HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
The Digital Operational Resilience Act requires 22,000+ financial entities to actively manage third-party ICT risk since January 2025. HodeiShield automates the Information Register, classifies incidents automatically, and keeps evidence ready for ESA inspection.
The 5 pillars
Conceptual illustration: the central graph represents concentration in critical ICT providers (e.g. relying on the same cloud provider for several functions).
The ICT Information Register is mandatory and must be delivered to ESAs in a standardized format. Every ICT vendor contract must be documented with specific DORA RTS fields, including SLAs, exit plans, and concentration analysis.
Incidents must be classified within 24 hours as major, significant, or minor according to the thresholds of Delegated Regulation EU 2024/1774. Without tooling, this triage requires a dedicated team and deep regulatory knowledge.
Concentration in cloud providers (AWS, Azure, GCP) is a systemic risk that ESAs actively monitor. Many entities rely on the same provider for critical infrastructure without visibility into this concentration.
Without an automated system, DORA compliance requires a dedicated team just to keep documentation updated and classifications current.
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
Our DORA approach starts by building the complete ICT Register, including all RTS-required fields: contracts, SLAs, exit plans, criticality classification, and mapping of business functions to ICT vendors. HodeiShield automates the collection and maintenance of this information. For banks, insurers, and fintechs, the scope varies by subsector: retail banks and asset managers require 100% vendor ecosystem coverage; insurers focus on claims data outsourcing; payment fintechs need exhaustive mapping of telecom and database vendors. We tailor the Register to your subsector.
We implement an automatic incident classifier based on EU 2024/1774 thresholds that detects reportable incidents in minutes, not hours. The system generates the preliminary notification for the competent authority and maintains the complete incident file.
Concentration analysis identifies what percentage of your critical vendors depend on the same cloud provider, flagging systemic risk before it becomes a regulatory problem. Additionally, we monitor exit plan status and alert when a critical vendor lacks a documented plan.
Structured methodology for measurable outcomes.
We build the ICT Information Register with all DORA RTS fields: contracts, SLAs, exit plans, criticality classification, and business function mapping.
Automatic incident classification per EU 2024/1774 thresholds. Detects reportable incidents in minutes and generates preliminary notifications for the competent authority.
Identifies cloud provider concentration, monitors exit plans, and alerts when a critical vendor lacks a documented exit plan. ESA-compatible export.
Tangible outcomes for your organization.
HodeiShield automates the ICT Register with all RTS fields, classifies incidents in minutes per EU 2024/1774, and detects cloud concentration before it becomes a regulatory issue.
Discover HodeiShieldDiscovery, execution, delivery and follow-up — a clear path to continuous operation.
DORA gap analysis and mapping with existing NIS2/ISO.
Automated construction of contracts, SLAs, and exit plans.
Automatic classifier and preliminary notifications.
Cloud concentration, TLPT, and resilience testing.
A real scenario of how we work, not a marketing figure.
The cloud provider hosting the core banking platform suffers a multi-hour outage. The ICT risk team checks the ICT Register to see which business functions depend on that provider and its exit plan, classifies the incident against the EU 2024/1774 thresholds, and prepares the notification to the competent authority within DORA's staggered deadlines — with the file already built instead of assembled mid-crisis.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
Talk to our team to evaluate how this solution can protect your organization.
Response within 24h
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.
Hodeitek's team are Spanish regulatory specialists: the National Security Framework (Esquema Nacional de Seguridad, or ENS) is a Spain-only requirement set by Spain's National Cryptologic Center (CCN), not a European or international standard, and it matters if you operate in Spain or sell to its public sector. The ENS is mandatory for all Spanish public administrations and their technology vendors — HodeiShield is the only platform with native ENS, with mapped controls, linked evidence, and automated system profiling.