Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Finance
    3. >What DORA & NIS2 means for financial institutions
    Finance

    What Dora & NIS2 Means for Financial Institutions

    Published by Jessica Weisman-Pitts

    Posted on June 28, 2024

    7 min read

    Last updated: January 30, 2026

    Add as preferred source on Google
    An informative graphic illustrating the implications of DORA and NIS2 on financial institutions, highlighting the importance of cybersecurity resilience in banking operations.
    Graph depicting cybersecurity regulations impacting financial institutions - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:compliancecybersecurityfinancial institutionsrisk managementregulatory framework

    What DORA & NIS2 means for financial institutions

    By Ben Stickland, Hive Member at CovertSwarm

    The Digital Operations Resilience Act, or DORA for short, is a new EU regulation aimed at improving the cyber resiliency of EU-based financial institutions.

    The NIS2 directive is an EU-wide legislation which asserts that ‘essential’ and ‘important’ entities, including financial institutions, implement technical, operational, and organisational measures to mitigate the risk of cyber threats. Rather than enforcing regulations, the NIS2 directive provides guidelines to ensure the consistent adoption of local law across EU member states.

    DORA’s requirements are set to come into force on January 17, 2025, while NIS2 is expected to come into play by October 17, 2024. However, each EU member state must apply this to their local legislation so enforcement dates may vary.

    Both of these legislations affect all EU-based financial institutions and any financial institutions that work with EU entities; if it’s not affecting your organisation now, there’s a high chance that it will in the future.

    DORA consists of a regulatory framework based upon digital operational resilience in which all financial institutions and their critical IT suppliers must ensure they can withstand, mitigate, and recover from cyber disruptions and threats, while NIS2 applies to a broader range of ‘essential’ and ‘important’ entities across various sectors.

    Within DORA, penalties for financial entities are decided by competent authorities whereas IT suppliers are fined based on a percentage of their global revenue. NIS2 imposes fines based on turnover for both ‘essential’ and ‘important’ entities.

    What are the requirements for financial institutions?

    Although the main requirements of DORA remain clear, greater details regarding technical standards will be published as part of the final draft in July. Nevertheless, the five regulatory pillars of DORA include:

    • ICT risk management: Financial entities must establish internal governance and control frameworks to effectively identify, assess, and mitigate ICT risks.
    • ICT-related incident reporting: Financial entities must classify and report ICT-related incidents that compromise their security and have adverse impacts on data integrity or service availability.
    • Digital operational resilience testing: All financial entities, except micro-enterprises, must periodically conduct advanced testing, known as ‘Threat Led Penetration Testing’ (TLPT), to prevent incidents. The frequency of testing may vary depending on the size and risk profile of the entity.
    • Management of ICT third-party risk: Financial entities must safeguard against external vulnerabilities by ensuring their third-party providers are secure and compliant.
    • Information and intelligence sharing: Financial entities are encouraged to share informative content about internal and external ICT-related incidents.

    NIS2 expands upon existing requirements from NIS, such as corporate accountability and business continuity. However, it also introduces new obligations for organisations, including risk management and reporting obligations.

    Here’s a closer look at the four overarching areas of NIS2 and what they entail:

    • Corporate accountability: corporate management must supervise, authorise, and undergo training on the entity’s cybersecurity measures.
    • Risk management: organisations must implement measures to mitigate cyber risks, such as incident management, supply chain security, network security enhancement, access control improvement, and encryption deployment.
    • Reporting obligations: ‘essential’ and ‘important’ entities must establish procedures for promptly reporting security incidents that significantly impact their service provision or recipients and adhere to specific notification deadlines.
    • Business continuity: organisations must strategize how to maintain business operations during major cyber incidents, incorporating plans for system recovery and establishing a crisis response team.

    Who is affected?

    Although there are many exceptions to the rule, at its base level, DORA primarily affects EU-based financial institutions and their ‘critical’ IT suppliers. This includes:

    • Financial institutions such as banks and credit institutions
    • Credit agencies and account information service providers
    • Pension funds and investment firms
    • Crypto-asset service providers
    • Insurance providers
    • Crowdfunding providers and alternative investment fund managers
    • Intermediaries and ICT service providers

    NIS2 applies to entities operating in the EU, regardless of the organisation’s geographical presence. Both ‘essential’ and ‘important’ entities will need to comply with the NIS2 directive. The industries affected by NIS2 include:

    ‘Essential’ sectors:

    • Energy
    • Space
    • Transport
    • Banking
    • Public administration
    • Financial market infrastructure
    • Health
    • Drinking water
    • Wastewater
    • Digital infrastructure
    • ICT service management (B2B)

    ‘Important’ sectors:

    • Postal and courier services
    • Waste management
    • Manufacturing
    • Digital providers
    • Research
    • Production, processing, and distribution of food
    • Manufacture, production, and distribution of chemicals

    What happens if financial institutions fail to comply?

    Financial institutions that fail to comply with DORA will be subjected to penalties determined by competent authorities. Depending on how each EU Member State decides to implement the penalty, organisations may face criminal and/or financial consequences.

    If an IT supplier fails to comply with DORA, they could risk a penalty of up to 1% of their average daily worldwide turnover in the preceding business year. This is applied every day for up to 6 months.

    It’s worth noting that penalties and fines under DORA will abide by the concept of proportionality. In other words, smaller financial institutions won’t be held to the same standards as larger, multinational companies.

    For ‘essential’ entities, fines for non-compliance can range from 10 million EUR up to 2% of the total worldwide annual turnover. ‘Important’ entities may face fines from 7 million EUR up to 1.4% of the total worldwide annual turnover.

