Celebrate 9 Years with EIMF
EIMF Has Assisted 6,000+ Professionals Get Certified
Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!
*complete your purchase before 21 April 2024
DORA has changed the rules of digital resilience
The Digital Operational Resilience Act (DORA) has introduced a harmonised European framework for managing information and communication technology risk across the financial sector.
DORA has applied since 17 January 2025. Financial entities within its scope must comply with Regulation (EU) 2022/2554 and the associated regulatory and implementing technical standards.
The Regulation applies to a broad range of organisations, including credit institutions, payment institutions, electronic-money institutions, investment firms, fund managers, insurance undertakings, crypto-asset service providers and certain financial-market infrastructures. Its requirements are subject to exclusions, exemptions, simplified frameworks and the principle of proportionality.
DORA brings together disciplines that were often managed separately, including ICT risk, cybersecurity, business continuity, incident reporting, resilience testing and third-party oversight. Its purpose is not simply to prevent incidents. Financial entities must be able to withstand, respond to and recover from ICT-related disruption while maintaining the continuity and integrity of their critical or important functions.
For Cyprus financial entities, the relevant competent authority depends on the entity and sector. Organisations should follow the requirements and reporting arrangements communicated by the Central Bank of Cyprus, the Cyprus Securities and Exchange Commission (CySEC), or another competent authority responsible for their supervision.
DORA is first and foremost a regulatory requirement. However, the capabilities needed to comply with it can also produce wider organisational benefits.
Reliable digital services help protect customer relationships and business continuity. Clear accountability can improve decision-making during disruption. Effective testing can expose weaknesses before they cause significant harm, while stronger oversight of technology providers can reduce the risks associated with outsourcing and complex digital supply chains.
Operational resilience should therefore not be treated solely as an ICT project or a collection of policy documents. It is an organisation-wide capability involving the board, senior management, business operations, technology, risk, compliance, legal, internal audit and third-party management functions.
Financial entities that embed resilience into everyday decisions may be better positioned to protect their services, support responsible innovation and maintain stakeholder confidence during disruption.
DORA compliance is an ongoing responsibility rather than a one-off implementation project. The precise measures required will depend on the entity’s size, risk profile, activities and applicable regulatory framework. Nevertheless, the following areas should form the foundation of a DORA compliance programme.
1. Establish governance and accountability
The management body has ultimate responsibility for the financial entity’s ICT risk. It should define, approve and oversee the ICT risk-management framework, establish clear responsibilities and receive timely information about major incidents, testing results, control weaknesses, third-party dependencies and remediation.
The management body should also approve and periodically review ICT business-continuity and response-and-recovery arrangements, oversee policies governing ICT third-party services and allocate appropriate budgets and resources.
Responsibility for managing and overseeing ICT risk should be assigned to an appropriate control function, with sufficient independence and segregation from internal audit. DORA permits the Three Lines Model or an equivalent internal risk-management and control framework.
Members of the management body must also maintain sufficient knowledge and skills to understand and assess ICT risk, including through regular training.
2. Maintain a comprehensive ICT risk-management framework
Financial entities should establish and maintain a sound, comprehensive and well-documented ICT risk-management framework as part of their overall risk-management arrangements.
This includes identifying and classifying ICT-supported business functions and maintaining accurate inventories of information and ICT assets. Entities should understand which systems, processes, people and third parties support their critical or important functions and how those dependencies could affect service continuity.
The framework should include proportionate protection, prevention and detection controls, secure and up-to-date ICT systems, continuous vulnerability and threat monitoring, and clear processes for assessing risk when systems, services or suppliers change.
Financial entities must also maintain ICT business-continuity and response-and-recovery arrangements. These should define recovery-time and recovery-point objectives, backup and restoration procedures, crisis-management responsibilities and communication plans.
For most entities, the ICT risk-management framework must be reviewed at least annually and after major incidents, material changes, testing results or audit findings. It should also be subject to regular independent internal audit. Certain microenterprises and qualifying entities are subject to different or simplified requirements.
