ICT-risk ownership for EU-licensed fintechs · EMI · PI · CASP
For fintechs that answer
to a regulator
One named owner for ICT risk, operating controls and the evidence your supervisor expects. From regulatory pressure to audit-ready in 90 days.
Fixed scope, fixed price · 2-4 hours a week of your team · 30-day exit after month 3
The requirements change. The owner does not.
Why the ownership model exists
Every requirement runs through the same four links.
Ownership is often the least explicit.
Across the requirements your regulated business has to meet, the same operating chain repeats: requirement, ownership, operating controls and evidence.
One named owner who operates the controls and keeps the evidence defensible across the requirements your business has to meet.
Management-body accountability remains. Where national law or licence conditions set further requirements, they apply.What you get
One owner. Three ways to start.
The same ownership function, at the scope you need today. Start with one defined engagement, build an audit-ready operating system in 90 days, or retain ongoing ICT-risk ownership.
Single-Engagement
One defined artefact or diagnosticGap analysis and roadmap, policy refresh, IR plan review, MiCA readiness review or regulator RFI support. Fixed scope, fixed price.
DORA 90-Day Programme
From gap to audit-readyBoard-approved ICT-risk framework and policy pack, Register of Information, incident classification and notification workflow, evidence index and board-ready evidence pack.
vCISO Retainer
Ongoing ICT-risk ownershipBoard Reporting Pack, regulator dialogue, quarterly tabletop, vendor reviews and testing plan. Further requirements such as MiCA, PSD2 SCA or SWIFT CSP can be incorporated where they fall within the agreed scope. 30-day exit after month 3.
Build · DORA 90-Day Programme
Ninety days is a programme,
not a slogan.
A fixed-scope build of the ICT-risk operating system your regulated business needs to run and evidence. Fixed price. Typically 2-4 hours a week of your team.
Diagnose
Gap analysis and roadmap- Gap register with per-obligation rating
- Prioritised remediation roadmap with owners
- Board-ready summary
Build
Build and implement- Board-approved ICT-risk framework and policy pack
- Register of Information in NCA column format
- Incident classification and notification workflow
- Evidence pack structured for external review
Validate
Test and validate- Resilience testing
- Tabletop and incident-response drills
- Evidence index brought current
Named ICT-risk ownership, a board-approved framework, registers a supervisor can read, an incident workflow that has been exercised, and a current evidence index. A defensible floor, not a promise of what a reviewer will find.
The programme ends at day 90, with its artefacts delivered. Ongoing ownership is a separate engagement, the vCISO Retainer, minimum three months. If you retain CyAdviso, the same function keeps operating: board reporting, regulator dialogue and further requirements as agreed.

Proof of work
“Show me the artefact.”
That is where advice becomes an operating function.
These are outputs of the operating system described above: the Register of Information, the Board Reporting Pack, the incident log, the evidence index. Reconstructed from real engagements with placeholder values; full anonymised samples are shown on a call, under NDA.
“We had fragmented evidence and couldn't explain our controls under review. Within 90 days, our framework was documented, defensible, and the regulator stopped repeating the same control questions.”CEO · EU-licensed EMI

Andrey Gubarev, founder and vCISO. CISO since 2008; former CISO at EU and UK-licensed financial institutions.
CISM · CDPSE · SABSAAbout CyAdviso →Independence rule: we do not independently assess controls we have built. Where an independent assessment is required, for SWIFT CSP or PSD2 SCA, it is a separate engagement.
The decision
The requirements change.
The artefacts change.
The owner stays named.
Fifteen minutes to a clear picture of your gaps, your exposure and a cost we can scope. One named owner for ICT risk, operating controls and evidence, from the first engagement.
info@cyadviso.com · SIA CyAdviso · Riga, Latvia · EU
- DORA
- MiCA
- PSD2 SCA
- SWIFT CSP
- What comes into scope next
- ICT-risk framework and policy pack
- Incident classification and notification
- Testing plan and drills
- Third-party clauses and vendor reviews
- Register of Information
- Evidence index
- Board Reporting Pack
- Incident log
