DORA: what financial sector executives must put in place now
Banks, insurers, fintechs: DORA has applied since January 2025. Here is what you need to put in place now.
What is DORA and who does it cover?
The DORA regulation (Digital Operational Resilience Act) has applied since 17 January 2025. It addresses the European financial sector as a whole and imposes a strict framework for digital operational resilience.
Covered entities include: banks, insurance companies, investment firms, payment service providers, fintechs, asset managers, and their critical IT service providers.
The five pillars of DORA
- ICT risk management: a documented governance framework, a defined risk appetite and clear responsibilities at board level.
- ICT incident management: classification and notification to the authorities within the prescribed deadlines.
- Resilience testing: threat-led penetration testing for significant entities.
- Third-party risk management: enhanced due diligence on critical IT providers and specific contractual arrangements.
- Information sharing: participation in cyber threat intelligence sharing arrangements.
What DORA means in practice for your board
DORA requires direct involvement from governing bodies. The board or supervisory body must:
- approve and regularly review the ICT risk management policy
- allocate sufficient budget to digital resilience
- undertake appropriate training on digital risk
- oversee critical providers and the associated contracts
- approve business continuity and disaster recovery plans
DORA goes further than NIS2 within the financial sector. Not only must your organisation be resilient, you must be able to demonstrate it to regulators.
The penalties provided for by DORA
Fines under DORA can reach up to 1 % of the average daily global turnover of the previous year, applied for each day of non-compliance. For critical ICT providers, penalties can rise to five million euros.
A DORA action plan for financial sector executives
- Map your critical ICT assets and identify your dependencies on providers.
- Assess the gap against DORA requirements through a compliance audit.
- Renegotiate your provider contracts to include the mandatory DORA clauses.
- Set up the register of ICT providers and the associated due diligence process.
- Plan your resilience testing according to your entity category.
- Train your board on digital risk and DORA requirements.
Key DORA dates
- 17 January 2025: entry into application
- Annual report to the regulator required
- Threat-led penetration testing every 3 years
- Incident notification within 4 hours (alert) and 72 hours (report)
Are you in the financial sector?
The CyberMasterClass Executives covers DORA, NIS2 and ISO 27001 in a 90-minute format designed for non-technical decision-makers.
Get the next publications.
One analysis per publication on cyber governance, resilience and compliance.
Take action in 90 minutes
Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.
See the masterclasses