Regulatory assurance for EU financial institutions

Watch the coast. Keep the record. Prove it.

Redinwatch monitors your institution from the outside, turns what it finds into evidence for your controls, and prepares the reports that DORA and NIS2 require.

Hosted in the EU. Built for supervised institutions.

ObservedLookalike domains, exposed hosts, expiring certificates, exploited vulnerabilities, leaked credentials and third parties.
RecordedEach finding scored, assigned an owner, dated and retained.
ProvenLinked to your controls and to the requirement behind each one.

How it works

From observation to evidence to the report.

Most tools stop at the dashboard. Supervisors and auditors ask for the next step: proof that a control was in place and working on a given date.

Observe. Continuous visibility of your external exposure.

  • Lookalike and typosquatted domains targeting your brands
  • Hosts, IP addresses and certificates discovered from public sources
  • Exploited vulnerabilities matched to the products you run
  • Leaked staff credentials, including through your existing data feeds
  • Third-party providers, assessed from the outside

Record. Every finding with its score, its owner and its history.

  • Scores that can be traced to the underlying evidence
  • Due dates set by the applicable rule, such as a certificate expiry or a published deadline
  • A tamper-evident record of findings, tests and evidence
  • Disputes and exceptions logged with an audit trail

Prove. Controls mapped to the requirements behind them.

  • DORA, NIS2 and supervisory guidance maintained at article level
  • Each control mapped to the requirements it satisfies, with gaps made visible
  • Findings linked to the controls they affect, and their resolution recorded as evidence
  • Reports and evidence packs generated from the record

The evidence chain

One finding, followed through.

Each link is retained, so the chain can be reviewed in either direction. Illustrative example; names are placeholders.

Finding
Certificate expires in 9 days
api.yourbank.example, observed 03:14 UTC, severity High
Control
CTL-14 Certificate and key management
Owner: Infrastructure. Tested monthly. Observed by the platform.
Requirement
DORA Art. 9(4)(c)
Mechanisms to protect the availability and integrity of ICT systems
Evidence
Renewed 7 days before expiry
Entered in the Q4 evidence pack with the before and after observations
finding → control → requirement → evidence

Platform

Three groups of modules that share one record.

Exposure modules produce evidence. Governance holds the requirements and controls. Third-party modules draw on both.

Exposure 01

What can be seen of your institution from the internet, checked continuously.

  • Domain monitoring lookalikes, watchlist
  • Attack surface hosts, certificates, DNS
  • Threat intelligence exploited CVEs, inventory
  • Leaked credentials own feeds supported

Governance 02

Applicable regulation, your control set, assessments and the risk register.

  • Library and requirements article level
  • Controls and mappings coverage view
  • Assessments and evidence audit trail
  • Risks and policies register

Third parties 03

Your ICT providers, assessed from the outside and maintained in the register.

  • Vendors and external checks exposure
  • Vendor assessments frameworks
  • Register of information DORA
  • Concentration and exit plans critical functions

Deliverables

Reports prepared from the record, ready for review.

Each document is assembled from findings and evidence already held on the platform, then reviewed and approved by your team.

DOC 1

Register of information

Your ICT third-party arrangements in the format required by the European Supervisory Authorities, maintained from the vendor module.

DOC 2

Major incident reports

Classification against the DORA criteria, followed by the initial, intermediate and final reports, with deadlines tracked from the incident record.

Initial: 4 hoursIntermediate: 72 hoursFinal: 1 month
DOC 3

Board report

A quarterly summary of ICT risk for the management body, with every figure traceable to its evidence.

DOC 4

Audit evidence pack

The controls in scope, their tests, the observations and the record entries showing when each took place.

Who it is for

Supervised financial institutions across the EU.

  • Credit institutions DORA, NIS2, EBA guidelines
  • Payment and e-money institutions DORA, PSD2
  • Crypto-asset service providers DORA, MiCA
  • Investment firms and fund managers DORA
  • Insurers and intermediaries DORA
  • Advisory firms supporting their clients multi-client

In 1658, Grand Master de Redin built thirteen watchtowers along Malta's coast.

Each stood within sight of the next. When a watchman sighted a threat, he lit a signal fire and the warning passed from tower to tower to the capital.

Redinwatch is developed in Malta for institutions that carry the same regulatory obligations as the largest firms, with far smaller teams.

Contact

Request a demo.

We will walk you through the platform using your own domains and the regulations you are supervised under. A first session takes about thirty minutes.

hello@redinwatch.com
We reply by email within two working days and use your details only to answer this request.