
DORA consulting
DORA 2025: New cybersecurity standards for the financial sector
Since January 2025, the Digital Operational Resilience Act (DORA) has introduced stricter regulations for the financial sector. The aim of the new EU regulation is to strengthen trust in the digital financial sector and minimize cyber risks.
In order to achieve DORA compliance, financial institutions must establish structured risk management, regularly monitor their ICT legacy systems and implement risk mitigation measures.
This is how we support you:
- Identify vulnerabilities & attack vectors of your legacy ICT system
- Evaluation & prioritization of threats based on the DORA protection goals
- Development of a concrete roadmap with risk mitigation measures

Crucial to the success of the project: the team did not try to bring security into the development teams from outside in a 'police role'. Instead, it empowered our teams themselves to systematically assess security.
Our references & projects
A reference is worth more than 1,000 words. Fortunately, we have dozens of them. Click through a selection of our most exciting projects and see for yourself!
-
MAN: Efficient threat analysis for control unitsLearn more
Digitalization increases cyber risks - especially for MAN's new CM4 control unit. Our experts use the 4×6 methodology and ThreatSea to identify threats at an early stage and develop targeted protective measures. Find out how MAN uses intelligent risk analysis to strengthen the security of its vehicles.
MAN: Efficient threat analysis for control unitsLearn more7 monthsProject duration
Over 20 workshopsThreat analyses
Over 500Potential risks evaluated

Why DORA consulting from MaibornWolff?
As experts in legacy systems, we know: Legacy systems are often the backbone of your company - they combine valuable functions with structures that are deeply integrated into operational processes. However, outdated components harbor high ICT risks that need to be addressed in a DORA-compliant manner.
With our experience from analyzing and evaluating over 100 legacy systems, we have perfected the balancing act: We preserve essential and valuable legacy functions, identify and modernize obsolete parts and ensure that operational and legal requirements are always the focus.
MaibornWolff: Your partner for DORA compliance
With MaibornWolff, you have a partner who can help you meet the DORA compliance requirements for your systems, strengthen their resilience and make them future-proof.
Technical and regulatory expertise:
Our team understands both the technology behind your systems and the industry-specific requirements.
Holistic approach:
We combine architecture, business processes and regulatory requirements into an integrated solution.
Practical experience:
Over 100 projects with legacy systems have taught us to minimize risks without jeopardizing valuable functions.
How we support you on the way to DORA compliance
Our DORA consultancy helps you to implement the new regulatory requirements efficiently and sustainably:
-
Implementation of DORA with existing business continuity
-
Cybersecurity training courses
-
Security Check-Up
-
Outstanding risk management
How does a DORA consultation at MaibornWolff work?
Our customized solution combines regulatory knowledge with innovative tools to bring your legacy individual software to the next level of digital resilience - while preparing it for future regulatory adjustments. Our structured consulting approach is geared towards the requirements of DORA and is based on three pillars:

1. Cybersecurity assessment
We identify threats and vulnerabilities in your processes and organizations using innovative methods and tools. Our focus is on the protection goals of confidentiality, integrity, availability and authenticity. We prioritize risks based on the level of damage and probability of occurrence and develop a concrete roadmap with risk mitigation measures.
2. Software health check
We analyze your legacy system and identify data flows and dependencies. We then assess the operational security and stability of all technical components of your legacy system and the associated technical and operational risks in accordance with DORA requirements. We uncover dependencies between components in your software landscape and visualize critical hotspots in the code. In this way, we create a sound basis for the implementation of technical and organizational improvements.
3. Future readiness & compliance support
Our advice goes beyond technical aspects: we also consider regulatory, business and personnel risks. We support you in making your systems DORA-compliant and preparing them for new regulatory requirements in the long term.