Turning DORA compliance into business value with Swedbank
In a time when cyber threats and new regulations reshape financial systems, this conversation explores how DORA can become more than a compliance task. Discover how resilience, collaboration and strategic thinking can turn regulatory pressure into long-term business value.
Building resilience through regulation
The Digital Operational Resilience Act (DORA) is reshaping how financial institutions approach cybersecurity and risk management. In this discussion hosted by Implement Consulting Group, experts from across the Nordic banking sector highlight why DORA should be seen as a catalyst for business transformation rather than just another regulatory project.
Lessons from Swedbank’s DORA journey
Sam Graflund Valle from Swedbank shares practical insights from the bank’s multi-year DORA program. By focusing on critical functions, leveraging existing frameworks and integrating stakeholders early, Swedbank demonstrates how risk management and operational resilience can strengthen business strategy and trust.
From compliance to business impact
The panel explores how aligning DORA implementation with strategic goals helps financial institutions gain efficiency, transparency and stronger governance. They emphasize collaboration, threat intelligence sharing and cross-functional engagement as keys to lasting digital resilience.
A catalyst for future-ready organisations
DORA marks a shift from reactive compliance to proactive resilience. By using regulation as a driver for better processes, testing and third-party governance, organisations can build confidence, reduce risk and create value that lasts beyond the regulatory deadline.
Turning DORA compliance into business value with Swedbank
In a time when cyber threats and new regulations reshape financial systems, this conversation explores how DORA can become more than a compliance task. Discover how resilience, collaboration and strategic thinking can turn regulatory pressure into long-term business value.
Building resilience through regulation
The Digital Operational Resilience Act (DORA) is reshaping how financial institutions approach cybersecurity and risk management. In this discussion hosted by Implement Consulting Group, experts from across the Nordic banking sector highlight why DORA should be seen as a catalyst for business transformation rather than just another regulatory project.
Lessons from Swedbank’s DORA journey
Sam Graflund Valle from Swedbank shares practical insights from the bank’s multi-year DORA program. By focusing on critical functions, leveraging existing frameworks and integrating stakeholders early, Swedbank demonstrates how risk management and operational resilience can strengthen business strategy and trust.
From compliance to business impact
The panel explores how aligning DORA implementation with strategic goals helps financial institutions gain efficiency, transparency and stronger governance. They emphasize collaboration, threat intelligence sharing and cross-functional engagement as keys to lasting digital resilience.
A catalyst for future-ready organisations
DORA marks a shift from reactive compliance to proactive resilience. By using regulation as a driver for better processes, testing and third-party governance, organisations can build confidence, reduce risk and create value that lasts beyond the regulatory deadline.
View transcript
Ransomware attack targets multiple organizations, in one single day. Swedish National Bank reports the ransomware attack to the police. This could be one of the worst attacks that Sweden had been hit by ever, said by the Swedish Minister for Civil Defense. Denmark hit with the largest cyber attack on record. The Swedes trust in decreasing is decreasing when it comes to the society's resilience against cyber attacks. So recently there was a speech by a board member at ECB and he said that now we can just consider the cyber risk as being one of the main issues for global security. And the associated annual cost is the mind blowing exceeding of more than 200 billion dollars globally and then without even including indirect and second order effects. And that is just based on what we know. So that is really crazy. And cyber crime is considered as the third largest economy in the world and is run as a professional business. So that is what we need to deal with here now. So cyber security is a systematic risk and hence that is why DORA is coming and we need to get ready for that really soon. DORA ISKALA- Yeah, welcome. Maybe we should say welcome first, Pernilla. Welcome and thank you for joining this webinar. We firmly believe that we have created a really, really cool event where we have invited a very nice and cool speaker that can share his insights. DORA ISKALA- We firmly believe that a regulatory transformation should be way more than just yet another compliance exercise. DORA ISKALA- Therefore, we will try to unfold some of the challenges and also some of the burdens there is when you really want to do or create impact in the regulatory transformation project. DORA ISKALA- And I really hope that Sam from Swedbank will touch upon that at a later stage. At least I will write a question in the chat. DORA ISKALA- The program is relatively simple. We are doing a short intro, right? DORA ISKALA- Mm-hm. DORA ISKALA- And when that is done, the main dish is on the plate. Sam will stand here and do his presentation on the experience from Swedbank. DORA ISKALA- And then we will turn it into a Q&A and panel discussion where we really hope for your interaction. So if you have any questions or any comments, please put them in the chat. DORA ISKALA- And we will try to raise them to the panel to as many as possible. Cool. You have the clicker? DORA ISKALA- Fantastic. Then that will turn us to the next element that we will- DORA ISKALA- There it is. DORA ISKALA- This is the implement team that will host this event. I will start with the presentation of you, Pernille. DORA ISKALA- Panilla is a very, very experienced cyber and security consultant. She spent, what, 20 plus years in the sector working in the sector and as a consultant. DORA ISKALA- Panilla is truly passionate about the diversity and women in technology, but also regulatory transformation in large financial organizations. DORA ISKALA- Yes, this is Klaus. You have more than 20 years of experience working in the whole regulatory industry as well and in financial organizations. You told that you're really passionate about ensuring that you get the most impact out of your transformations and that you're really connected to the business side. And yeah, what else, Klaus? DORA ISKALA- Yeah. Then we have two other colleagues that will join us at a later stage. Thomas. Thomas is possibly the most nice guy you will meet in the cybersecurity sector. He has more experience than I have, so he's slightly older. DORA ISKALA- And he's really into the techie stuff and he will hopefully unburn that in a bit. DORA ISKALA- And then we also have... DORA ISKALA- Luisa. And definitely not least, we will meet her. And she's a great colleague from our cross-competency DORA team. She has 50 plus years of experience working as a consultant and in different line management roles. So she's one of those cool consultants that actually comes with both hardcore legal expertise and also great information security insights. So she's one of those that can really help you as getting the legal assessments and all the priorities right when it comes to DORA and these two projects that we are running with our clients at the moment. DORA ISKALA- And just to clarify, she only has 15, not 50. DORA ISKALA- Did I say 50? Sorry, Luisa. DORA ISKALA- Okay, moving on to the topic and the journey that we all have been on for the past couple of years. Some of us have spent what feels like a decade investigating and trying to understand the upcoming DORA regulation. We have done a lot of presentation and have had a lot of talks on that. Currently, we are in March 24, right? So the clock is ticking. And what we really want to focus on today is how can we really support you in driving the DORA implementation initiatives? Because, well, we only have, what, nine months plus to go. And we've received a portion of the RTSs, well, five in total, and they are truly transparent. But then we are expecting the rest to come before the summer holiday, right? So the clock is ticking. And that's really what we want to put focus on here. How can we really enable that transformation that needs to take place? DORA ISKALA- Yeah. So just a short introduction to the pillars. So there are five pillars in total. The first one is around ICT risk management framework. And it's all about establishing policies, procedures, make sure you have your control frameworks in place, and just efficient processes on how to deal with your ICT risks and how to deal and interact with the