42 Rue Broca, 75005 Paris, France
DORA: The new European standard for digital resilience in the tech & cloud sector
The digital transformation of the financial sector is not new. What is changing is the scale of its dependence on information technology and cloud services. Payments, investments, insurance, online banking: everything runs through connected, highly automated and interdependent systems. The slightest incident can spread within seconds and generate shockwaves across the entire European financial system.
It is in this context that Regulation (EU) 2022/2554 comes into play, better known as DORA (Digital Operational Resilience Act). Published in December 2022, it will apply from January 17, 2025. This text represents a major step forward in the regulation of cybersecurity in finance.
Why is it important to be aware of it? Because DORA impacts all financial operators (banks, insurers, fintechs, asset managers, etc.) as well as their technology providers, particularly in cloud, storage or cybersecurity. And because it imposes a high standard for managing digital operational risk.
What is DORA?
DORA is a European regulation that harmonises requirements for digital operational resilience in the financial sector. It aims to ensure that financial entities can withstand, respond to and recover from IT incidents, whether accidental or malicious in origin.
It applies to a wide range of stakeholders:
- Banks and credit unions
- Insurers and reinsurers
- Asset management companies, fintechs, platforms
- ICT (Information and Communication Technology) service providers (cloud, storage, cybersecurity)
The pillars of DORA: key obligations
a) ICT (Information and Communication Technology) risk management
Each entity must have a robust framework to manage ICT risks:
- Identification of critical assets
- Prevention, protection and detection methods
- Response and recovery plans
- Management involvement (governance)
b) Incident reporting
Major ICT incidents must be reported promptly to the competent national authorities.
c) Resilience testing
TPeriodic testing of information systems, tailored to the organisation’s maturity level. Critical players will have to carry out TLPT (Threat-Led Penetration Testing).
d) Contracts with ICT providers
Mandatory standard contractual clauses:
- Audit rights
- Data management and subcontracting
- Exit plans in the event of failure
e) Oversight of critical providers
Critical ICT providers (cloud, SaaS, etc.) will have to comply with direct European oversight.
Why this is strategic for cloud, security and storage professionals
- Commercial positioning: Providing DORA-compliant services will be a competitive advantage from 2025.
- Access to the financial market: DORA is a passport to remain in the financial services value chain.
- Increased accountability: Traceability, support, audit and reversibility obligations are stepping up a level.
- Technical dialogue: Relationships between CIOs, CISOs and providers will need to be closely formalised.
What to prepare right now
- Map your critical dependencies (internal/external)
- Review your ICT supplier contracts (audit, exit clauses, reversibility…)
- Update your business continuity and disaster recovery plans
- Run a TLPT simulation if you are a systemic or critical entity
- Establish clear cyber governance at board level
DORA is an opportunity (if you are ready)
DORA should not be seen as a constraint but as a catalyst. It pushes the financial sector and its technology partners to raise their standards in security, traceability, continuity and transparency. For storage, cloud or cybersecurity professionals, it is an opportunity to broaden their scope and establish a lasting presence within European financial ecosystems.
Staying informed, anticipating and formalising practices: that is the key to turning this regulation into a competitive advantage.
Source: Regulation (EU) 2022/2554 on digital operational resilience (DORA), Official Journal of the European Union, 27 December 2022.
Available online: eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32022R2554

