The Digital Operational Resilience Act (DORA) is now in force, setting a single standard for how financial entities manage technology and cyber risk across the EU. It applies far beyond banks — payment firms, insurers, investment firms, crypto-asset providers and many of their IT suppliers are all in scope.
Five pillars to organise around
DORA is built on five areas: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. Treating them as one connected programme, rather than five projects, is the difference between compliance and box-ticking.
Third-party risk is the pressure point
Most firms now depend on a web of cloud and software vendors. DORA expects you to map those dependencies, build resilience and exit plans into contracts, and monitor critical providers continuously. This is where many organisations discover they lack a complete picture of their own supply chain.
Where to start
- Build a register of all ICT third-party arrangements and flag the critical ones.
- Define your incident classification and reporting workflow before an incident happens.
- Schedule resilience testing and document the results.
DORA rewards firms that can prove resilience, not just claim it. The organisations that move first will spend less time firefighting and more time building trust with regulators and clients alike.