management bodies that you have to answer to. And this is also a good opportunity if you don't feel that you are on top of your overall risk management. This is a good time to combine those and get everything right at the same time. Then there is the second one. It's the incident reporting, ICT-related incident reporting. Again, if you feel that there are some issues or challenges with the different type of incidents, it's a good opportunity to look into the overall holistic process. But it's all about getting getting in control of your incidents, knowing how to deal with them and how to report on them, etc. The third one is the digital operational resilience testing. So this is where you need to get into the hardcore test and technology and make sure that you do stress test your digital operational resilience. Then we have one of your special topics, right? The ICT third party risk. So that is all about getting a good understanding and assessment of the risks that are related to the outsourced of the financial services that are working with. How do we deal with them and how do we make sure that we capture any incidents and things going on and make sure that we have proper agreements, not the least, in place with our third parties. The last one is all about threat intel sharing. So there is a need to collaborate in the market and maybe we will hear some more on how that is going on in the Swedish banking sector from SAM. So that's all about how can we share information to at least try to be on top or be in as quick as the threat actors if it's possible at all. But it's all about exchanging information. Yes? Good. We are in one of the privileges of being a consultant is that you have the chance to speak to a lot of clients and really understanding your challenges. Some of the key questions that we meet again and again and I also expect that you are in the midst of solving is really well how can we communicate with the business owners that now we have yet another expensive or relatively perceived expensive transformation project within the regulatory space. How can we get our hands around that and really create the business benefit that we need? And a lot of organizations still have GDPR issues that probably not fully solved yet. We have the outsourcing regulation in Denmark being implemented. We have all sorts of stuff in the in the legacy organization. How are we able to really communicate what are the business benefits of doing this and how can we prioritize this activity compared to other important business activities? I was also thinking about the one we have here in the middle. Here we go again just another expensive and risky IT project. Yeah I've been around for 20 years in the IT tech industry so we've heard that a few times. And but no this is not an IT project. It's so much more than that. It's a strategic business program that you need to get in place if you haven't already established the DORA program. So it's much more than that, right? Another question that we often try to get our hands on around, especially in the Danish banking sector, how can we interact with our key suppliers in this aspect? What's the best way forward here? How can we ensure that that they are ready for us to be ready? And that's a relatively complicated dialogue, but you need to initiate it especially if you are a larger bank in a in the bank central. But that also goes for for the large Scandinavian banks that you really need to get a firm grasp of your key suppliers and really be in control of that journey. And can we truly say that we have strong vendor management governance processes in place on all our critical vendors? Probably not. But that is for sure a journey that we need to undertake. And that also means that this is not an IT security project. This is really a cross bank or financial institution project. You really need to be able to align all your docs to assure that you get all the benefit you need, right? Actually, I had just the other day a challenge from one of the connections in my network saying that so what's next after Dora? So in January 25, she was already there. Where are we heading? How do we deal with it then? Because it's not just a project or a program, right? Sure, sure. But we will come back to that, I assume. Yeah, cool. So that was some of the questions. One of the key fruit for thought we would like to bring to you is really, what if we aimed a little bit higher than just compliant? And I know just being compliant with the Dora regulation is a complex matter. But if we really want to be successful in driving change in a complicated financial organization, well, how can we grasp some business benefits by doing these regulatory transformations? And that's really what we're trying to unfold in the customer dialogues that we're having. How can we make sure that this is not yet another compliance exercise? It's an exercise with the aim to be more efficient and really drive business value. And it could be that there are nuggets in getting a better understanding of your client side or having a deeper understanding of your processes or product. So there are a lot of elements that really could drive business value. So that's really how we try to phrase it in the dialogues. And I firmly believe that if you or I would make the bold statement that if you want to be successful in this journey, you need to make sure that you really can get a cross company initiative in place. But we will test that in the panel later. The reason that I'm pointing in that direction is that the panel are waiting patiently to get into the camera. Good. Pernille, we also have a point of view on this one. Yes, we do. So, I mean, even though, yeah, we are saying and we're emphasizing that Dora is really a strategic initiative. It's covered across the different businesses and a lot of functions are involved. Nevertheless, I mean, in a digital operational resilience perspective, you need to have control over your cybersecurity risks. You need to have control over your information security governance and all that. So I just really wanted to take the opportunity to say that we have like 70 or more experts in the field from very strategic governance around information security all the way down to the very, very techie parts of cybersecurity. And we at Implement, we really want to embrace all our nerds and our inner nerds. We are allowed to be as nerdy as we like. So with that said, I really would like to take the opportunity to invite my dear friend and my ex colleague Sam Graflund Valentin from Swedbank. He will talk more about how they are dealing with Dora. And I'm really looking forward now to hearing what he has to say. Agree. All right. All right. Pernilla and Klaus here in the in the room, thank you so much for that introduction. I took with me that this is the first time that I've been called a cool speaker. So thank you for that. That's really nice to hear. Really, really glad and excited to be here to speak about this topic, Dora. I am Head of Information Security Governor at Swedbank, based in Stockholm, Sweden. So I came here to Copenhagen to talk with these guys and all of you. I will sort of, I've been with this journey from the start at Swedbank. So today I will speak a little bit about what we are doing, what's our approach, what are our challenges in this area, and hopefully capturing some of the key takeaways. But before, I have a script obviously here, but I captured some things in the conversation just recently. So you guys talked about, you talked about why, why do we do this? And I probably will get a few angry comments about this, but it's a regulatory implementation for sure. But being compliant, it's binary. It's on and off. Being resilient is something that we achieved. And the guys just talked about that this is a strategic transformation, and it's something that sort of provides business value, which I think is the key thing here. So what is the promises that we provide to the market to our customers and how can we make sure that we can always deliver that no matter what happens? That's not being complying. That's really about sort of keeping sort of the promises to the market. So I think that's a really important takeaway. So I will start with my presentation and just sort of a quick summary of what Swedbank is, what I come from. So it is one of the oldest banks, probably the oldest bank in Sweden then, except our central bank, which is the oldest central bank in the world, by the way. It's really a wholesome company that has sort of a socially engaged roots since way back. It's a huge bank. We're one of the largest retail banks in all of Nordics and the Baltics. We have four main markets. It's Sweden, Lithuania, Estonia, and Latvia. And then we have offices all around the world. So, I mean, this is a huge financial group and we are systemically critical. If we go down, the rest of the financial systems within