Étude de cas MiliSec — Virtual CISO
How a French fintech mapped ICT risks, qualified critical ICT providers, and passed its internal DORA assessment without surprises.
Contexte
80-person fintech, regulated by the ACPR, must demonstrate DORA (arts. 3-4) compliance before the semi-annual inspection.
Intervention
The Virtual CISO runs a fast-track audit: ICT register, critical ICT third-party assessment, risk scenarios, resilience test plan.
Résultat
Audit report ready in 90 days, 0 major non-conformities, critical providers documented and tested.
Leçon clé
'Comply before inspect' turns compliance from a burden into a competitive edge.
<!-- TODO editor: review, add metrics/stats if available, then set status: published -->