3. Classify, manage and report ICT-related incidents
Financial entities must have processes to detect, manage, record, classify and report ICT-related incidents.
Incident classification should consider factors such as affected clients and transactions, service downtime, geographical spread, data loss, the criticality of affected services, reputational consequences and economic impact. Potential major incidents should be escalated promptly, and reporting responsibilities should be understood before a disruption occurs.
Major ICT-related incidents must be reported to the relevant competent authority through initial, intermediate and final reports. Under the current EU framework, the initial notification is generally due within four hours of classification as a major incident and no later than 24 hours after the entity becomes aware of the incident. An intermediate report generally follows within 72 hours of the initial notification, while a final report is generally due within one month of the intermediate or latest updated intermediate report.
For CySEC-regulated entities, the applicable forms, submission process and deadlines are explained in CySEC Circular C700. CySEC has subsequently highlighted deficiencies in how some entities classify and report incidents and has reminded regulated entities to apply the relevant criteria and thresholds carefully in Circular C751.
Notification of a significant cyber threat is voluntary under DORA where the entity considers the threat relevant to the financial system, service users or clients.
Incident processes should also be coordinated with other potentially applicable requirements, including personal-data-breach reporting. Major incidents that disrupt core activities should lead to structured post-incident reviews, root-cause analysis and corrective action.
4. Test digital operational resilience
Policies and plans cannot, by themselves, demonstrate resilience. Financial entities other than microenterprises must maintain a proportionate digital operational resilience testing programme.
Testing may include vulnerability assessments, network-security assessments, gap analyses, scenario exercises, performance and end-to-end testing, penetration testing and crisis simulations involving management and relevant business functions.
Appropriate tests must be conducted at least annually on ICT systems and applications supporting critical or important functions. Weaknesses identified through testing should be prioritised, remediated and subject to follow-up validation.
Threat-led penetration testing is a separate advanced requirement. It does not apply automatically to every financial entity. Entities selected by the competent authority under DORA’s criteria must generally undertake TLPT at least every three years, although the competent authority may adjust the frequency according to the entity’s risk profile and operational circumstances.
Recovery arrangements should also be tested under realistic conditions. An organisation should be able to demonstrate not only that systems can be restored, but also that business services, decision-making and communication can continue effectively during disruption.
5. Manage ICT third-party risk
Using an external service provider does not transfer the financial entity’s regulatory responsibility. ICT third-party risk must be managed as an integral part of the entity’s ICT risk-management framework.
Before entering an arrangement, financial entities should assess the provider, the services involved and whether they support a critical or important function. They should consider concentration risk, substitutability, subcontracting and the consequences of provider failure.
Contracts must contain the provisions required by DORA. Depending on the service, these may include service descriptions, security and availability requirements, incident-assistance obligations, data-access and recovery provisions, audit and inspection rights, subcontracting conditions, termination rights and cooperation with competent authorities. Arrangements supporting critical or important functions are subject to additional requirements.
Entities should monitor provider performance and risk throughout the relationship and maintain credible exit strategies. The objective is not necessarily to use several providers for every service, but to demonstrate that concentration and continuity risks are understood and can be managed without unacceptable disruption.
DORA also requires financial entities to maintain a register of information covering contractual arrangements for ICT services at the relevant entity, sub-consolidated and consolidated levels.
CySEC-regulated entities must currently submit their register annually by 28 February, with a reference date of 31 December of the preceding year. CySEC requires the register to be submitted in XBRL-CSV format, as explained in Circular C751.
DORA also establishes EU-level oversight for ICT third-party providers formally designated as critical. Other technology providers may be affected through the contractual and oversight obligations imposed on their regulated financial-sector customers.
6. Maintain evidence and invest in people
Regulators need evidence that controls operate effectively, not simply confirmation that policies exist.
Financial entities should maintain appropriate governance records, asset and dependency inventories, risk assessments, incident reports, test results, remediation records, supplier assessments, contract reviews, training records and internal-audit reports. Management information should allow the board and senior management to understand the organisation’s risk exposure and progress in addressing weaknesses.