the markets that we operate will also go down, most likely. So, this is me then. I've been at Swedbank for almost four years now. So, throughout my career, I have had sort of one foot in technology, one foot in business. Some would say I might be willful or indecisive, but to me, it's more about having sort of a sense of disposition, if you like, and an urge to try to understand the system and the context of sort of what I do, where I work, and what it is that I'm trying to solve. I'm an ex-Stockholmer. I live in the countryside now, but Copenhagen and Denmark, where we are now, is close to home, being in southern Sweden, close to my heart. So, really glad to be here, as I just said. So, as I said before, I was with Swedbank from the start when I was one of the people that initiated this program in Swedbank a couple of years back. And it's a journey, and it's going to be a journey. We've had a few of these RTSs that were mentioned just being sort of adopted last week, and it's more coming in the pipeline, and we're all very, very busy. I think talking to peers, talking to consultants, I think some of the things that Swedbank has done really well, starting off quite early, is to bring about multiple stakeholders. It's not only security. It's not only IT. It's not only compliance. So, I think that has been an early approach that we have adopted, and it continues to be a part of where we are now and where we are going to be going forward. Another thing that I think is important for us and for many of the financial institutions and third-party service providers that are affected by this, is that it's not necessarily something completely new, but we do have a lot of good things in place already, and let's reuse that. Let's adopt that. We don't have to build a completely new framework. We don't have to build new programs, but let's use what we've got, and that's been one of the key things that we've tried to adopt at Swedbank. All right, but we also have challenges, of course. And I'll tell you about a few of them. Number one, we have plenty of ICT third parties, and so do most of you guys, too. And it's a lot of controls that need to be amended, and it's a lot of agreements that need to be reshuffled, and it's a lot of stakeholders that we need to interact with. It is a tedious task. We will get there, but it takes a lot of effort from many of us. Another thing is what I just mentioned, which is a success factor on one hand, but it's also a challenge, and it is all the internal stakeholders. Who is accountable for this? How are we dependent on that? Who makes those decisions? What's first line? What's second line? And so on. So I think we're getting there. We're coming together in this group of a lot of different stakeholders from across the group, but it's not easy. Secondly, we're a big financial institution with a lot of different products, subsidiaries, and that legal structure and matrix structure or group functions and business areas is not easy. And I'm sure particularly the larger financial institutions can recognize themselves in that. Thirdly, external stakeholders. And I'm not only talking about regulators and customers, but we actually, and many of us large financial institutions, we also provide IT services to some customers. So we are also need to look at ourselves as a night ICT third party service provider. And not the least, many of our even financial services customers, they also sort of are affected by this, and the relationship towards them will most likely always also be affected. Number four, CIF, critical or important function. So in the conversations that we have with our peers, this is really hard not to crack. What is it? Is it a process? Is it a product? Is it a unit? What do we make of it? And we're going to map it to all these different things. How do we do that? So what is this definition? What is the critical or important function? We spent quite a bit of time on that, and I mean, we have sort of settled that, but it's still going to have to be implemented and operationalized. Secondly, these different entities that has to be mapped and dependently mapped, registered, classified. How do we deal with them? What is criticality? And how do we deal with that to drive efficiency and to do good risk management? And lastly, resilience. Again, stakeholders. We really need to acknowledge that resilience is greater than all of us. Sort of, it's the sum is greater than however you phrase that saying. But what does that mean? Does that change the way that we govern our bank? How we make decisions? How we prioritize? Probably, but that will take some time to settle. But we know that it's not going to work as we do today. All right. So one of the things that I would like to mention is how we are implementing this risk management framework. And Dora is quite clear on that. Sure, it's risk management framework. But actually, it's the broader internal governance and control structure and other governance arrangements. So framework-wise, we talk about three main things. It's the risk management system. It's the frameworks or capabilities that make up ICT. And it's how we strengthen our overall governance in the financial group. Again, it's not only IT. It's not only security. But it's going to affect all of these aspects of how we run this financial institution. For example, if I support a critical function, what does that mean in terms of I mandate, how I can challenge the rest of the organization, how I report? Just as an example. All right. So I'd just like to talk a bit about the core that is very close to my heart. And it's this phrasing in Article 5.1 and Article 6.1. And it's really about we become digitally operational resilient if we do risk management in this way that Dora talks about. So, again, it's not necessarily a new framework. It's how we do risk management that makes us become digitally operational resilient. And what is that, this thing, this type of risk management? Well, you recognize it from Dora. And it's about talking about risk management across these risk management functions. If you're a security professional, you will recognize them from this cybersecurity framework, for example. But really, it's a way to look at how we do risk management. The second thing is this diligent detail to what's critical, really to drive risk-based risk management. Skip the rest. Skip the far end of the long tail. Focus on high-impact things. That's where we get most bang for buck. And that needs to color everything that we do after that. It also talks about severe but plausible scenarios. Focus on the top things that are sort of the most severe for your organization, for organizations dependent on you, and for the financial system. Thirdly, third parties. Third parties, it's not something separate that we deal with within procurement. Procurement is a very good and important group function. But third parties, exposure is in information security. It's in BCM. It's in IT. And so on. So it needs to be a part of all of those other frameworks or capabilities as well. And the last one, the vigilance and detail to testing and validation. And not only digital operational resilience testing, that is, threat-led penetration testing and those technical tests, but also simply validating that the plan actually works. A business continuity plan, for example, or an incident response playbook, for that matter. So, by doing risk management in this way, we become digitally operational resilience. What about these functions, then, that many of you security professionals at least recognize from, for example, this cybersecurity framework? Well, we like to think about it that, we think, actually, Dora is quite clear on that the governance aspect or the framework itself is owned by a second line. Many of you will debate that, obviously. But to put it simply, the risk management function in an organization runs the risk management framework. And these risk management functions or capabilities are provided by first line of defense. So, in first line of defense, we are the ones that identify what's critical, what are the risks. We are the ones that build walls, protect our organization and assets from compromise. We are the ones that provide detection capabilities, respond to incidents or attacks, and recover our operations. And collectively, we are the ones that learn and evolve. So, the last one, actually, is a bit peculiar, for that matter. To us, it really seems like this is a risk management function or capability that we need to monitor and develop and measure over time. It will be interesting to see how that develops, how that is a part or a central part of how we do risk management. But it's quite natural, really, that a part of being resilient, ability to adapt, and a core part of that is to learn after things have happened and improve. So, from me being a security professional, middle management, I mean, we obviously