Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking and Finance Review - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > Firms should address vulnerabilities ahead of the Digital Operational Resilience Act (DORA)
    Business

    Firms should address vulnerabilities ahead of the Digital Operational Resilience Act (DORA)

    Published by Jessica Weisman-Pitts

    Posted on November 9, 2022

    5 min read

    Last updated: February 3, 2026

    Vector illustration featuring the EU map and flag, highlighting the importance of the Digital Operational Resilience Act (DORA) for enhancing cybersecurity in the financial sector.
    Illustration of EU map and flag symbolizing digital resilience in finance - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:compliancecybersecurityfinancial servicesDigital transformationrisk management

    By Alexandre Vandeput, ICT Risk Lead, Capco

    The abundance of virtual data, so integral to the financial services industry, presents some clear dangers to the safety of our money and personal information. At a time when digital vulnerabilities could lead to serious and potentially widespread disruptions to banks’ own systems, regulatory bodies are increasingly focusing on mitigating digital risk in financial services.

    Regulators face a tricky balancing act of ensuring new legislation protects consumers and businesses alike, yet prevents financial innovation from being stifled. The European Union’s answer to this conundrum is Digital Operational Resilience Act (DORA), which will introduce a common set of standards to mitigate digital risks across the financial sector, and ensure the necessary measures are in place to protect against cyberattacks and other sources of disruption.

    Exploring DORA

    DORA seeks to promote important goals such as data sharing and open finance while maintaining the EU’s very high standards on privacy and data protection. The legislation is expected to pass into national law across the Continent before the end of 2022. While there will be a 24-month grace period to allow firms to comply with the new regulations, there are clear ‘first mover’ advantages for those financial services firms who use DORA as an opportunity to decisively embrace the digital revolution.

    Firms that act quickly to ensure they are DORA-compliant will benefit from the enhanced data security the regulation mandates. As it stands, just half of the largest insurance companies in Europe are prepared for the level of testing that is required by DORA. Businesses that have not yet began to scale up their Threat-Led Penetration Testing (TLPT) capacity in line with DORA will struggle to be compliant in time. This will necessitate a diversion of time and resources to scale up testing capabilities. Companies that instead opt to rely on third party consultants to ensure they meet DORA regulations will likely find that they struggle to meet the high standards at regular three-yearly testing periods that is required by the Act.

    DORA requires firms to address cybersecurity-related vulnerabilities alongside disparities concerning operational resilience requirements, reporting and testing shortcomings, and the current lack of joined-up oversight of third-party providers. Similar to forthcoming FCA regulations in the UK, DORA is also concerned with the current concentration risks attached to a majority of financial institutions and service provers using a small pool of mostly US-based Cloud Service Providers (CSPs). If one provider fails, a company or industry sector could see its infrastructure critically affected. DORA requires companies to ensure they are not disproportionately vulnerable to failures of CSPs and other Critical Third Party Providers (CTTPs).

    There is an increasing number of interconnected digital service providers supporting financial services. Currently, these providers do not have to comply with the same strict rules as financial institutions, which increases the risk of digital problems. So-called critical third-party providers who deliver key services and support and who were not previously required to comply with existing regulations, will now have to shift up a gear under the principle of “same activity, same risk, same rules”. CTPPs, who have come under fire from EU and UK regulators this year due to concerns around concentration risk, do not have the same high-level risk management systems in place as financial services institutions; leaving them with a significant challenge ahead to become compliant.

    Don’t delay – address vulnerabilities now

    The ultimate objective of DORA is to help cement Europe’s position as a global leader in digital financial services. The modernisation of risk mangement frameworks and sharing of data amongst financial services firms in EU member states augments the industry’s ability to mitigate risks of malware and ransomware. The standardisation of reporting standards is a boon to multinational firms that have previously had to operate across disparate reporting standards in different countries of operation.

    While further clarity is needed on some of the more technical aspects of DORA, certain key first steps can certainly be taken today. As a first step, financial institutions should focus on identifying and addressing their digital risks. One approach is to use systems that can detect non-standard or unexpected activity, enabling them to identify areas they can maximise the resilience of their digital structures.

    Firms can do this in multiple ways. One is to ensure that a robust Information Security Management System (ISMS) is in place. This presents the opportunity for firms to secure their most critical assets: for example, by augmenting their supply chain risk management processes, or by improving their digital resilience testing capabilities by carrying out periodic ‘intelligence-led’ penetration testing (whereby critical systems are subjected to techniques deployed by sophisticated cyber criminals).

    Such assessments of potential weaknesses within a firm’s own business – and that of its third-party digital service providers – will allow risks to be identified and the effects of cyberattacks mitigated. Firms should also focus on defining the range of assessments, test scenarios, methodologies, practices, tools and external parties needed to support the digital operational resilience testing program. Senior management engagement and active participation is also critical – among the biggest mistakes a firm and its leadership can make is to treat this is as merely a tick-box exercise.

    While DORA will undoubtedly be seen by some as yet more red-tape hampering the success of a hugely profitable industry, those financial institutions who recognise the value inherent to improving operational resilience standards can use it as a catalyst to build more robust digital services and embrace the regulation, rather than fear it.

    Frequently Asked Questions about Firms should address vulnerabilities ahead of the Digital Operational Resilience Act (DORA)

    1What is the Digital Operational Resilience Act (DORA)?

    DORA is a regulation by the European Union aimed at ensuring financial institutions can withstand and recover from digital disruptions, including cyberattacks.

    2What is cybersecurity?

    Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks, which can lead to unauthorized access and data breaches.

    3What is operational resilience?

    Operational resilience is the ability of an organization to continue delivering services despite disruptions, ensuring business continuity and minimizing impact.

    4What is risk management?

    Risk management involves identifying, assessing, and prioritizing risks followed by coordinated efforts to minimize, monitor, and control the probability or impact of unfortunate events.

    More from Business

    Explore more articles in the Business category

    Image for How Commercial Lending Software Platforms Are Structured and Utilized
    How Commercial Lending Software Platforms Are Structured and Utilized
    Image for Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Oil Traders vs. Tech Startups: Surprising Lessons from Two High-Stakes Worlds | Said Addi
    Image for Why More Mortgage Brokers Are Choosing to Join a Network
    Why More Mortgage Brokers Are Choosing to Join a Network
    Image for From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    From Recession Survivor to Industry Pioneer: Ed Lewis's Data Revolution
    Image for From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    From Optometry to Soul Vision: The Doctor Helping Entrepreneurs Lead With Purpose
    Image for Global Rankings Revealed: Top PMO Certifications Worldwide
    Global Rankings Revealed: Top PMO Certifications Worldwide
    Image for World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    World Premiere of Midnight in the War Room to be Hosted at Black Hat Vegas
    Image for Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Role of Personal Accident Cover in 2-Wheeler Insurance for Owners and Riders
    Image for The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    The Young Rich Lister Who Also Teaches: How Aaron Sansoni Built a Brand Around Execution
    Image for Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    Q3 2025 Priority Leadership: Tom Priore and Tim O'Leary Balance Near-Term Challenges with Long-Term Strategic Wins
    Image for Using Modern Team Management Methods to Improve Collaboration in Hybrid Work Models
    Using Modern Team Management Methods to Improve Collaboration in Hybrid Work Models
    Image for Why Email Deliverability is a Business Risk Your Company Can’t Afford to Ignore
    Why Email Deliverability is a Business Risk Your Company Can’t Afford to Ignore
    View All Business Posts
    Previous Business PostFashion brands should focus less on sustainability ambassadors and more on real change to the global supply chain
    Next Business PostScaling a company in a post-pandemic environment