Posted on Leave a comment

Obligations under the DORA (Digital Operational Resilience Act) Regulation

Obligations under the DORA Regulation

The DORA Regulation, once in force (15/1/2025), will require all affected entities to adopt specific technical and organisational measures to ensure digital operational resilience.

The financial institutions involved will have to prioritise the implementation of an ICT risk management process, aimed at identifying cyber threats in advance and minimising the impact of cyber incidents. The main responsibility for this process will lie with the company’s management body, which will have to assume ‘full and ultimate responsibility’ for:

  • ICT risk management;
  • The definition and approval of the digital operational resilience strategy;
  • The review and approval of the company’s policy regarding third-party ICT service providers.

Risk Assessment Approach

In detail, the DORA Regulation establishes the adoption of a risk assessment approach that includes:

  • The definition of requirements to harmonise the ICT risk management process with a comprehensive view of business processes;
  • The creation of an ICT Risk Management Framework;
  • The development of a resilient strategy for Disaster Recovery and Business Continuity.

Financial institutions will also need to be able to classify cyber threats and incidents related to ICT vendors, based on criteria established by the DORA Regulation, such as:

  • The number and significance of customers or financial counterparties involved;
  • The duration of the incident;
  • The loss of data, assessing the availability, authenticity, integrity and confidentiality of the data.

Internal Procedures and Communication

Institutions should establish internal procedures to identify, record and categorise incidents, assigning roles and responsibilities and developing communication plans for stakeholders, including board members.

The classification and tracking of incidents are functional to the implementation of a reporting system to the competent bodies provided for in Article 46 of the DORA Regulation. This includes:

Compliance with Third Party ICT Service Providers

In the context of ICT risk management, the DORA Regulation also imposes obligations towards third-party suppliers, requiring:

  • The identification, classification and documentation of all processes that depend on third-party suppliers;
  • The inclusion of contractual clauses to ensure adequate monitoring of supplier activities on services critical to financial operations.

Information Sharing and Resilience Testing

The DORA Regulation also promotes, through Article 45, a voluntary cyber threat intelligence sharing programme among financial actors, aimed at preventing new threats and improving the resilience of the financial ecosystem.

Finally, financial institutions will have to regularly test their operational resilience through periodic tests based on the Threat Led Penetration Testing method, tailored to the size, type of business and risk profile of the institution.

Posted on Leave a comment

Introduction to DORA – Digital Operational Resilience Act

The Digital Operational Resilience Act (DORA) Regulation 2022/2554/EU is a European regulation that aims to strengthen the digital operational resilience of the EU internal market in the context of increasingly sophisticated cyber threats.

The DORA Regulation sets out the technical standards that financial entities and their critical third-party technology service providers must implement in their ICT systems by 17 January 2025.

Target audience
The DORA Regulation is aimed at banks, insurance companies, financial institutions and ICT service providers.

What it establishes
DORA sets out the technical requirements for financial entities and ITC providers in four areas:

  • ICT risk management and governance
  • Incident reporting and response
  • Digital operational resilience testing
  • Third Party Risk Management
  1. ICT Risk Management (Articles 5-16)
    The first pillar of DORA concerns operational risk management. Financial entities are required to identify, categorise and manage the operational risks associated with their digital activities, with an emphasis on involving the entire organisation in adopting and maintaining measures to meet the identified tolerance level, with particular emphasis on critical functions and the evolution of Business Continuity into comprehensive resilience systems.
  2. ICT Incident Management (Articles 17-23)
    Incident management is a key aspect of ensuring operational resilience in the financial sector and digital services, and the DORA Regulation sets out guidelines involving a rapid, coordinated and well-planned response to events that threaten the security and business continuity of companies in the digital environment, as well as conducting a post-mortem analysis to identify lessons learned and areas for improvement. This continuous learning process is essential to strengthen operational resilience and prevent future similar incidents.
  3. Digital Operational Resilience Testing (Articles 24-27)
    With a view to achieving operational resilience, it is important to adopt testing as an integral part of the risk management strategy. DORA-compliant digital operational resilience testing aims to assess an organisation’s ability to withstand and recover from adverse events in the digital environment.
  4. Third Party ICT Risk Management (Articles 28-30)
    Third Party Management according to the DORA Regulation requires companies to proactively and carefully manage third party relationships to protect digital infrastructure and ensure operational resilience by assessing and monitoring the risks associated with the ICT vendor supply chain in relation to the type, criticality and number of services provided. Financial entities are required to conduct thorough due diligence before engaging with a third party and monitor it over time, integrate security requirements into contracts, and contingency measures in the event of contract termination.
  5. Information and Intelligence Sharing (Article 45)
    The fifth pillar of DORA promotes collaboration and information sharing between financial entities and competent authorities to protect against common threats, vulnerabilities, and to support overall defence capabilities to effectively address digital threats, including cross-border threats.