engage with decision makers and top management and board. So, these are the kind of conversations we would want to have with those types of people. We don't just want them to say, are we secure enough? But we want them to ask us, so can we identify what's critical? How well do we recover from that type of incident? And what have we learned based on what we knew last year? So, what we're trying to say is that we really think that DORA, again, it's not necessarily something new, but it's a shift in how we do risk management. And by doing risk management in a certain way, we become resilient. Now, I've said it probably five times. All right. Oh, we have a little animation as well. So, let me try to be a bit pragmatic here then. So, let's think about a couple of scenarios. And most of you recognize these ones. It could be applicable to more or less any organization, not necessarily a financial institution. But you all recognize them. You all report them. You measure them. And you test them. Good. So, what's resilience in terms of these scenarios? Well, let's ask DORA then. So, DORA tells us that in order for us to measure or talk about how resilient we are, we need to understand how well do we identify again? What's critical? What are the dependencies? Which are the risks to this particular function? How well do we protect, detect, respond, and recover? And that's easily applied through all of these scenarios as an example. So, what we would see if we would measure our ability to manage risk towards these set of scenarios, we also would be able to talk about how resilient we are in the very same sentence. Again, by doing risk management in a certain way, we become or we can understand how resilient we are. And this is just an example of how we can talk about it. And there's plenty of things to say about this. But this is how we, in Swedbank, are trying to talk about what does it mean and how do we know if we are resilient or not? And I said a couple of times, and the colleagues before talked about it, it's not only about cyber security. And these are some of the capabilities that we work collectively with in Swedbank. And these are some of the capabilities and functions that we and you all need in order to become digital operational resilient. We need to understand our IT environment. We have IT processes, IT operations. We need to understand information. We need to do risk management in a certain way. We need business continuity plans, playbooks, good interest response, crisis management, and so on and so on. And all these different functions, they actually contribute to our understanding of how well we do ICT risk management. In terms of identifying, protect, detect, respond, and recover. So we can go back and use these scenarios that I talked about. So what I'm going to show you now, again, might be debated by some of you in the crowd. But to put it simply, the group functions, let's put it like that, that I just mentioned, each contributes more or less to different risk management functions. And this is what we mean when we say that resilience is above each and every framework owner. That's what we call ourselves, by the way, in Swedbank. So collectively, we can provide the resilience capability. And collectively, we need to understand on a group level what are each of these functions contribute to, let's say, an ICT third party compromise or an infrastructure outage for that matter. Again, it's not only information security. It's not only a business continuity plan. Understanding, for example, how well we do business continuity. It's not only about we've done the BIA, for example, and we've invested in these measures and we've built these plans and we've tested them. Sure. But can we deal with a ransomware attack? What's going to happen in a state of high alert when the society is getting ready for war? What's that for business continuity? The same goes for IT operations. So let's say we have a change incident, for example, which obviously we have IT processes. We have change management processes for that, to do that in a good way. But what about continuing IT operations following that type of event or during that type of event? Yeah. So for each of these scenarios, we identify risks. We build specific protective and preventive measures. We build particular detection rules and policies so that we can capture them should our defenses not be successful. And we build particular structures and playbooks to deal with them in a swift way. And we test our recovery plans should they occur. The colors in this, let's call it dashboard or visualization, would sort of reflect our level of resilience towards these scenarios. And obviously, the result is validated by proper testing and validation, being it technically or organizationally. Because we want the board of directors and top management to really challenge us and say, well, do we really know that this is green? Can you prove that this is green? Yes, of course. We've done this test, right? Or we've done this assessment or we have this attestation for that matter. It's not only us guessing. So I think when the regulators ask the board of directors or management body, as they call it in DORA, to be more proficient in security, that's the type of questioning we can expect going forward to be more challenged in a good way. So maybe I'm quicker than I should have been. I'm on time. Fine. All right. So some of the key takeaways then. We really think that DORA is a catalyst for business transformation, as our colleagues just said. It's really about, for SpedBank, it's really about delivering on our promise to the market and to our customers. It's intrinsically a part of our DNA, our value and strategic direction. We really, really think that the catalyst is the attention to what is critical, forget the rest almost, and really to do risk management in a certain way and talk about risk management in a certain way so that we actually become resilient or know whether we're resilient or not. The second thing that I'm coming back to a couple of times is that it's not all about security. Sure, the main driver of DORA is our increased dependency on third parties, increased digitalization, the increased interdependence between financial entities, sort of the pervasiveness of the systemic cyber risk. But it's not only cyber. There are others that need to do the job or we need to do, for my sake, good information security. I can't do it alone. The third thing is how do we know whether we are resilient or not? It's not a separate dashboard. It's within the existing way to do and report on resilience, security, IT and risk management. It's cheaper to do and exercise and then test than to be hit by, let's say, a ransomware attack. So let's just do it. And segue to the last one then. Ransomware eats framework for breakfast, which I'm not too keen about being responsible for governance and being responsible for our frameworks. But it's the truth. It doesn't matter how many policies and procedures we update. We need to know now what's critical. We need to know now. Can we deal with this type of event? And if we don't know, then let's fix it. And we can fix the policies and documents at the same time. But those are less important. Because the latter thing, being resilient, that's about delivering value to our customers. And I think that's the last thing I will say. Thank you for this time. Thank you, Implement, for giving me this opportunity to talk about, well, for me to speak. Well, then for me to talk about Swell Bank and what we are doing when it comes to Dora. Thank you so much for that nice introduction to how your Dora journey and approach is. Thank you. And while we wait for some good questions from our audience, we have a few. But I just really want to know that if you could do it all over again, what would you do if different? If you would do anything different? I think maybe the last thing I said. I think as many organizations, I think we started off. What do we need to do? What policies, procedures, what investments do we need? And that's important. And I think as time has went by, we realize that actually we know what's critical. Let's have a look at that and see how we perform in that area. Okay. So I think if we would have done it again, I think we would have need to spend more time on that. And I think that would be- On scoping, do you mean? I think on scoping and I think, as I've said in the keynote, focusing on what's critical. And I think if we would have done that from the beginning, I think it would have saved. It would have been more efficient, actually. Okay. Yeah. Really nice. That's what we hear often, too. People want just to get ahead and start doing. But if they actually stop up and look at what's the best risk-based approach to this, they might have gotten about it easier. Yeah. All right. But I've got some good questions here, so I'll just read the first