What do you know about DORA?

6 February 2024

DORA (Digital Operational Resilience Act) is a comprehensive regulatory framework within the EU for managing digital risks in the financial sector. Through DORA, the scope is expanded from only looking at the financial situation of companies to also include stability in their operations. This takes into account how well they cope with various business-impacting digital incidents, cyber threats and other IT problems. The purpose of DORA is to ensure that financial institutions and market participants are equipped to manage and prevent cyber threats, while maintaining operational stability. This is particularly important given the increasing digitalization of the financial sector and the increasing number of cyber attacks. Companies must broaden their view of identifying resilience for critical functions and underlying processes. They will need to improve their understanding of critical business processes, improve their detection capabilities and incident management routines, expand their testing of critical ICT systems and work closer with their suppliers, who will also have the same obligations. The regulatory framework and its follow-up are under the responsibility of the European Supervisory Authorities (ESAs). ESA will have the power to request information, carry out inspections and issue recommendations, administrative sanctions and remedial measures.

DORA should be seen as a catalyst for strategic improvements in companies’ risk management and increase management awareness of the consequences of serious operational disruptions and increased understanding of the organization’s limitations.

From an EU perspective, nearly 25,000 financial companies and ICT providers are covered by DORA. Those covered include banks and other credit institutions, investment firms, insurance companies, crypto asset providers, data reporting providers and cloud service providers.

The regulations take a cohesive approach to effective risk management, the organization’s ability to manage IT and cybersecurity risks and the management of third-party risks. This is to achieve stability and structure in its entire service delivery. Looking at the regulations, the following points are particularly central:

  • Risk management of ICT services.
  • Reporting of ICT-related incidents.
  • Testing of digital resilience.
  • Risk management of third-party ICT service providers.

Companies affected by DORA should be prepared for increased supervision. When it comes into force, both Swedish and EU regulators will receive extensive new mandates and powers. Looking at experiences from the UK and their new regulatory framework, the authorities have been “pressure testing” companies and asking affected companies about their recovery plans and processes already the same week the regulations were implemented. In other words, companies should, given the tight timeframes, focus on areas that require review by regulators.

The regulation came into force on 16 January 2023, which means that organisations covered by DORA have until 16 January 2025 to comply with its requirements. That means there is now only one year left.

What should you as a company do?

A GAP analysis based on the requirements of DORA should be initiated immediately to identify the deficiencies that will need to be addressed in 2024.

How can Upgraded help?

We have specialists who can help you understand the regulation and its impact on your business, identify the actions that need to be taken, and have access to the resources to implement the changes required to become DORA compliant.