
IT resilience is the ability of an information system to keep its integrity and recover quickly after an incident. Whatever the cause of that incident, human or technical. It is put to the test by, say, a technical failure, a natural disaster or a cyberattack. IT resilience is therefore a form of cybersecurity.
IT resilience matters, and needs strengthening, particularly in the banking and financial sector, because the EU DORA regulation (Digital Operational Resilience Act) came into force in early 2023, and non-compliance becomes punishable from autumn 2024.
Here we look at what IT resilience involves, and how it connects to the DORA regulation.
What is at stake with IT resilience?
A few things are worth taking in to grasp what IT resilience really means.
Start with the plain fact that companies depend more and more on their information system to operate. If service is interrupted, a company can lose a great deal of revenue — and its reputation with it. Working on IT resilience is what keeps the business running when service goes down.
As you would expect, IT systems hold sensitive data: administrative records on employees, financial information, sometimes sensitive data about suppliers and contractors. IT resilience is what protects that data against leaks.
Finally, genuine and effective IT resilience reassures customers and keeps their trust.
IT resilience in the banking and financial sectors
Why talk about IT resilience in finance and banking?
The EU DORA regulation came into force on 23 January 2023. It aims to strengthen the IT resilience of financial and banking infrastructure against cyberattacks and other disruptions. The entities concerned have less than a year left to comply, and only a few months to get started.

Which tests apply, by company size.
In practice, what is DORA for?
Before DORA, the approach was ‘defensive security’: protecting yourself after the fact. IT resilience asks companies and public bodies to organise themselves from the outset so they can keep working despite outages, and above all despite cyberattacks. Cybersecurity now has to be active if operational IT resilience is to be reached.
DORA also introduces something genuinely new: shared responsibility between a client and its suppliers. Until now, if data leaked from a supplier, the supplier alone was responsible. Under DORA, the client shares that responsibility. It is precisely this shared responsibility that obliges the companies and public bodies covered by DORA to check their suppliers’ IT resilience, and to monitor open sources for data leaks.
Read the article ‘The EU DORA regulation: what the text says’
So what obligations does DORA impose?
DORA places a number of obligations on financial and banking entities, in particular:
- A duty to identify and analyse the risks their IT systems are exposed to.
- A duty to put protective measures in place — data backups, access controls — to reduce the risk of data leaks.
- An obligation to notify incidents to the competent authorities.
- A duty to test and rehearse business continuity plans, in order to prove the IT resilience plan actually works.
IT resilience is a necessity for every company. We advise running tests and monitoring the risks.
How do you monitor potential cyberattack risks as part of your IT resilience?
→ With Aleph Alert. Aleph Alert tells you immediately about any data leak on the clear, deep and dark web that exposes your company to cyberattack.