one to you. Would you use DORA as an opportunity to get more comprehensive view on criticality beyond the cyber resilience regulation? A little bit of background. I'm thinking particularly about payment service providers who might choose ICT risks due to API connections and sanctions risk in payment flows. Or who might pose ICT risks, of course. I'm not so into payment regulation, but what I can say is that one of- Well, that's actually a success factor, I think, when I think about it. We've really tried to approach critical or important function on what is a function. Yeah. And what's critical function in X, Y, and Z regulation, because there are many. Yeah. We have outsourcing arrangements from EBA. We have a resolution in recovery planning and PST2. We have N-I and so on and so on. Yes. So we've really tried to capture that. So what's a function? Yes. And how can it be critical? In different angles. So try to describe a function in relationship to our internal operating environment, regardless of the regulation. So answering the question, well, yes, you know, sort of capitalize on what it is trying to say. Prioritize what's most important and critical, regardless of what it is. Absolutely. Really nice. Another good question. You got a lot of clapping and thumbs up here in the chat. That's why I'm scrolling up and down. Next question is, there is a writing in Dora that companies should assess their critical third parties for environmental and human rights aspects. How would you regard this criteria and how far, how deep would you do this analysis? I haven't read that paragraph, to be honest. But I know that we have a very mature way to deal with third parties in which ESG types of risks are a centerpiece, same as security. So I would be very surprised if we haven't dealt with that. But I think actually maybe that area of this regulation is probably a bit ahead of the curve compared to the rest of us. Okay. So we are dealing with it. If exactly how, I cannot really respond. But maybe it fits into this whole data ethics agenda. Yeah, absolutely. Absolutely. All right. Cool. When deciding between using a supplier's digital operational testing services or building an internal testing environment, what factors should you consider? How do you weigh the benefits and the challenges of each approach? I think like this. Well, we're a large financial institution. Many other large financial institutions probably have their own offensive cybersecurity function. Smallers probably don't and probably shouldn't, to be honest. It's many, many smaller organizations. They buy other security and IT services. They outsource them. This is a way to build resilience or redundancy yourself. So I think if you don't really have to have it internally, you shouldn't. No. It's more effective to buy it, I think, to be honest. And it can be a huge internal cost as well. Absolutely. And it's hard to maintain, to attract and to maintain resources. Absolutely. So it's nothing. I really don't think it's not you need to have. All right. What is primarily different between, I suppose it should say DORA, but it says Nora, and some of the other regulations that have come in recent years, and how have you identified the difference? So how is DORA different? Well, it depends on what angle you come about. So if we're talking about resolution, I think resolution has been really focused on what's sort of, well, it's similar because it talks about critical function. It talks about our promises to the market or what someone tells us this is important. Yeah. And it talks about operational continuity. So from that perspective, those two regulations now are becoming sort of closer in how we try to look at them. Yeah. And then when it comes to EBA ICT, for example, being a bank, this is just a continuation, I think. So I really do think this regulation we have regarded as being a lot broader, as I talked about in the keynote, while it's more or less the same topics as EBA ICT. Yeah. So from that perspective, it's a program. It was not a program before. Yeah, because DORA is sort of the umbrella for all of the different sorts of types and regulations that we've been exposed to. And when it comes to, well, then obviously another regulation was GDPR. Yeah. But that was before my time. I know it was a big program at the time. And there are probably sort of leftovers for that as well. But yeah, that's what I can say. Yeah. I think with GDPR, a lot of stuff was new. Too many companies. Yeah, absolutely. With DORA, we are building on a lot of fundamental pillars that actually needs to be broadened and more detailed. Yeah. And compared to GDPR, I think actually it's about being risk-based. It's about you need to dare to make decisions and prioritize. And I think that's just simply risk management maturity. Yes. Being able, having the accountability and feeling the need, you know, I have to do that, so to say. Yeah. Absolutely. Yeah. Not Nora, but DORA. Have you leveraged any existing classification model when designing your model to classify CIF? For example, essential processes based on your processor. Well, I think we had a conversation in the Swedish Bankers Association in December. And we try to see that there is definitely similarities with how we do business continuity and the BIA, business impact assessment. It's maybe not the BIA, but we really think that the concept needs to be applied, sort of BIA on a function, if you like. Yeah. So the previous or historical focus on processes has been important because it has set the foundation for what's material and what's significant and so on. But this time around, I think there's a layer above process. So more talking about the outputs of a process, the products. Yes. DORA talks about processes being supporting to functions. Yes. So definitely capitalize on that. I actually think what we've seen is that we've tried to lean on the CIF definition and then lean on what's critical from a resolution perspective, what's critical from a BCM BIA perspective. Yes. And what other important functions do we need to have to maintain our license to operate? Of course. So I think we know what's critical more or less. Yeah. Yeah. Yeah, really nice. Let's see. I have another question here. Is DORA favoring the bank to adopt more software as a service models for software delivery or rather relying on the do-it-yourself model? I think neither. I think it's about the business strategy. Yeah. Are you a cloud-first strategy or sort of how mature are you in that area? How you build your stack and your infrastructure? I think it has nothing to do with DORA. Obviously, I mean, well, bad cloud security has nothing to do with the cloud vendors. It's about how we configure and set those services up. So it's really about the maturity of the organization and the strategy, I think. Could be something about size, too, maybe. Absolutely. Absolutely. But, yeah. But then again, yeah. Now we have all these new cool AI services that I think more or less any data scientist will become a SaaS developer more or less. So I think that's something to look into as an organization. You know, it's easy to configure and set up small services. And that's actually a SaaS. And we need to deal with that from a DORA perspective then. Yes. Very interesting. How do you anticipate the implementation of DORA's threat intelligence sharing requirements will transform the cybersecurity landscape for financial institutions? And what challenges and opportunities do you foresee in fostering a culture of collaboration while ensuring compliance and data protection? That was a large one. I think it's easy to forget that in this learn and evolve, by the way, it's a big chunk of threat intelligence there. The ability to sort of consume those data feeds and improve yourself from outside in. So that's not to forget. When it comes to information sharing, first of all, it's voluntary. Secondly, I think I had it in my intro slide. We do that really well in Swedbank. Yes. We have established communication channels, public-private, with the sector and with a few other peer banks that we work really close with, namely Handelsbanken and SEB that sort of name their names, which is a quite public thing. So, well, I think, well, it's a capability that we can measure from a board of directors perspective. How well do we do information sharing and how do we excel in that? Yeah. And maybe it's not necessarily, well, in my experience, it's not necessarily between the incumbents or participants of the market, but maybe more so between private and public. Yes. And how that works, so to say. Sometimes the supervisory authority is on the receiving end. So how open do we want to be there? Absolutely. So for you as a big bank, it might be quite simple because you have some setups around you. But what could smaller institutions do? Yeah. Well, I think, again, Swedish Bankers Association, where we are quite