Audit IT, ethical hacking & CAATs

Audit your digital operational resilience, in the DORA era.

ARCAD supports organisations in reviewing their IT systems, IT controls, technical security, access and critical data.

In the DORA era, IT risks must be addressed as issues of governance, continuity, provider management, information security, and remediation capability.
Digital resilience A structured review of IT risks, controls, and vulnerabilities.
01
IT Governance & DORA Organisation, responsibilities, continuity, incidents, and IT service providers.
02
Guided technical tests Vulnerability identification, finding qualification and prioritisation.
03
Analyse by data CAATs, exceptions, anomalies, intelligent sampling and targeted controls.
IT Audit Review of governance, controls and security arrangements.
DORA Digital operational resilience and ICT arrangements analysis.
Ethical hacking Controlled tests to identify exploitable vulnerabilities.
CAATs Computer-assisted analysis to detect anomalies and exceptions.

Digital resilience is not limited to IT security.

It involves clear governance, defined responsibilities, controlled systems, structured incident management, monitored providers, controlled access, and action plans capable of supporting business continuity.

Our approach

Link technical findings to operational risks and governance decisions.

ARCAD intervenes with a regulatory, operational and technical perspective. The objective is not only to identify weaknesses, but to qualify them, prioritise them and transform them into concrete actions.

The mission may cover IT governance, digital operational resilience requirements, access rights, application controls, penetration testing, data analytics, business continuity, incidents, and IT outsourcing.

Area of operation

Targeted reviews of your IT risks, controls and digital resilience.

The scope is defined according to your environment, your exposure to risks, your maturity level, your obligations, and your governance priorities.

01

IT Audit & IS Governance

Review of IT organisation, responsibilities, policies, controls, documentation and technology risk management.

02

DORA & Operational Digital Resilience

Review of ICT risk, business continuity, incident management, ICT providers, testing, and resilience documentation related devices.

03

Access rights & segregation of duties

Analysis of authorisations, sensitive profiles, privileged accounts, obsolete accesses, right conflicts and periodic review mechanisms.

04

Application controls

Review of embedded controls in systems, validations, parameters, activity logs and key processes.

05

Ethical hacking and penetration testing

Managed technical tests to identify vulnerabilities, qualify their impact, and prioritise remediation actions.

06

CAATs and data analysis

Using computer-assisted audit techniques to analyse data, detect anomalies, isolate exceptions and strengthen testing.

Intervention Method

A structured approach, from framing to the action plan.

The work is conducted within a clear framework: defined scope, documented tests, qualified findings, and recommendations prioritised according to their impact.

Step 01

Scope

Definition of the scope, systems concerned, priority risks, stakeholders and elements to be collected.

Step 02

Review

Analysis of governance, procedures, controls, access, continuity, incidents, suppliers, and available documentation.

Step 03

Tests

Performance of technical tests, targeted reviews, application controls or data analysis according to the chosen scope.

Step 04

Recommendations

Formalisation of findings, risk scoring, prioritisation of actions and preparation of a pragmatic remediation plan.

Technical tests and data

Complete the IT review with targeted tests and factual data analysis.

Technical testing and CAATs allow us to go beyond documentary review. They provide a more concrete view of vulnerabilities, exceptions, and the actual functioning of controls.

This approach allows for better prioritisation of actions, avoids overly generic findings, and produces directly actionable recommendations.

Managed penetration tests

A controlled approach to identifying exploitable vulnerabilities, assessing risks, and documenting findings.

Exception analysis

Data-driven checks to identify atypical operations, parameter deviations or situations requiring review.

Smart sampling

A more targeted selection of items to test, based on risks, volumes, profiles and detected anomalies.

Risk prioritisation

The findings are classified according to their criticality to focus efforts on the most important actions.

Deliverables

Clear, prioritised conclusions with an action-oriented plan.

The value of an IT audit lies in its ability to transform findings into concrete decisions: understanding risk, prioritising corrections and tracking remediation.

  • Structured IT audit report with findings, risks and recommendations.
  • Review of digital operational resilience measures and DORA points of attention.
  • Scoring of findings based on criticality, impact and treatment priority.
  • Summary of identified control vulnerabilities, exceptions or weaknesses.
  • Access review results, application controls, and data analysis.
  • Pragmatic action plan with recommended priorities, responsibilities, and deadlines.
Organisations involved

An approach suitable for organisations wanting to strengthen their IT mastery.

ARCAD supports organisations that need to demonstrate a clear mastery of their technological risks, their IT controls, their security arrangements, and their digital operational resilience.

Regulated organisations
Directions IT
Risk & Compliance Functions
Management committees
Entities concerned by DORA
Service providers and outsourced functions
Exchange

Let's assess your digital resilience and remediation priorities.

Would you like to review your IT governance, test your security, analyse your access, exploit your control data or formalise a DORA action plan? ARCAD can support you with a structured, independent and pragmatic approach.

en_GBEnglish