Are you thinking, “I’m not a financial institution in the EU, so I can ignore DORA.” Well, not so fast. Sorry to bring you some bad news. DORA's reach extends to the ICT service providers of financial institutions too. Everyone who works with financial institutions in the EU will be impacted. This includes SaaS and cloud providers, insurers, investment firms, payment services, credit institutions, and users of ICT systems, etc.
Let’s start with what it is. The Digital Operational Resilience Act, or DORA, is a new EU law. It aims to boost cyber defenses in the financial sector. Adopted on January 16, 2023, it will take effect on January 17, 2025. DORA establishes a unified framework for securing information and communication technology (ICT). DORA has 64 articles. So, here's the TL;DR: All financial sector organizations must prove they can withstand, respond to, and recover from all types of tech-related disruptions and threats. They must prove they are set up to be resilient. Not just from cloud outages and natural disasters but also from cyberattacks too.
Organizations must prove ironclad cyber defenses and robust digital operational resilience. Secondly, they must prove a strong governance structure to manage risks. This includes ICT Risk Management and monitoring of Third-Party Risk Providers. So, let's dive in.
Mandates internal governance and control frameworks to identify, assess, and mitigate ICT risks required.
Mandates organizations detect, manage, and promptly report major cyber or ICT-related incidents.
Mandates rigorous testing to find, fix, and reduce vulnerabilities.
Mandates oversight and management of ICT third-party service providers, including cloud computing services to ensure compliance with DORAs resiliency requirements.
Mandates sharing cyber threat intelligence among organizations to boost collective resilience against cyber threats.
I will admit that the list above is still dense. So, here are the highlights in TL;DR style.
Top Ten DORA Takeaways:
Want to learn more about how to get prepared for DORA? Read our DORA: Get Prepared guide.
Today’s teams need to know the specifics—controls, processes, technologies, and reporting requirements for achieving resilience and DORA compliance. Veritas can help! This is our business. We offer a variety of solutions that can help your organization protect your data, secure it and prove compliance. Additionally, Veritas offers our customers cyber resiliency assessment and recovery services, that can help set up your systems, protocols and teams in accordance with the requirements. To learn more about our Cyber Resilience solutions, read our white paper, DORA: Deep Dive into the Cyber Resilience Aspects of the New Legislation. Additionally, for the risk management strategy side of the DORA legislation read the DORA Risk Management white paper.
Lastly, watch our recent interview, Demystifying DORA with Veritas experts, Alain Pelegrin and Magnus Martensson. Remember DORA will take effect on January 17, 2025, so kick off your preparations today.