an active part. And I think that's a really good, where there's an information security group, for example, and other topic-specific group. And those sort of industry-wide, potentially trade union or trade organization-driven or publicly-driven forums would be the way to go, I think. Because then you can sort of piggyback on the larger institutions. Yeah. And that's a nice model. And then we are back to maybe some compliance about data protection and that sort of stuff. But I foresee that they'll be scrutinized as well. Absolutely. All right. Let's see here. Is Dorof? Oh, no, that was the one. Could you give an example of what functions you classified as critical? I spoke about in the earlier presentation that we're a large lender. Yes. We're a large entity in the payment system. So payments, obviously. We're the largest card issuer. So we have the largest deposits. So savings. Yeah. So those are four. And it's not a secret. So in that area, obviously. And I think for an organization, too, I think what we need to think about is what's most important to financial stability. So at first glance, we might want to prioritize something that affects the most number of customers. Yeah. But actually, that's not what might be the most critical. It might be what we provide to, let's say, certain types of government agencies or other financial institutions. So honestly, I think some of, particularly us, larger organizations have something to think about. What's most impactful? And really considering impacts on others and the sector in doing that prioritization. So that's also sort of a shift inwards to outwards, so to say, that this will bring about, I think. Back to the risk-based approach to society. Yeah. I'm not sure we do have time for any more questions. Do we have a final one? I will be quick. All right. Have you defined the risk tolerance for ICT risk? We, as a large organization, we have a mature risk management function. And we have a mature way to do risk governance, which means we have defined risk appetite statements and metrics and limits and so on. Yeah. So that we do have. Sure. We don't have it expressed as an ICT tolerance. Okay. Yet. I'm not sure we will even, but maybe that's just a reporting packaging. Let's see. Okay. Thanks a lot, Sam. That was it for the questions from the audience. And now we'll move over to our panel discussion. And we'll invite Thomas and Penilla to our little lounge area here. Thank you for a great presentation, Sam. And Pernilla for the introduction. I come to think about when I heard your presentation, you more or less in between the lines said testing is the new black. What do you mean and how do you organize the whole testing regime in Swedbank? Well, I think again, as a large financial institution, offensive cybersecurity is a big part of how we do security. And testing, I think it's not only for the security function. I think it's quite broad. I mean, this is a risk management framework. It cuts across sort of all three lines of defense. So the way that we are trying to approach digital operational resilience testing is that from a security perspective, we've been quite mature. We have a function, we have a program, we do it on a regular basis. We do red teaming and so on. And I think now it's about extending that to other means of testing and putting it together. So these are the set of testing capabilities that we have to really validate whether we are resilient or not. So that's sort of what we are doing now. Again, we have plenty of in-house capabilities, but on occasion we might use externally as well. And then we're challenged by our control function called control functions and external parties as well. So I think it's not one thing. It's a toolbox really. And it's a risk-based toolbox for a particular type of risk, a particular type of control, a particular type of criticality. It might call for a type of test or a type of advanced or complexity of tests. So I think, again, being an engineer, I really think of it as a matrix, like a scoring matrix that sort of, for this particular thing and this criticality, this is what we do and this is what's expected. And then the control function could say, well, you said you were supposed to do this, but you haven't done it. So, well, it's planned next month or whatever. But do you also test your organization and their capability of reacting? You mentioned ransomware earlier in your presentation. Have you tested the ability how to do communication externally if you're hit by ransomware, as an example, or how high in the organization have you tested the ability to communicate areas like that? Yeah. Because that goes all the way up, right? Yeah, I think it's a good point. And I think we, I mean, red teaming, for example, it comes across as something very, very technical. And that's just one piece of the puzzle. And testing sort of the broader scope of resilience, we do. We test our crisis management teams. We have several crisis management teams. We test them on a regular basis and including these types of scenarios. And also, well, we test our business continuity plans. But what I do really think is sort of the shift as I came back to, these are different pieces of the puzzle. And I think we can be a bit better, to be honest, to put these things together. Let's say, let's put it in identify, protect, detect, respond, recover type of way or a scenario timeline type of way. So now we do this. We can protect here. But how do we deal with impacts and customer communication and so on? I think that's what we can do a bit better. And I think most can to, you know, paint the whole picture. Interesting. Samar, I was thinking about, listen to you when you spoke at the conference with the national cybersecurity team in December. And you were on stage with the other, two of the other big banks in Sweden. Yes. And I know you talked about it a bit earlier, but could you elaborate a bit more on that collaboration and what that has meant for, you know, for your work and for the industry itself and how you collaborate among the big banks and in the wider community in Sweden? Well, I think, I think it's, there are a couple of forums that we have in the sector for various reasons driven by different, you know, organizations. And we're, we're a part of that. But then I think it started off as, you know, following a couple of incidents and people met. Like, what happened over at your guys? You know, what did you learn? And sort of, let's change numbers. I think that's how we started a couple of years ago. Yeah. So it started off as something informal. And I think, I think last year, there's, there's a proper agreement and it's a part of each of these three organizations security strategy. Right. To build on this, this relationship and it's, it's an operating model. We have a steerco. We have operational sort of collaboration teams and we produce white papers and, and so on and so on. So that's how we, how we operate now. And we try to, to some extent, we will talk about it as I did and I do now. We talk about it in different contexts and then at times we share it with our peers that are not part of this exclusive club, so to say. So to say. But I think it's also, we're culturally, we're, we're, we're the same size. Yeah. We're sort of quite similar culture and it's also about people fit, I guess. And I think there are plenty of forums and constellations that we could use. But at this point in time, I think it's most value for money in this constellation between the three of us for now. And, well, one of the successes of, of what sort of the results of that has been that we have played a prominent role in establishing what's called financial forum. And which is one of the forums that is built by National Cyber Security Center for different sectors. So what have we learned in this sort of triumvirate of these three organizations and how can we capitalize on that on a sector level? So it's been quite good and we, we improve it and we talk about it. I think other sectors are, you know, jealous to be honest. Yeah. So they are looking into how you're doing it. Yeah. And we're, we're, we're, we're, we're sharing, you know, happily. Of course. Yeah. I mean, is, is there anything similar in Denmark? I, I just realized that we have a Swedish and a Danish side there. That was unintentionally, but is there anything similar? It's the bridge here. Yeah, yeah. I love the bridge. I have it on my arm. I can't see. Yeah. Is there anything similar? How, how, how is the Danish? On, on sharing. Yeah. Like, like having that type of more like formal collaboration. We have the formal collaborations as the NFSERT, but that's an order in collaboration. So I think there might be some sharing, but it's not formalized in the way that you have it. Yeah. Not, not even close, I think. Yeah. And especially, a small and medium sized financial companies, they are looking into how