People are equally important. DORA requires ICT-security awareness and digital-operational-resilience training to form compulsory elements of staff training. These requirements apply to employees and senior management, with the depth of training reflecting each person’s responsibilities.
Training should help personnel understand how to recognise and escalate risks, what to do during an incident and how their decisions affect the continuity of critical or important functions. Cross-functional exercises can help directors, executives, operations teams, technology specialists, compliance professionals and risk managers practise working together during realistic disruptions.
One of the most significant implementation mistakes is treating DORA as an initiative owned solely by the ICT department. Technology teams have an essential role, but resilience failures can also arise from unclear accountability, poor communication, inadequate supplier oversight or delayed decision-making.
Operational resilience ultimately depends on informed leadership, capable professionals and a culture in which risk information is shared and acted upon.
DORA establishes a regulatory baseline, but the operational environment will continue to evolve.
Financial entities face changing risks from cyberattacks, software supply-chain weaknesses, digital fraud, cloud concentration and increasingly complex third-party dependencies. Artificial intelligence can strengthen monitoring and threat detection, but it may also introduce new security, data-governance and model risks.
Continuous monitoring, resilience analytics and advanced scenario testing may offer benefits where they are proportionate, appropriately governed and supported by suitable expertise. The objective should not be to adopt every new technology, but to understand how technological change affects the entity’s risk profile and whether its governance, controls and skills are keeping pace.
Developing operational resilience requires sustained investment in professional knowledge across governance, risk, compliance, technology and financial regulation.
The European Institute of Management and Finance supports professionals and organisations through executive education, professional qualifications and academic programmes in these areas. Relevant learning opportunities include EIMF’s Master in Governance, Risk and Compliance, its governance, compliance and risk programmes and its catalogue of self-paced professional courses.
Professional development should complement not replace an entity’s legal, regulatory, technical and assurance arrangements.
DORA moves the focus beyond cybersecurity controls and policy documentation towards the demonstrable ability to maintain critical or important functions during adverse events.
Successful implementation requires active governance, comprehensive ICT risk management, disciplined incident reporting, meaningful testing, effective third-party oversight and continued investment in people.
For boards and senior managers, the central question is no longer whether disruption will occur. It is whether the organisation has the governance, capabilities and evidence needed to respond effectively when it does.
DORA compliance is not the end of that process. It provides a framework through which financial entities can build stronger, more adaptable and more trustworthy organisations.
Questions for your organisation
• Does the management body receive sufficient information to understand and challenge ICT risk?
• Has the organisation identified the systems and third parties supporting its critical or important functions?
• Can major incidents be classified and reported within the required deadlines?
• Have recovery arrangements been tested under realistic conditions?
• Can the organisation demonstrate that incidents, tests and audits produce measurable improvement?
Notes
This article provides general educational information and does not constitute legal or regulatory advice. Financial entities should assess the requirements applicable to their activities and follow the instructions of their competent authority.
Resources and further reading
• Regulation (EU) 2022/2554 — Digital Operational Resilience Act
• CySEC: Digital Resilience and DORA
• CySEC Circular C700: Incident Reporting and Register of Information
• CySEC Circular C751: Reporting, Governance and Portal-Related Obligations
• Central Bank of Cyprus: Application of DORA
• ESMA: Digital Operational Resilience Act
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the opinion to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
The MAP S.Platis Group uses cookies in order to deliver a better user experience on its websites. For further information regarding cookies please see the MAP S.Platis Cookies Policy at https://eimf.eu/cookies-policy
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
These cookies track your online activity to help advertisers deliver more relevant advertising or to limit how many times you see an ad. These cookies can share that information with other organizations or advertisers. These are persistent cookies and almost always of third-party provenance.
Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.
On All Self-Paced eLearning CPD Courses in Financial Regulation
Hosted by the EIMF and the Chartered Governance Institute
Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.
Not sure if it’s right for you? Let’s talk.
Discount Coupon: NYNY10
Valid until 31 Jan 2025 23:59
Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!
On Self-Paced eLearning Courses
*complete your purchase before 21 April 2024