The EU’s DORA Regulation: A Model for Cyber Resilience in Any Industry?

Written by: Piers Shearman

Categorised: Cyber Resilience

If you work for a company that doesn’t operate in the  EU financial services sector, you might not have heard of DORA. But while it may not affect you, this regulation may serve as a blueprint for regulation that does affect your sector, and arguably provides the strongest example of best practice for digital resilience. And it has just come in to force. If this sounds interesting, read on for a short primer on the Digital Operational Resilience Act.

The Digital Operational Resilience Act (DORA) is a pivotal EU regulation designed to fortify the financial sector’s ability to withstand and recover from cyber threats and ICT disruptions. Effective from 17 January 2025, DORA introduces a standardised framework for operational resilience, ensuring financial entities can respond robustly to evolving digital risks.

Why Was DORA Introduced?

Like all sectors financial services is fully awake to the impact of cyber risk, and this has been increased by the spike in attacks as a result of the Ukraine war and the numerous supply chain attacks that have impacted the sector. There is an understandable concern amongst regulators that a major outage on a big player could lead a financial crash effecting both investors and ordinary members of the public.

DORA addresses the increasing dependency on digital infrastructure and third-party service providers in the financial sector. As cyber-attacks targeting ICT supply chains rise, the regulation aims to create a unified approach to cyber resilience, safeguarding critical financial operations across the EU.

Key requirements of DORA

DORA outlines five core pillars that financial institutions must comply with:

  1. ICT Risk Management: Implementing a comprehensive framework to identify, assess, and mitigate ICT-related risks.
  2. Incident Response and Reporting: Establishing detailed incident response plans with mandatory reporting of significant ICT incidents to regulators.
  3. Digital Operational Resilience Testing: Regular testing of systems through scenario-based exercises and technical assessments like penetration testing.
  4. Third-Party ICT Risk Management: Ensuring third-party providers meet the same resilience standards, with risk management integrated into contracts.
  5. Information Sharing: Promoting collaboration and intelligence sharing among financial entities to strengthen collective cyber defences.

As you can see, this is a substantial undertaking for the sector, which is already, generally speaking, ahead of the curve when it comes to digital resilience. There is a strong emphasis on preparation and prevention, with the implementation of risk frameworks and development and testing of plans and playbooks along with ensuring that your third party providers are also resilient, bringing in a large number of organisations who support the financial service sector.

The role of leadership in DORA compliance

Under DORA, the management body holds accountability for digital resilience. Leaders must ensure sufficient training, resources, and governance structures are in place to meet regulatory standards.

DORA makes the board and senior management accountable for the resilience of their organisation. This, along with the upskilling they may need to have to fully understand what digital resilience is, would be a major task for any organisation.

So how are businesses expected to prepare for DORA compliance?

Organisations prepare for DORA by developing robust incident response plans, conducting regular cyber exercises, and ensuring third-party risk management practices align with DORA’s principles. Part this should will include engaging in scenario-based training and boardroom workshops to increase readiness.

What should I take away from this?

If you work in financial services outside the EU, you can expect some jurisdictions to bring in identical or very similar regulations in the near future, so you can already begin to prepare the ground.

Even if you don’t work in financial services, DORA provides a clearly thought out blueprint for improving the resilience of your organisation.

It could be argued that the focus on information sharing would be excessive for less regulated sectors with weaker integration. However, the emphasis on supply chain security, testing, and having a well-informed, accountable board would benefit any organisation that takes its cyber resilience seriously.

for more information, contact us or download our DORA guide:

 


DORA and the Role of Cyber Resilience

The DORA and the Role of Cyber Resilience guide provides a comprehensive overview of the Digital Operational Resilience Act (DORA) and its implications for financial organisations. This essential resource covers:
  • DORA Explained: A clear breakdown of the regulation, its purpose, and who it applies to.
  • Key Compliance Requirements: Insight into the five core pillars of DORA: ICT risk management, incident response and reporting, digital operational resilience testing, third-party ICT risk management, and information sharing.
  • Cyber Resilience Best Practices: Guidance on building operational resilience through risk management frameworks, incident response plans, and regular testing.
  • Board-Level Responsibilities: Clarification of leadership roles and accountability in ensuring compliance.
  • Practical Steps for Implementation: Tips on scenario-based exercises, staff awareness training, and third-party risk management.
This guide is ideal for financial organisations seeking to enhance their cyber resilience and meet regulatory expectations under DORA.
Download File
DORA and the Role of Cyber Resilience

Related Content

Menu