#DORA
16 articles
DORA and TLPT — What Threat-Led Penetration Tests Look Like for the Financial Sector
DORA raises the bar for testing in the financial sector: significant entities must carry out TLPT — tests targeted at real threats, on live systems, by independent testers. We explain the scope, the TIBER-EU framework, and how to prepare.
DORA for the Financial Sector — Practical Implementation Step by Step (2026)
DORA has been in force since January 2025. Most Polish banks, fintechs, insurers and investment firms still lack full compliance. What to actually do in 90 days, how much it costs, who is responsible.
OWASP API Security Top 10 (2023) — complete guide to API threats
The OWASP API Security Top 10 (2023) is to APIs today what the Web Top 10 was a decade ago — a shared language for development teams, pentesters and compliance functions. Except that an API is a different attack surface than a classic web application.
What Is Cybersecurity? Definition, Pillars, Threats, and Best Practices
Cybersecurity is the protection of systems, networks, and data against digital threats. Learn about the pillars, threats, and best practices.
Cybersecurity Checklist for Financial Sector — 2026
A complete cybersecurity checklist for banks and financial institutions in 2026. Covers DORA, NIS2, PCI DSS requirements and best practices for financial sector protection.
Security Policies — Why Internet Templates Don't Work
How to write security policies people actually read and follow? 5 essential policies, document hierarchy, RACI, implementation. Expert guide by nFlo.
Cloud Compliance Checklist — Legal Requirements for Cloud Environments
A complete regulatory compliance checklist for cloud environments — from GDPR through NIS2 to DORA. Legal requirements, shared responsibility model, and practical implementation steps.
Cybersecurity Trends 2026 — What Awaits Organizations in the Coming Year
What will dominate cybersecurity in 2026? AI-driven attacks, identity-first security, platform consolidation, and NIS2, DORA, and CRA enforcement — for IT leaders.
DORA for insurers — digital operational resilience requirements
Comprehensive guide to DORA requirements for the insurance sector. ICT risk management, resilience testing, incident reporting, and third-party provider management.
DORA for Financial Sector: Requirements and Step-by-Step Implementation
The DORA regulation transforms cybersecurity in finance. Learn about the 5 pillars of DORA, implementation timeline, and concrete steps for banks, insurers, and fintechs.
Cybersecurity Risk Assessment — The Foundation of Every Security Program
How to conduct a cybersecurity risk assessment? ISO 27005, NIST RMF, FAIR, MITRE ATT&CK, risk matrices and security roadmaps. Expert guide by nFlo.
DORA and Digital Resilience Testing — How to Prepare for TLPT and Threat-Led Scenarios
How to prepare for TIBER-EU-compliant TLPT under DORA? A guide for CISOs: requirements, testing scope, costs and implementation timeline for financial firms.
DORA for the Financial Sector — What Banks, Insurers, and Fintechs Must Implement
What does DORA require from banks, insurers and fintechs? ICT risk management, incident reporting and TLPT testing explained step by step by nFlo experts.
DORA in practice - requirements for the financial sector and its suppliers
DORA is the most rigorous cybersecurity law in the world. Banks, insurers, and their suppliers must meet requirements that change the approach to digital resilience.
DORA for Insurance Companies — Requirements and Implementation Plan
The DORA regulation imposes digital operational resilience obligations on insurance companies. A practical implementation guide: ICT risk management, resilience testing, incident reporting.
How DORA Protects Against Digital Threats? Processes, Mechanisms, Regulations and Development
Check how DORA protects against digital threats. Learn about key processes and regulations in the financial sector.