A managed pathway from the Central Bank's IT Thematic Review to DORA compliance readiness — built specifically for Irish credit unions, delivered on the CyberPrism platform with CRI's advisory team beside you.
Understanding the road from the CBI IT Review to DORA. A practical briefing designed for credit union leaders responsible for technology oversight, cybersecurity, and regulatory compliance.
You'll leave with a clearer understanding of the regulatory landscape and a practical roadmap to strengthen digital resilience in your organisation.
The Central Bank of Ireland's IT Risk Thematic Review marks a critical supervisory milestone — and the formal starting point on the journey toward DORA compliance. It is not the destination.
Our managed programme guides credit unions from structured review alignment through governance strengthening, evidence validation and optional independent board-level sign-off — building durable foundations for DORA compliance readiness.
The IT Thematic Review is an essential starting point for DORA compliance. It strengthens:
Why this matters beyond today: these are the same foundations required under DORA. Addressing the IT Thematic Review properly today reduces future regulatory friction and positions your credit union for smoother DORA alignment. Our managed service escalates you from the IT Thematic Review to DORA compliance as part of the same journey.
The Central Bank's IT Risk Thematic Review has highlighted sector-wide weaknesses in four areas. Regulatory engagement is increasingly focused on what boards can demonstrate — not simply what policies exist.
Clear accountability, informed challenge, and demonstrable board engagement with ICT risk.
Policies are not enough — supervisors want evidence that controls operate in practice.
Tested continuity arrangements and resilience that stands up to disruption.
Oversight of critical providers, aligned to supervisory and DORA expectations.
This is no longer an operational issue. It is a governance and accountability issue.
"Carlow Credit Union was looking for a solution that would help us manage and coordinate our obligations for the CBI IT Thematic Review, while also scanning the environment for assistance in managing compliance obligations under DORA. We wanted to establish what "good looked like" in terms of policies, procedures and processes. We now have a clear roadmap to get to where we want to be. The ease of use of the system coupled with the built-in AI tools will provide a valuable, efficient, cost-effective resource for the organisation. We see it as an investment in our knowledge base rather than merely another cost item.
"Progressive Credit Union have been using the CyberPrism platform (cudora.ie) as a tool to measure our cyber security readiness against the CBI Thematic Review and ultimately DORA. It has transformed the way we assess and manage our security posture. The platform is intuitive, comprehensive, and incredibly efficient at identifying vulnerabilities and measuring risk levels. What sets this system apart is its ability to translate complex cybersecurity data into clear, decision-ready reports.
"Completing the Certified Digital Operational Resilience Officer programme for New Ross Credit Union has been an exceptionally valuable and timely experience. The programme provided a comprehensive understanding of digital operational resilience, with a strong focus on governance, risk management, ICT resilience, and incident response. This certification has enhanced my ability to support strategic decision-making, ensure regulatory compliance, and contribute to building a robust, forward-looking resilience culture.
Developed by CRI specifically for Irish credit unions, this annual programme provides a clear framework to help your credit union:
Each stage not only aligns you with current supervisory expectations but also builds the governance foundations required for DORA compliance. It is designed to support credit unions at any stage of maturity.
CyberPrism, configured for credit unions — cudora.ie.
See your posture the way supervisors will look at it.
Prioritised actions, tracked to completion with evidence.
CRI's experts beside you throughout the programme year.
It is designed to support credit unions at any stage of maturity — start where you are.
The annual subscription represents proportionate, governance-focused engagement. The Independent Sign-Off add-on reflects the additional effort required for independent validation and formal board assurance. See the CUDORA Terms of Service.
Looking beyond the IT Thematic Review: while the review has sharpened supervisory focus, DORA compliance is the long-term regulatory framework shaping digital resilience in the financial sector. This managed service ensures that work undertaken today contributes directly to long-term DORA alignment — avoiding duplication and reducing future remediation burden.
At Cyber Risk International (CRI), we are proud to stand alongside our sister organisation, the International Cyber Threat Task Force (ICTTF), in delivering tailored cybersecurity, compliance, and resilience services to credit unions across Ireland.
We are honoured to be working in partnership with the Irish League of Credit Unions (ILCU) on these important initiatives. Our approach combines practical regulatory expertise from ICTTF's world-class training and certification programmes with technological innovation from CRI's CyberPrism Digital Resilience Platform — enabling credit unions to assess, improve, and sustain digital resilience in a simple, measurable, and strategic way.
This is more than a compliance journey — it's a resilience movement. And we're proud to help lead it.
Watch the recorded walkthrough below — or request a live demo session tailored to your credit union.
Starting with your IT Thematic Review alignment — extending through governance strengthening and independent sign-off where required.