Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >Firms should address vulnerabilities ahead of the Digital Operational Resilience Act (DORA)
    Business

    Firms Should Address Vulnerabilities Ahead of the Digital Operational Resilience Act (dora)

    Published by Jessica Weisman-Pitts

    Posted on November 9, 2022

    5 min read

    Last updated: February 3, 2026

    Add as preferred source on Google
    Vector illustration featuring the EU map and flag, highlighting the importance of the Digital Operational Resilience Act (DORA) for enhancing cybersecurity in the financial sector.
    Illustration of EU map and flag symbolizing digital resilience in finance - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:compliancecybersecurityfinancial servicesDigital transformationrisk management

    By Alexandre Vandeput, ICT Risk Lead, Capco

    The abundance of virtual data, so integral to the financial services industry, presents some clear dangers to the safety of our money and personal information. At a time when digital vulnerabilities could lead to serious and potentially widespread disruptions to banks’ own systems, regulatory bodies are increasingly focusing on mitigating digital risk in financial services.

    Regulators face a tricky balancing act of ensuring new legislation protects consumers and businesses alike, yet prevents financial innovation from being stifled. The European Union’s answer to this conundrum is Digital Operational Resilience Act (DORA), which will introduce a common set of standards to mitigate digital risks across the financial sector, and ensure the necessary measures are in place to protect against cyberattacks and other sources of disruption.

    Exploring DORA

    DORA seeks to promote important goals such as data sharing and open finance while maintaining the EU’s very high standards on privacy and data protection. The legislation is expected to pass into national law across the Continent before the end of 2022. While there will be a 24-month grace period to allow firms to comply with the new regulations, there are clear ‘first mover’ advantages for those financial services firms who use DORA as an opportunity to decisively embrace the digital revolution.

    Firms that act quickly to ensure they are DORA-compliant will benefit from the enhanced data security the regulation mandates. As it stands, just half of the largest insurance companies in Europe are prepared for the level of testing that is required by DORA. Businesses that have not yet began to scale up their Threat-Led Penetration Testing (TLPT) capacity in line with DORA will struggle to be compliant in time. This will necessitate a diversion of time and resources to scale up testing capabilities. Companies that instead opt to rely on third party consultants to ensure they meet DORA regulations will likely find that they struggle to meet the high standards at regular three-yearly testing periods that is required by the Act.

    DORA requires firms to address cybersecurity-related vulnerabilities alongside disparities concerning operational resilience requirements, reporting and testing shortcomings, and the current lack of joined-up oversight of third-party providers. Similar to forthcoming FCA regulations in the UK, DORA is also concerned with the current concentration risks attached to a majority of financial institutions and service provers using a small pool of mostly US-based Cloud Service Providers (CSPs). If one provider fails, a company or industry sector could see its infrastructure critically affected. DORA requires companies to ensure they are not disproportionately vulnerable to failures of CSPs and other Critical Third Party Providers (CTTPs).

    There is an increasing number of interconnected digital service providers supporting financial services. Currently, these providers do not have to comply with the same strict rules as financial institutions, which increases the risk of digital problems. So-called critical third-party providers who deliver key services and support and who were not previously required to comply with existing regulations, will now have to shift up a gear under the principle of “same activity, same risk, same rules”. CTPPs, who have come under fire from EU and UK regulators this year due to concerns around concentration risk, do not have the same high-level risk management systems in place as financial services institutions; leaving them with a significant challenge ahead to become compliant.

    Don’t delay – address vulnerabilities now

    The ultimate objective of DORA is to help cement Europe’s position as a global leader in digital financial services. The modernisation of risk mangement frameworks and sharing of data amongst financial services firms in EU member states augments the industry’s ability to mitigate risks of malware and ransomware. The standardisation of reporting standards is a boon to multinational firms that have previously had to operate across disparate reporting standards in different countries of operation.

    While further clarity is needed on some of the more technical aspects of DORA, certain key first steps can certainly be taken today. As a first step, financial institutions should focus on identifying and addressing their digital risks. One approach is to use systems that can detect non-standard or unexpected activity, enabling them to identify areas they can maximise the resilience of their digital structures.

    Firms can do this in multiple ways. One is to ensure that a robust Information Security Management System (ISMS) is in place. This presents the opportunity for firms to secure their most critical assets: for example, by augmenting their supply chain risk management processes, or by improving their digital resilience testing capabilities by carrying out periodic ‘intelligence-led’ penetration testing (whereby critical systems are subjected to techniques deployed by sophisticated cyber criminals).

    Such assessments of potential weaknesses within a firm’s own business – and that of its third-party digital service providers – will allow risks to be identified and the effects of cyberattacks mitigated. Firms should also focus on defining the range of assessments, test scenarios, methodologies, practices, tools and external parties needed to support the digital operational resilience testing program. Senior management engagement and active participation is also critical – among the biggest mistakes a firm and its leadership can make is to treat this is as merely a tick-box exercise.

    While DORA will undoubtedly be seen by some as yet more red-tape hampering the success of a hugely profitable industry, those financial institutions who recognise the value inherent to improving operational resilience standards can use it as a catalyst to build more robust digital services and embrace the regulation, rather than fear it.

    Frequently Asked Questions about Firms should address vulnerabilities ahead of the Digital Operational Resilience Act (DORA)

    1What is the Digital Operational Resilience Act (DORA)?

    DORA is a regulation by the European Union aimed at ensuring financial institutions can withstand and recover from digital disruptions, including cyberattacks.

    2What is cybersecurity?

    Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks, which can lead to unauthorized access and data breaches.

    3What is operational resilience?

    Operational resilience is the ability of an organization to continue delivering services despite disruptions, ensuring business continuity and minimizing impact.

    4What is risk management?

    Risk management involves identifying, assessing, and prioritizing risks followed by coordinated efforts to minimize, monitor, and control the probability or impact of unfortunate events.

    More from Business

    Explore more articles in the Business category

    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    Image for Submit Your Nominations Today for Education & Training Awards 2026
    Submit Your Nominations Today for Education & Training Awards 2026
    Image for Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Image for Submit Your Entry Today for Business Awards 2026
    Submit Your Entry Today for Business Awards 2026
    Image for Decentralized Masters’ ‘family culture’ building trust instead of hierarchy
    Decentralized Masters’ ‘family Culture’ Building Trust Instead of Hierarchy
    View All Business Posts
    Previous Business PostFashion Brands Should Focus Less on Sustainability Ambassadors and More on Real Change to the Global Supply Chain
    Next Business PostScaling a Company in a Post-Pandemic Environment