    What steps should financial institutions take to reduce the risk of non-compliance?

    Two components of DORA set it apart from other regulations, in that they mandate security testing to ensure both the appropriateness and effectiveness of your security controls.

    A key part of the regulation is to carry out regular ‘Threat Led Penetration Testing’ (TLPT), which is far beyond today’s typical penetration testing regime; this starts by thinking like a real-world attacker, building an attack plan for your environment, and then carrying it out at depth throughout your infrastructure. The TLPT exercise should then fold back into your security program to address the discovered vulnerabilities, whether these are people, process or technology-based.

    Article 25 of DORA mandates that applications and infrastructure are tested after each new deployment or change, therefore a great way to approach this is to move to a model of continuous testing; one where you have capacity on demand, and that can work in step with your SDLC and change management pipelines.

    Asset management is key to compliance. Financial institutions need to know what’s on their estate, what they’re using and interacting with and what the risks and threats are to them, as well as how their third-party suppliers operate. From here, organisations can leverage the frameworks and embed policies and frameworks for evaluating and prioritising risks. This is where deploying tactics like threat-led penetration and cybersecurity testing, instant reporting, and instant management come in.

    Risk management within finance and banking is incredibly complex. When it comes to third-party vulnerabilities, there’s much more engagement required with supplier management. Finance institutions need a deep understanding of their contracts with their IT provider and where the roles and responsibilities lie. DORA is really emphasising this point and it’s the area that will carry the biggest penalties – potentially on both sides. Institutions need to be crystal clear on which party is managing what and who is accountable.

    An example is patching and monitoring: if there were to be a compromise on the third party, how much responsibility falls on the financial institution for spotting it, if any at all? This is a simple example, but it underpins the importance of laying clear roles for responsibility in all cases.

    There is still time to address any indistinct gaps in responsibility; approximately 6 months until 17 January 2025. Now is the time to comb through any contracts and clearly outline and tackle any areas of ambiguity to avoid legal implications and potential reputational damage later down the line.

    The importance of the regulations

    While some may see compliance with the DORA and NIS2 regulations as a check box exercise, it’s become essential given the increase in pace and scale of cyber security attacks, particularly in the finance sector.

    Customer trust is so important for financial institutions; if a bank’s customers suspect it’s vulnerable to hackers, the bank is certainly going to lose its customers and receive a damaged reputation. DORA and NIS2 have been developed to build better operational resilience and to bring every institution up to the same standard, making attacks from nefarious actors as difficult as possible.

    Table of Contents

    • Who is affected?
    • What happens if financial institutions fail to comply?
    • The importance of the regulations

    Frequently Asked Questions about What DORA & NIS2 means for financial institutions

    1What is DORA?

    The Digital Operations Resilience Act (DORA) is an EU regulation aimed at enhancing the cyber resilience of financial institutions by requiring them to manage and mitigate ICT risks.

    2What is NIS2?

    The NIS2 directive is an EU legislation that mandates essential and important entities to implement measures to manage cybersecurity risks and report incidents effectively.

    3What are ICT risks?

    ICT risks refer to potential threats to information and communication technology systems, which can impact the integrity, availability, and confidentiality of data.

    4What are penalties for non-compliance?

    Penalties for non-compliance with DORA can include fines based on a percentage of global revenue, while NIS2 imposes fines based on turnover for affected entities.

    5What is risk management in finance?

    Risk management in finance involves identifying, assessing, and prioritizing risks followed by coordinated efforts to minimize, monitor, and control the probability or impact of unfortunate events.

    More from Finance

    Explore more articles in the Finance category

    Image for NatWest to sell HR consultancy unit Mentor in streamlining push, Sky News reports
    NatWest to Sell HR Consultancy Unit Mentor in Streamlining Push, Sky News Reports
    Image for Italy's growth outlook darkens due to Iran conflict, business lobby says
    Italy's Growth Outlook Darkens Due to Iran Conflict, Business Lobby Says
    Image for Denmark's prime minister hands in government resignation after election defeat
    Denmark's Prime Minister Hands in Government Resignation After Election Defeat
    Image for ECB's Lane flags selling prices and wages as key indicators
    ECB's Lane Flags Selling Prices and Wages as Key Indicators
    Image for UK house prices rise by least since September 2024 in January
    UK House Prices Rise by Least Since September 2024 in January
    Image for Commerzbank supervisory board committee met 11 times to discuss UniCredit in 2025
    Commerzbank Supervisory Board Committee Met 11 Times to Discuss UniCredit in 2025
    Image for Swiss air transport caterer Gategroup considers listing
    Swiss Air Transport Caterer Gategroup Considers Listing
    Image for German business sentiment fell less than expected in March, Ifo finds
    German Business Sentiment Fell Less Than Expected in March, Ifo Finds
    Image for On Holding names co-founders as CEOs
    On Holding Names Co-Founders as CEOs
    Image for ECB may need to act on even 'not-too-persistent' inflation surge, Lagarde says
    ECB May Need to Act on Even 'not-Too-Persistent' Inflation Surge, Lagarde Says
    Image for Europe's STOXX 600 gains 1% on prospect of Middle East ceasefire
    Europe's Stoxx 600 Gains 1% on Prospect of Middle East Ceasefire
    Image for Estonia says drone enters from Russia, hits power station, ERR reports
    Estonia Says Drone Enters From Russia, Hits Power Station, Err Reports
    View All Finance Posts
    Previous Finance PostCarv Launches Alphanet: $35m Node Sale Propels Decentralization Milestone
    Next Finance PostHow Startups Can Maximize R&d Tax Credits in 2024