER Touristik referenceDER Touristik Online: Development and migration of a multi-client capable travel booking platformCloudWeb & Portal PlatformsIT ScalingSee DER Touristik referenceConsolidation of websites onto a scalable travel booking platform
See DER Touristik referenceMulti-tenant platform in microservice architecture, cloud infrastructure & migration (AWS), digital design, testing
See DER Touristik referenceModern user experience, forward-looking travel experience platform
-
See MAN referenceMAN: Secure Software Development Life CycleCybersecurityIT Consulting & StrategyQuality EngineeringSee MAN referenceProtection of digitalized vehicles against virtual attacks & digital threats
See MAN referenceSSDLC in vehicle backend systems (UNECE R155), cybersecurity management system
See MAN referenceGuidelines, methodologies & tools for independent risk identification, assessment & treatment by employees
-
See Bayernwerk referenceBayernwerk: Knowledge management via teamsCloudIT Consulting & StrategyIT ModernizationSee Bayernwerk referenceTeams app for service technicians
See Bayernwerk referenceUser-centered, intuitive UX/UI design
See Bayernwerk referenceIdentification & utilization of implicit knowledge within the company
-
See Es geht LOS referenceEs geht LOS: Development of a cloud-based application for citizen participationCloudAppsWeb & Portal PlatformsSee Es geht LOS referenceApp for digitalizing lottery-based participation processes for municipalities
See Es geht LOS referenceDigital Garage, AWS Amplify & Google Maps integration, MVP in just 5 weeks
See Es geht LOS referenceSelection, contact & user management via the app: data-secure, efficient, user-friendly
-
See referenceMonitoring alarms in industrial plantsCybersecurityIoTEmbedded Systems & RoboticsSee referenceLive monitoring platform for visualizing connected warning devices
See referenceAutomation & cloud services (MS Azure), API management
See referenceAlarms visible worldwide within seconds, multi-tenant system
-
See referenceGlobal workforce planning systemCloudData/Data PlatformsPublic/AdministrationSee referenceCentralized web-based IT system to replace individual isolated solutions
See referenceEvent sourcing for planning & analytics, domain-driven design, cloud migration
See referenceEasy updates, expansion, maintenance, optimized security
-
See DER Touristik referenceDER Touristik: Become a digital travel companion in 7 monthsCloudAppsWeb & Portal PlatformsSee DER Touristik referenceApp for digital customer support before, during & after the trip
See DER Touristik referenceCross-platform app with Flutter, UX/UI design, requirements engineering
See DER Touristik referenceArchitecture flexibly integrates and extends to many languages, countries & brands
-
See DEKRA referenceDEKRA: Modern enterprise architecture thanks to co-creationCloudIT Consulting & StrategyIT ModernizationSee DEKRA referenceOperational & technical harmonization of the legacy IT landscape
See DEKRA referenceEnterprise architecture as co-creation by the lead architects of all IT business units
See DEKRA referenceEA community worldwide for all operational units
-
See BMW Group referenceBMW Group: Remote software upgrade for vehiclesCloudCybersecurityIoTSee BMW Group referenceSoftware upgrades without the need to visit a service center
See BMW Group referenceBackend system for over-the-air communication with the vehicle, 24/7 support
See BMW Group referenceIT security, more comfort, on-demand provision of new features
-
See digikoo referencedigikoo: A data platform for the Azure CloudCloudData/Data PlatformsIT Consulting & StrategySee digikoo referenceData-based information for planning & implementing the climate transition for the public sector & energy providers
See digikoo referenceScalable foundation data platform on MS Azure for migrating & automating differently formatted geo-data into a structured data schema
See digikoo referenceQuality-checked data, provision in the form of the target data model, robust, scalable database & infrastructure
-
See Creditreform referenceCreditreform: Secure proof of identity on the webCybersecurityWeb & Portal PlatformsBanking/Insurance/FSISee Creditreform referenceFast, customer-friendly & fraud-proof digital identity verification
See Creditreform referencePilot for the forgery-proof storage & management of identity & company information in a Decentralized Identity (DID)
See Creditreform referenceVerified data reusable across different providers
-
