Decoding DORA

By January 17, 2025, financial institutions and their critical ICT third-party service providers must prove their digital operational resilience.

The Five Pillars of DORA

Unlike previous directives which focused on capital allocation, DORA mandates systemic resilience against cyber threats. Financial entities must demonstrate they can withstand, respond to, and recover from all types of ICT-related disruptions and threats.

  1. ICT Risk Management: Comprehensive frameworks to identify, protect against, and detect anomalies. See our NIS2 vs DORA analysis.
  2. Incident Reporting: Streamlined, mandatory reporting of major ICT-related incidents to competent authorities. Calculate your timelines with our Breach Timer.
  3. Digital Operational Resilience Testing: Regular basic testing for all entities, and advanced Threat-Led Penetration Testing (TLPT) for critical entities.
  4. Third-Party Risk Management: Stringent contractual requirements for ICT service providers (e.g., cloud hosts, data analytics). Profile your vendors using our Vendor Risk Profiler.
  5. Information Sharing: Encouraged intelligence sharing among financial entities.

Third-Party Impact

DORA brings Critical ICT Third-Party Providers (CTPPs) directly under the oversight of European Supervisory Authorities (ESAs). Test if your vendor might be a CTPP using the DORA Assessor.

Common Implementation Mistakes

  • Ignoring intra-group dependencies: Many institutions focus solely on external vendors, forgetting that internal shared service centers are also subject to strict ICT risk management rules.
  • Treating DORA as an IT problem: DORA explicitly makes the management body ultimately accountable. It is a board-level governance issue, not just a CISO mandate.
  • Siloed incident reporting: Failing to integrate DORA's reporting requirements with existing GDPR or NIS2 workflows can lead to double-reporting or missed deadlines.

FAQ

Does DORA apply to UK firms?

Not directly, unless they have operations within the EU. However, the UK is implementing its own similar framework (PS21/3) regarding operational resilience.

What is TLPT?

Threat-Led Penetration Testing. It involves simulating targeted cyber-attacks by sophisticated adversaries to test an entity's defensive capabilities on live production systems.