Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Business and Policy - Exploring the Implications of DORA
Business and Policy Articles Regulations and Compliance Security

Exploring the Implications of DORA

Javvad MalikBy Javvad MalikApril 8, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Exploring The Implications Of DORA
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As of January 17, 2025, the Digital Operational Resilience Act (DORA) came into force across all European Union member states, with the crucial aim of strengthening the IT security of financial entities such as banks, insurance companies, and investment firms. To do this, the regulation looks to standardize how financial entities report cybersecurity incidents, test their operational resilience, and manage third-party risk.

However, while DORA is directly applicable across the EU, its implementation and enforcement vary from country to country. Some member states have swiftly adapted to the new framework, introducing national guidelines and additional supervisory measures, while others face delays or challenges in aligning their regulatory infrastructure. As organisations in various regions brace for the impact of DORA, it’s crucial to understand its implications and the key considerations that should guide compliance efforts.

The Essence of DORA

At its core, DORA seeks to establish a comprehensive framework for managing ICT (Information and Communications Technology) risks within the financial sector. It recognises that the increasing reliance on digital technologies has exposed financial institutions to many cyber threats, from data breaches to system disruptions. By setting requirements for risk management, incident reporting, and third-party oversight, DORA aims to strengthen the sector’s defences and resilience.

How Has it Been Adopted?

While DORA applies uniformly across the EU, its enforcement varies by member state. Each country designates its own supervisory authorities responsible for ensuring compliance and imposing penalties, which can differ in severity and scope.

Countries like Germany and the Netherlands have taken proactive steps, issuing detailed national guidelines and strengthening oversight to facilitate smooth compliance. In Germany, the Federal Financial Supervisory Authority (BaFin) has established a dedicated portal with legal acts, interpretative notes, and FAQs to provide financial institutions with clear directives and resources.

Conversely, some member states have faced delays in integrating DORA into their regulatory frameworks due to resource constraints or challenges in aligning existing laws with the new requirements. This disparity creates difficulties for financial entities operating across multiple jurisdictions, as they must navigate varying levels of enforcement and differing interpretations of the regulation. Such inconsistencies could lead to regulatory arbitrage, where organisations take advantage of less stringent oversight in certain countries, ultimately undermining DORA’s goal of a harmonised and resilient financial sector across the EU.

Implications for Organisations

Like any new legislation or regulatory requirement, the impact on organisations is always far-reaching. It has required organisations to review and map out their controls to the new practices, and will look to where the controls overlap with other legislations too.

Any gaps identified will need to be addressed to mitigate or otherwise compensate.

Perhaps one of the biggest impacts DORA will have is the significant emphasis it places on the resilience of third-party service providers, such as cloud computing providers and other outsourcing partners. Financial entities are required to conduct more in-depth due diligence and ongoing monitoring of their third-party relationships to ensure that they meet the necessary security standards.

This heightened scrutiny will likely lead to a reshaping of the vendor landscape, with organisations gravitating towards providers that can demonstrate strong cybersecurity practices and compliance with DORA.

Embracing the Spirit of DORA

While the specific requirements of DORA are undoubtedly important, it’s equally crucial for organisations to embrace the spirit behind these regulations. DORA is not merely a checklist of technical controls; it represents a shift in how we approach cybersecurity in the financial sector. It recognises that resilience is not just about preventing incidents but also about the ability to detect, respond, and recover from them effectively.

To truly embody the essence of DORA, organisations must foster a culture of cybersecurity awareness and accountability at all levels. This involves empowering employees with the knowledge and skills to identify and report potential threats, as well as establishing clear lines of communication and decision-making processes for incident response. It also requires a proactive approach to risk management, continuously monitoring the threat landscape and adapting defences accordingly.

Furthermore, organisations should view DORA as an opportunity to strengthen their cybersecurity posture and build trust with their customers and stakeholders.

The Road Ahead

With DORA now in force, financial institutions across the EU must shift from preparation to full compliance, ensuring they meet the regulation’s stringent requirements. This requires seamless collaboration between IT, risk management, and compliance teams to embed a holistic approach to cybersecurity. Many organisations are also engaging external experts and industry peers to refine best practices and navigate the complexities of the evolving regulatory landscape.

However, while some member states have swiftly integrated DORA into their national regulatory frameworks, others are trailing behind, facing delays in enforcement or challenges in aligning with the new standards. This uneven implementation creates uncertainty for financial entities operating across multiple jurisdictions, requiring them to stay agile and adapt to varying levels of regulatory oversight.

The success of DORA will ultimately depend on the financial sector’s ability to not just comply but to fully embrace its principles. By fostering a culture of resilience, organisations can strengthen their digital defenses and enhance long-term operational stability in an era of increasing cyber threats.

With laws like DORA, the EU continues to lead the way in mandating transparency, accountability, and operational resilience—setting a new global standard for financial cybersecurity, even as some member states work to catch up.

Javvad Malik
Javvad Malik
Javvad Malik is the Lead Security Awareness Advocate at KnowBe4 and is based in London. Malik is an IT security professional with over 20 years of experience as an IT security administrator, consultant, industry analyst and security advocate. He is also a multi-award winner and is currently a Guinness World Records holder for the most views of a cybersecurity lesson on YouTube in 24 hours.
  • Javvad Malik
    https://informationsecuritybuzz.com/author/javvad-malik/
    7 Real Security Predictions
  • Javvad Malik
    https://informationsecuritybuzz.com/author/javvad-malik/
    Ransomware Detection 101: Six Best Practices To Prevent Propagation And Minimize Damage

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Rethinking the Security Estate: Why IT Spend Isn’t the Same as Cybersecurity Readiness

February 5, 20264 Mins Read

Have You Read the F***ing Policy?

December 2, 20254 Mins Read

UK insurers pay nearly £200m to help businesses recover from cyber attacks

November 12, 20252 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}