Back to Insights Compliance

Have you heard about the EU’s DORA?

New Regulation for Strengthening Digital Resilience: DORA – Protecting Financial Institutions Against Cyberattacks

DORA (Digital Operational Resilience Act) is a new European Union regulation that entered into force in January 2025, aimed at strengthening the resilience of financial firms against cyber threats and severe technological failures. The law requires banks, insurance companies, investment funds, and financial service providers to take significant steps to ensure operational continuity even under extreme scenarios.

The regulation imposes clear obligations on financial institutions in key areas. Foremost, they must implement ICT (Information and Communication Technology) risk management, including ongoing monitoring, in-depth analysis of digital risks, and the development of mitigation strategies. Additionally, organizations are required to report significant cyber incidents promptly and share information with relevant authorities. Periodic digital resilience testing, including penetration testing and attack simulations, is mandatory. Furthermore, organizations must manage third-party risk and ensure that external services, such as cloud and cybersecurity providers, comply with the law’s stringent requirements. Finally, a heavy emphasis is placed on recovery capabilities—developing restoration plans for technological failures and maintaining ongoing operations during emergencies.

Who is Subject to the Regulation and What are the Implications? Broad Impact and Required Preparation
DORA applies to banks, credit companies, investment funds, insurance companies, and trading platforms, but also to ICT third-party service providers offering financial solutions, including cloud services, computing infrastructure, and cybersecurity. This means that not only the financial institutions themselves must comply with the regulations, but their entire technological supply chain as well.

To meet these requirements, financial institutions must map risks and assess vulnerabilities in their systems, implement regular resilience testing, update procedures and policies for incident management, establish a Business Continuity Management (BCM) plan, and ensure their employees are skilled in identifying cyber threats. While organizations will need to invest considerable resources in security systems, this investment will help maintain customer trust and protect sensitive data in the long run.

Recommendations from IPV Security’s Information Security Experts:
* Risk Mapping: Threat analysis, vendor reviews, and compliance audits.
* Security Controls: Zero Trust architecture, encryption, and advanced monitoring (SIEM).
* Resilience Testing: Penetration testing, attack simulations, and incident response planning.
* Business Continuity: Disaster recovery plans, automation, and periodic drills.
* Security Culture: Employee training and information sharing.

Summary
DORA is a significant step in protecting financial institutions from cyberattacks and ensuring operational stability in a digital environment. The regulation establishes a uniform standard for ICT risk management, setting strict obligations for attack prevention and improving response to cyber incidents. Organizations that fail to prepare accordingly expose themselves to heavy fines and damage to customer trust.

Is your organization compliant with the new requirements? Now is the time to prepare.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation