
One year remains to comply with the EU DORA regulation — the Digital Operational Resilience Act. Its purpose is to strengthen the operational IT resilience of banking and financial players.
That IT resilience means a company or body being able to withstand a cyberattack while continuing to deliver its services. DORA is a cybersecurity framework aimed at preventing attacks linked to information and communication technologies (ICT).
The international financial system is interconnected, and very large players operate across multiple markets — which is a source of serious threat, because weakness in one necessarily means weakness in the others. Should a major player’s information system fail, most often through an attack on one of its suppliers, the collapse of the financial system would become not merely conceivable but instantaneous.
In concrete terms, what does DORA change in banking and finance?
Who does DORA apply to, and why cybersecurity?

As a reminder, DORA applies to 20 types of financial company, including:
- credit and payment institutions,
- electronic money institutions,
- investment firms,
- crypto-asset service providers,
- trading venues,
- management companies,
- insurance and reinsurance undertakings and their intermediaries,
- institutions for occupational retirement provision,
- credit rating agencies,
- crowdfunding service providers,
- and alternative investment fund managers.
These companies must have more than 10 employees and an annual turnover and/or balance sheet total of at least 2 million euros.
Add to that list IT providers — third-party ICT service providers — operating within the European Union.
DORA therefore reaches some ten thousand companies across Europe.
A look back at cybersecurity legislation
DORA was conceived by the European Commission to encourage innovation and the adoption of new technologies. In effect, it could give European — and therefore French — cybersecurity players a larger place.

What are DORA’s main cybersecurity pillars?
Most summaries and readings of the DORA text present it as five pillars, but financial sector resilience is better described in four.
Here are the four pillars of DORA as we would set them out:
- Company security: articles 4 to 16
- Incident management: articles 17 to 23 and 45
- Testing ICT providers: articles 24 to 27
- IT contracting: articles 28 to 30
The pillars of DORA, in short
You might imagine the four pillars hold up the roof equally. They do not — some carry more than others.
The first involves securing the company against attack. This is resilience in the face of cyberattacks, and the ability to detect data leaks early.
The second, incident management, requires a system for detecting and analysing the company’s ecosystem. It also mandates incident reporting to public third parties and obliges the financial entity to share threat intelligence.
The third, testing ICT providers, is a little more involved and matters a great deal. IT providers are a major element of a company’s security, which is why this pillar obliges the financial company to invest in its subcontractors’ cybersecurity — and, in doing so, lets the supplier improve its own.
The fourth is IT contracting, which produces an overall picture of contracts. It gives you a map of contracts, obligations and controls, and so strengthens the cybersecurity of everyone under contract.
DORA therefore helps financial sector companies review and improve their cybersecurity.
Watch our DORA webinar: how to implement your compliance in 2024
How do you apply DORA’s requirements to your cybersecurity?
We recommend seeing the information system as an ecosystem. That pushes organisations to look beyond the system itself, to the data that may sit outside it.
First, identify the flows and take a position. For instance: what leaves my company? What comes into it, in terms of data? Through suppliers or not?
Asking those questions is what lets you take a position on those flows within your cybersecurity. Is that daily 4 a.m. data flow to China to be considered toxic, or not?
The second step is to identify data outside the information system. DORA requires a map of the data for financial players’ cybersecurity — a map that reveals, for example, whether a cyberattack has already happened without being spotted.
DORA mandates this exercise once a year to secure financial entities’ cybersecurity.
Read the article ‘DORA — IT resilience in the banking and financial sector’