Sector · Irish Credit Unions · CUDORA

Managed DORA compliance for credit unions

A managed pathway from the Central Bank's IT Thematic Review to DORA compliance readiness — built specifically for Irish credit unions, delivered on the CyberPrism platform with CRI's advisory team beside you.

Recorded briefing · Watch now

Digital Resilience Briefing for Credit Unions

Understanding the road from the CBI IT Review to DORA. A practical briefing designed for credit union leaders responsible for technology oversight, cybersecurity, and regulatory compliance.

You'll leave with a clearer understanding of the regulatory landscape and a practical roadmap to strengthen digital resilience in your organisation.

The journey

The IT Thematic Review is the starting point — not the destination

The Central Bank of Ireland's IT Risk Thematic Review marks a critical supervisory milestone — and the formal starting point on the journey toward DORA compliance. It is not the destination.

Our managed programme guides credit unions from structured review alignment through governance strengthening, evidence validation and optional independent board-level sign-off — building durable foundations for DORA compliance readiness.

The IT Thematic Review is an essential starting point for DORA compliance. It strengthens:

  • ICT risk management structures
  • Governance frameworks
  • Oversight documentation
  • Resilience controls

Why this matters beyond today: these are the same foundations required under DORA. Addressing the IT Thematic Review properly today reduces future regulatory friction and positions your credit union for smoother DORA alignment. Our managed service escalates you from the IT Thematic Review to DORA compliance as part of the same journey.

CUDORA roadmap: pathway from IT Thematic Review to DORA compliance
Governance

Why this matters for your board

The Central Bank's IT Risk Thematic Review has highlighted sector-wide weaknesses in four areas. Regulatory engagement is increasingly focused on what boards can demonstrate — not simply what policies exist.

ICT governance and board oversight

Clear accountability, informed challenge, and demonstrable board engagement with ICT risk.

Documentation and evidence of control

Policies are not enough — supervisors want evidence that controls operate in practice.

Business continuity and operational resilience

Tested continuity arrangements and resilience that stands up to disruption.

Outsourcing and third-party risk management

Oversight of critical providers, aligned to supervisory and DORA expectations.

This is no longer an operational issue. It is a governance and accountability issue.

Credit unions on CUDORA

What your peers are saying

"

Carlow Credit Union was looking for a solution that would help us manage and coordinate our obligations for the CBI IT Thematic Review, while also scanning the environment for assistance in managing compliance obligations under DORA. We wanted to establish what "good looked like" in terms of policies, procedures and processes. We now have a clear roadmap to get to where we want to be. The ease of use of the system coupled with the built-in AI tools will provide a valuable, efficient, cost-effective resource for the organisation. We see it as an investment in our knowledge base rather than merely another cost item.

Ultan RyanCEO — Carlow Credit Union
"

Progressive Credit Union have been using the CyberPrism platform (cudora.ie) as a tool to measure our cyber security readiness against the CBI Thematic Review and ultimately DORA. It has transformed the way we assess and manage our security posture. The platform is intuitive, comprehensive, and incredibly efficient at identifying vulnerabilities and measuring risk levels. What sets this system apart is its ability to translate complex cybersecurity data into clear, decision-ready reports.

Carol BoonBSc, QFA, CUA, CUG, DCCS — Digital Transformation & Resilience Manager, Progressive Credit Union Ltd
"

Completing the Certified Digital Operational Resilience Officer programme for New Ross Credit Union has been an exceptionally valuable and timely experience. The programme provided a comprehensive understanding of digital operational resilience, with a strong focus on governance, risk management, ICT resilience, and incident response. This certification has enhanced my ability to support strategic decision-making, ensure regulatory compliance, and contribute to building a robust, forward-looking resilience culture.

Aoife CheastyRisk and Compliance Senior Manager — New Ross Credit Union
CUDORA

A structured supervisory readiness programme

Developed by CRI specifically for Irish credit unions, this annual programme provides a clear framework to help your credit union:

  • Identify gaps against IT Thematic Review expectations
  • Prioritise remediation actions
  • Strengthen ICT governance structures
  • Improve outsourcing oversight
  • Enhance operational resilience documentation
  • Demonstrate board-level oversight

Each stage not only aligns you with current supervisory expectations but also builds the governance foundations required for DORA compliance. It is designed to support credit unions at any stage of maturity.

Secure cloud-based assessment platform

CyberPrism, configured for credit unions — cudora.ie.

Supervisory-aligned dashboards

See your posture the way supervisors will look at it.

Structured remediation planning

Prioritised actions, tracked to completion with evidence.

Ongoing advisory support

CRI's experts beside you throughout the programme year.

Get started

Choose your starting point

It is designed to support credit unions at any stage of maturity — start where you are.

The annual subscription represents proportionate, governance-focused engagement. The Independent Sign-Off add-on reflects the additional effort required for independent validation and formal board assurance. See the CUDORA Terms of Service.

Looking beyond the IT Thematic Review: while the review has sharpened supervisory focus, DORA compliance is the long-term regulatory framework shaping digital resilience in the financial sector. This managed service ensures that work undertaken today contributes directly to long-term DORA alignment — avoiding duplication and reducing future remediation burden.

A resilience movement

CRI and credit unions in Ireland

At Cyber Risk International (CRI), we are proud to stand alongside our sister organisation, the International Cyber Threat Task Force (ICTTF), in delivering tailored cybersecurity, compliance, and resilience services to credit unions across Ireland.

We are honoured to be working in partnership with the Irish League of Credit Unions (ILCU) on these important initiatives. Our approach combines practical regulatory expertise from ICTTF's world-class training and certification programmes with technological innovation from CRI's CyberPrism Digital Resilience Platform — enabling credit unions to assess, improve, and sustain digital resilience in a simple, measurable, and strategic way.

This is more than a compliance journey — it's a resilience movement. And we're proud to help lead it.

Compliance Connect
International Cyber Threat Task Force
See it in action

Play the 20-minute CUDORA platform demo

Watch the recorded walkthrough below — or request a live demo session tailored to your credit union.

Begin your managed journey to DORA readiness

Starting with your IT Thematic Review alignment — extending through governance strengthening and independent sign-off where required.

Sign me up for CUDORA →