See Weidmüller referenceWeidmüller: Progression of the Industrial Service PlatformCloudIoTWeb & Portal PlatformsSee Weidmüller referenceCreation of a centralized, intuitive, expandable portal as the foundation for industrial applications (remote access, data visualization, ML)
See Weidmüller referenceExploration, setup & further development of the base platform for industrial services
See Weidmüller referenceInnovative portal for end-to-end solutions, MVP in just 7 months
-
To the FinOps referenceTravel information systems: 25 percent savings in cloud costs and stable operation thanks to FinOpsCloudIT Consulting & StrategyWeb & Portal PlatformsTo the FinOps referenceAlignment of the distributed travel information system with many data sources & target groups on the AWS cloud
To the FinOps referenceFinOps: cost transparency, cloud strategy, system & architecture design, usage-based operating times, early anomaly detection
To the FinOps referenceCost transparency at team level, lean operating processes, robust observability
-
To the FinOps referenceSupply chain management: Reducing cloud operating costs by 50 percent with FinOpsCloudData/Data PlatformsIT Consulting & StrategyTo the FinOps referenceReduction of costs caused by over-dimensioning & manual processes, establishment of transparency
To the FinOps referenceTargeted process modernization, automation & rightsizing
To the FinOps referenceAnnual cloud operating cost reduction: 400,000 EUR, scalability, reliability
Why DORA consulting from MaibornWolff?
As experts in legacy systems, we know: Legacy systems are often the backbone of your company - they combine valuable functions with structures that are deeply integrated into operational processes. However, outdated components harbor high ICT risks that need to be addressed in a DORA-compliant manner.
With our experience from analyzing and evaluating over 100 legacy systems, we have perfected the balancing act: We preserve essential and valuable legacy functions, identify and modernize obsolete parts and ensure that operational and legal requirements are always the focus.
MaibornWolff: Your partner for DORA compliance
With MaibornWolff, you have a partner who can help you meet the DORA compliance requirements for your systems, strengthen their resilience and make them future-proof.
Technical and regulatory expertise:
Our team understands both the technology behind your systems and the industry-specific requirements.
Holistic approach:
We combine architecture, business processes and regulatory requirements into an integrated solution.
Practical experience:
Over 100 projects with legacy systems have taught us to minimize risks without jeopardizing valuable functions.
How we support you on the way to DORA compliance
Our DORA consultancy helps you to implement the new regulatory requirements efficiently and sustainably:
-
Implementation of DORA with existing business continuity
-
Cybersecurity training courses
-
Security Check-Up
-
Outstanding risk management
How does a DORA consultation at MaibornWolff work?
Our customized solution combines regulatory knowledge with innovative tools to bring your legacy individual software to the next level of digital resilience - while preparing it for future regulatory adjustments. Our structured consulting approach is geared towards the requirements of DORA and is based on three pillars:
1. Cybersecurity assessment
We identify threats and vulnerabilities in your processes and organizations using innovative methods and tools. Our focus is on the protection goals of confidentiality, integrity, availability and authenticity. We prioritize risks based on the level of damage and probability of occurrence and develop a concrete roadmap with risk mitigation measures.
2. Software health check
We analyze your legacy system and identify data flows and dependencies. We then assess the operational security and stability of all technical components of your legacy system and the associated technical and operational risks in accordance with DORA requirements. We uncover dependencies between components in your software landscape and visualize critical hotspots in the code. In this way, we create a sound basis for the implementation of technical and organizational improvements.
3. Future readiness & compliance support
Our advice goes beyond technical aspects: we also consider regulatory, business and personnel risks. We support you in making your systems DORA-compliant and preparing them for new regulatory requirements in the long term.