DORA: The new European standard for digital resilience in the tech & cloud sector

What is DORA?

DORA is a European regulation that harmonises requirements for digital operational resilience in the financial sector. It aims to ensure that financial entities can withstand, respond to and recover from IT incidents, whether accidental or malicious in origin.

It applies to a wide range of stakeholders:

The pillars of DORA: key obligations

a) ICT (Information and Communication Technology) risk management

Each entity must have a robust framework to manage ICT risks:

b) Incident reporting

Major ICT incidents must be reported promptly to the competent national authorities.

c) Resilience testing

TPeriodic testing of information systems, tailored to the organisation’s maturity level. Critical players will have to carry out TLPT (Threat-Led Penetration Testing).

d) Contracts with ICT providers

Mandatory standard contractual clauses:

e) Oversight of critical providers

Why this is strategic for cloud, security and storage professionals

What to prepare right now

DORA is an opportunity (if you are ready)

Source: Regulation (EU) 2022/2554 on digital operational resilience (DORA), Official Journal of the European Union, 27 December 2022.

Available online: eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32022R2554

Leave a Reply

Your email address will not be published. Required fields are marked *