can we actually come about this thread and tell sharing? Should we become a member of NFSERT or should we do something else? So this could be a school book example of how to, to, to share knowledge. Because I think that's one of the issues in the industry in general. We have not been very good at sharing knowledge because we had an incident. We better have it behind closed door because nobody needs, needs to know, right? And then that's, but, but we need to know. We need to share in order to be better at mitigating those risks. Yeah. I think a part of the national security strategy or cyber security strategy for that matter, I think it's the same, more or less the same in Denmark and Sweden, I guess. And, you know, it's about protecting what's critical and so on. And another thing is probably about protecting the citizens from being fraud and so on. And the third one is probably about, you know, all small and medium enterprises. And for the financial sector, let's say, talk about the smaller financial institutions. Yeah. And it's very easy for a government to say that this is what we want in the strategy. Okay, so what do you do about it? And what do you want to achieve? And what do you invest in that transformation, dear government? And one of the things for the financial sector could be, so how do we make it easier for all these small enterprises to tap into threat intelligence, to be able to test properly or to detect and respond in a good way? Yeah. How do we help them to build that capability? Because that's of national security matter. I really think so. Why don't they subsidize threat intelligence services? Yeah. And it's a good question. I think it will maybe become easier for smaller financial institutions because right now it is difficult. Yeah. But now it's also becoming regulated. Yeah. So something must happen. And it will be interesting to see how they go about it. Yeah. No. I mean, it can be a really smaller financial institution without being a micro enterprise that only has to deal with a simplified risk management framework. So it's quite tough. Yeah. And how do we deal with that? I think it's really for something for the governments. Yeah. And the agencies to think about. Because I think we talked about it last week, Thomas, around just if you're a smaller actor on the financial market, you are, you have maybe a huge dependency on the financial market. You have to see to your suppliers that are providing a lot of services on both technical and products and application level. And how do you go about with that then? You know, the whole threat intel and gathering the information you need. And I mean, if you get most from your supplier, how do you go about with that and what can you do? I mean, I guess that has been up for discussion a lot in your team, right? Yeah, we are discussing a lot in our cyber tech team also and also related to the whole testing, the digital resilience testing program, which is supposed to be threat led in the future. And I know that a lot of the smaller medium sized FS companies, they're really struggling about that because they have not been used to working on the type of framework as you are. Yeah. So that whole scenario based pentesting is something new to them. Yeah. And I listen carefully to what you answered for before on one of the questions outsource or in-source. Definitely for the smaller and medium size, I would say outsource to a strong technical partner that can help on taking all these threat intel and turn it into a threat led penetration based testing program. Yeah. Because you cannot, you might be able to find one or two resources that will help you internally, but in the longer run they will probably go for more, you know, say larger teams where they can cooperate with the, can say, peers. So what do you think about that? No, but I think, I think, I just remember just speaking last week with other sort of security leaders in a session like this almost. And they were private organizations and they were public organizations and one of the public organizations, a few of the public organizations, they were equally the size of Swedbank in terms of employees. So what do you do about threat intelligence? We don't do it. We can't afford it. And they have definitely critical services provided to society and they do a lot of important stuff. They, we can't do it. We don't have the money. We don't have the funds. So how, what will you do? Well, I think, I mean, not everyone needs to be best in class and there's plenty of open source material that you can sort of capitalize on and use. So I think that's maybe the first step before you hire someone when it comes to threat intel. Yes. You can definitely utilize that and I mean train yourself from the, to start off with. And if, if you don't become better, you know that you don't become better than you, you need to think about, okay, so how do I purchase this? So, but when I really think there's a skills shortage and it's four, we'll lack four million cybersecurity professionals globally or whatever. At least. Something like that, right? And, you know, we can't fix it. No. And we need to deal with it in another way. Well, first, other people need to act more securely within our organization. We need to train them to be more secure, right? And secondly, we simply can't do it. Then we need to sort of think about where can we acquire that type of competence and capabilities elsewhere. Yeah. I think Dora is for many upscaling what they, I mean, on capabilities and skills that are not really in scope of their organization at the moment. Yeah. So either they need to outsource more, hire consultants, external help, or they need a different business model. Yeah. Yeah. Yeah, exactly. I mean, we cannot, we will never solve the skills shortage gap. I'm 100% sure. Then it's a different way. Absolutely. Completely agree. But maybe it's for the small and medium sized financial services companies that are being better at setting the requirements then to partners, outsourcing partners, being it within or testing and so on. And that could potentially be something they should focus more on. How can we set the requirements for our type of business? Yeah. And then through that, go and find the right partner in the longer run. Apparently according to Dora, you might have heard third party management is quite important. Oh yes. Yeah. So yeah, but it's really tough. It is. Yeah, it's really hard. But then you have to be critical about the proportionality. Really looking into how much do I actually have to implement? Exactly. Being the size and complexity I have. Yeah. So I think that's going to become a very important factor for the smaller organizations too. Yeah. And I think you, Klaus and you said it before, it's about business transformations and I think proportionality. Yeah. It's the same thing. You know, what is my objective? Yes. Which are my objectives? What's important? That's what this needs to be about. Really? Yeah. It's all about that connection and we have been around for a while in the industry. I mean, it's been such a shift from, you know, sitting in a server room, a computer hall somewhere, talking to technicians, you know, moving into the board rooms now. And I know you have a very active board and you have a senior management that are really into cybersecurity. And how has that been, you know, their development? I mean, not that you should like give a rationale on that, but just, you know, how has that changed over the years? I mean, you've been working a long time in the industry as well. How have you seen that shift, you know, coming from a tech side into the more strategic side and get it really up as one of the top strategic risks? No, but I think, I mean, well, they'll read the news and we talked about risk management maturity previously. So I think that's another thing. And thirdly, I mean, we have been quite vocal as a security function. So I think since I started in 2020, I've seen a shift in, you know, how we interact with them, report and talk and the questions that we get asked. So, I mean, it's just an expectation. And just, I think last week or two weeks ago, ECB had this paper and that said that all organizations under regulation from ECB are expected to, you know, have at least one person with cyber proficiency. Yes, it's for ECB, you know, regulated entities, but I think it sets a precedence for what's expected. So it's just going to be, it's a KPI. Yes. Do we have it or not? Yeah. Can we prove that they are, and Dora is like that. So I think we've seen a maturity and, you know, they challenge us before the nice slide. Now it's like, what do you mean? How do you know it's like this? What about this? So we really welcome that. And it's a really active conversation for sure. So that's basically an acknowledgement that cyber risk is becoming a business risk, right? Absolutely. So do you see Dora becoming