KryptoKnight, a CySEC-regulated crypto-asset service provider, needed to comply with DORA — Regulation (EU) 2022/2554 — and to prove its security posture to the regulator. TetraMatrix delivered the full compliance programme, then validated it with an authorised, nine-domain penetration test of the production platform.
KryptoKnight Ltd operates a production crypto-asset platform — custodial wallets, fiat on/off-ramps, KYC/AML onboarding — under the supervision of the Cyprus Securities and Exchange Commission (CySEC).
As a microenterprise (Art. 2, Recommendation 2003/361/EC), KryptoKnight qualifies for DORA's Article 16 simplified ICT risk-management framework — but "simplified" still means a documented risk framework, incident reporting to CySEC within regulatory deadlines, resilience testing, and full third-party risk governance, all with evidence the regulator can inspect.
DORA applies to KryptoKnight directly — no transition period, no exemptions for being small. Three problems had to be solved at once:
Article 16 removes the internal-audit mandate, the three-lines-of-defence model and TLPT — but every other obligation stays. The programme had to be lean without leaving gaps a CySEC review could expose.
A working control isn't compliance — a documented, inspectable one is. Every requirement needed to map to a named implementation on the live platform and a formal deliverable ready for submission.
The DORA package asserts a hardened platform. Those claims needed independent validation: an authorised penetration test of the real production environment — frontend, API, infrastructure and third-party integrations.
Every applicable DORA requirement was mapped to a concrete technical implementation running on KryptoKnight's platform — with named evidence for each:
20 risks on a 5×5 matrix, with treatment plans for every High and Very High exposure.
9 providers assessed against the Art. 30 contractual checklist.
26 assets classified across hardware, software/SaaS, cloud, data and network.
Standalone, board-approved Digital Operational Resilience Strategy — 10 sections.
Full DORA gap assessment — prepared and submitted to CySEC.
Regulator's DORA self-assessment questionnaire completed and filed.
An authorised, grey-box security assessment of KryptoKnight's production platform — the same environment the DORA package describes — across nine domains:
DNS enumeration incl. zone-transfer attempt and SPF/DKIM/DMARC, full TCP port scanning of both production IPs, TLS/cipher configuration, Traefik reverse-proxy review.
Full security-header enumeration — CSP, HSTS, X-Frame-Options, COEP/COOP/CORP — plus version-disclosure and cookie-attribute review.
43 endpoints enumerated and tested: auth bypass, JWT algorithm-confusion, IDOR and privilege escalation, rate-limit bypass, SQL/NoSQL/OS/LDAP injection, mass assignment, fuzzing.
Registration and login flows, username enumeration (direct and timing-based), 2FA/TOTP brute-force and replay, password-reset token security, per-device session revocation.
Reflected, stored and DOM-based XSS across all user-controllable inputs; clickjacking; CSP bypass via script gadgets and JSONP; client-side sensitive-data exposure.
Fireblocks webhook RSA-SHA512 signature bypass, replay and body-manipulation attempts; SumSub HMAC-SHA256 forgery attempts; API-key entropy and scoping.
Backend and frontend dependency audits against NVD, GitHub Advisory DB and OSV; container base-image CVE assessment.
Full OWASP ZAP spider and active scan in authenticated mode — 38 pages crawled, 147 attack patterns across the OWASP Top 10.
k6 load testing against frontend assets and authentication endpoints — ramp to 10 VUs, spike to 25 VUs, controlled ramp-down.
Six findings — all low-risk, all remediated and verified. Zero critical or high-severity issues.
| ID | Finding | Risk | Status |
|---|---|---|---|
| F-01 | Insufficient HTTP response security headers | Low | Fixed |
| F-02 | Missing Content-Security-Policy header | Low | Fixed |
| F-03 | HSTS max-age below regulatory minimum | Low | Fixed |
| F-04 | Web server version disclosure | Low | Fixed |
| F-05 | CORS policy accepting wildcard origin | Low | Fixed |
| F-06 | Dependency security advisory (ORM) | Low | Fixed |
"KryptoKnight's DORA submission package is complete, internally consistent, and backed by an independent penetration test of the production platform — compliance that survives scrutiny, not just paperwork."
TetraMatrix delivers end-to-end DORA compliance programmes and independent security assessments for EU-regulated financial entities — scoped to your size, evidenced for your regulator.