DORA: beyond compliance, an opportunity for digital transformation

10–16 minutes

reading

Published on

Now that it is about to come into force, the DORA Regulation represents for the CIOs concerned – over and above compliance obligations and the risks involved in not meeting them – an opportunity to strengthen the sector’s preparedness for digital threats and its ability to recover from them through long-term operational resilience.

The challenge of meeting compliance requirements is becoming an increasingly heavy burden for CIOs. Many of the projects they undertake within their portfolios are therefore designed to help companies prepare to comply with new regulations that are about to take effect… or to catch up on the issue.

Given its critical role in the overall functioning of the economy, the financial sector (banks and insurance companies, credit institutions, investment firms, payment service providers, etc.) is subject to numerous directives and regulations. Within the European Union, the DORA Regulation (Digital Operational Resilience Act), which is structured around five pillars, is one of them.

With the countdown underway ahead of its effective implementation and transposition in each EU member state (on January 17, 2025, exactly two years after its entry into force), the level of preparedness among the various entities involved appears to be uneven. While large institutions have been anticipating this issue and preparing for it for several years, many smaller institutions are not as far along and are watching the deadline and the risk of penalties approach with concern.

With just a few weeks left until the deadline, there’s still time to tackle the issue with a realistic plan of action based on a reverse schedule… but above all, to change our perspective on DORA. While the framework it provides undeniably imposes constraints on businesses—and even more so on CIOs— it also presents a genuine opportunity to shift perspectives on the management of risks related to ICT ( information and communication technologies) and may even serve as a catalyst for accelerating digital transformation.

What are the intentions behind DORA and why was it set up?

Does DORA represent a simple regulatory constraint or a real opportunity for IT?

How can DORA help accelerate digital transformation?

How does DORA offer an opportunity to reconcile Manage project risks within the organization?

1. Capitalize on the “CIO-RSSI-internal control” trinity

2. Strengthen the internal culture around risks and operational resilience, and benefit from better listening by management.

What are the particular issues involved in Tracking third-party suppliers for DORA?


What are the key points to remember about DORA?


What are the six priority work areas if your organization is not yet ahead of DORA?