a business benefit then? You know, having this holistic view on the processes and functions and getting the complete overview and, you know, the work you described you've been on or the journey you've been on for the last few years. You've tried to map out all the critical functions and systems and so on. Do you think in the longer run there will be a business benefit to it as well? Yeah. I think, I mean, I think, identify. That's operational excellence to me. You know your internal operating environments. You know, your drawer is in order. Yes. You know, that's efficient. You know, you don't have to look for today I want yellow underwear or whatever. It's there in that drawer. You know, I know. So that's, to me that's operational efficiency, excellence. And the second thing is that, as I said, we try to tap into resolution, EBA outsourcing, those, the work that has already been done, very good work. And try to not create something new, but sort of, okay, so how does this fit the picture? So, I mean, that's efficiency as well. And I think another, a third thing is sort of, now we really need to get rid of these old, you know, machines that are running over here, right? That's also efficiency. He's old machines. He's old machines. We really need to get rid of these old machines now because they expose us and they would jeopardize X, Y, and Z sort of ability to create, you know, result in a business disruption. So I think that's another, that's cost saving, I think. And if we are able to talk about the tip of the iceberg, the crown jewels of what's most important, then simply our risk mitigation will be cheaper, really, and more efficient. More bang for buck. It could be a funny calculation if you, on the hindsight, once we are on the other side, right? Absolutely. We could have done some calculations. Yeah, what's DORA ROI? Yeah, exactly. Oh, yes. Because maybe there's also a potential in optimization of the third parties. So, because when we talk to a lot of clients, they are really struggling who has the responsibility or who owns the risk of when the X, Y, Z. And, you know, just getting that overview of that and potentially use that as a leverage when you negotiate new contracts or SLAs. Do you think there could be some cost savings there or at least improve resilience then at least? Yeah, but I think. You will be better at setting the requirements. Yeah, but I think if we think about the DORA ROI and then, I mean, we are a large financial institution. There are smaller ones like we've talked about. But let's say where I come from and represent a large one. We have different business areas and group functions. We have different legal entities. We have, I guess I said before, quite mature approach to third party risk management. And then we have improvements to do in that area obviously. But giving the fact that we're so sort of distributed, we might have the same, you know, for one service, we might have multiple suppliers. Right? Which is, you know, not cost effective and it's driving our risk exposure by definition. So, absolutely it can sort of save money in that area as well. And I think it's going to be because just shortly, some of the things that we can see that this thing is improving. I mean, what are the type of vendors that we have? And what are the type of services that those vendors provide? Just that understanding and seeing that landscape. I think DORA will help us to, you know, just clearing that picture out. It's a bit blurred now and it will be more crystal clear. And then we can say, I imagine, I simply just imagine by the end of the year or next year, we can say, you know what? These 40%, or 10%, I don't know, whatever. These ones are redundant. We don't need them anymore or we might need them because of redundancy. That's a different type of strategy. But I think definitely that will be the case. But looking into simplification. Absolutely. For sure. There is a lot of streamlining or opportunity to streamline processes and get connecting the dots because I mean, I know that many, many are struggling with that. I was sitting here thinking a bit about, I mean, I know that there are big and smaller companies out there in both sides of the bridge that are maybe a bit sweaty now because they know that they're not really compliant with current ICT and operational risk regulations. And now DORA is coming and needs to and there are a little, much, much stuff coming their way. So what? I mean, you talked about training, talked about talking to the boards, get them to understand that this is the time. What would be your advice? I mean, I would like to hear advice from all of you. If you're sitting there, okay, we are not really, we don't have stuff in order from current perspective. So how will we get to where we need to be in January next year? Where do you start? Use a gap assessment template that is probably provided by a public, private or some sort of organization that's free. Start there and take the regulation and put it on a timeline and start sort of from the beginning. And I'm not meaning the framework because that's complicated. Start at eight, identify, think about what's critical and then build from there. Then you can do the framework later on. So you would do the gap assessment risk based, not from one end to the other? No, I think I will do the assessment, I think end to end. Yeah. But implementation wise, I will start at risk based. Absolutely. That's what I mean. All right, cool. Where do you see Sweatbank one year from now? One year from now, I think we will be busy doing some pretty, well we do testing already. Yeah. I think we will do some pretty cool testing in a year from now. And we're probably a bit anxious about the supervisors knocking on our door. Yeah. Are we ready for that? Yeah. I mean, I guess they usually start with the larger organizations. So I think that's what we will be ready for. All right. And do you have any interpretations or guess work? What will they ask us first? Are you preparing some documentation for them or your gap assessments or your strategy, your plan? Are you preparing stuff for the authorities? You don't have to tell in detail of course, but do you have some sort of strategy towards demonstrating compliance? No, but so, I mean, the authorities, I'm sure they have already visited many, particularly large organizations already. Yeah. Where are you, what are you doing and so on. But I really think these registries that we need to maintain. Yeah. Do you have them? Yes. Can we see them? Do you have the drawer? Fundamentals. I think so. And can you show us the resilience test if you've done anything? I think, you know, are you in control and have you, you know, do you know? I think that's what I think. Absolutely. I think so too. Yeah. Do you have any other good questions? We have little time left for final question, I think. So many questions. So choose one wisely before we wrap up. Maybe there are some ones on. Yeah. Do you have anything else Thomas? No, just a final remark. Yeah. I would expect that the, can say the level of visits or audits will, the complexity will probably increase over time. So in the beginning they will just open the drawer and look, is it okay? Does it look fine? Yeah. And then in the longer run they will probably test, test deeper and deeper into your organization. That's also what we saw on GDPR. And of course, if you have an incident the day after Dora has come into interact, then they will probably come knocking on your door and say, can we please see how you handle that? Otherwise I expect fairly, let's call it easy audits in the beginning and then the level of complexity will increase over time. I think that was the time we had actually. So we're wrapping up, Penelope. Yes. So, well, what have we learned today? There has been a lot of conversations around using Dora as a catalyst. So there is an opportunity for us here to take a bit of a bigger, bigger investments, slightly bigger investment can make a huge impact on our operational businesses. strategic, have an impact on the strategic part. We know that it's not just about cyber. It's about the whole business and it's a strategic initiative that needs to get in place. And we need to make sure that we do connect the business strategies with the investment we are doing in information and cyber security. And what else? I heard that testing is the new black. So that's a catchphrase I will pick up on. So thank you so much for listening and for all the great questions coming in. That was super exciting. Thank you for all the guys on the behind the scenes that has helped us with this. And until next time we will get back. We don't know yet when, but it will be soon, I guess, because there is so much to deep dive in this. So until then, take care and good luck. Bye bye. Bye bye. Bye bye. Bye bye. Bye bye. Bye bye. Bye bye. Bye bye. Bye bye. Thank you. Thank you. Thank you.