Now that it is about to come into force, the DORA Regulation represents for the CIOs concerned – over and above compliance obligations and the risks involved in not meeting them – an opportunity to strengthen the sector’s preparedness for digital threats and its ability to recover from them through long-term operational resilience.
The challenge of meeting compliance requirements is becoming an increasingly heavy burden for CIOs. Many of the projects they undertake within their portfolios are therefore designed to help companies prepare to comply with new regulations that are about to take effect… or to catch up on the issue.
Given its critical role in the overall functioning of the economy, the financial sector (banks and insurance companies, credit institutions, investment firms, payment service providers, etc.) is subject to numerous directives and regulations. Within the European Union, the DORA Regulation (Digital Operational Resilience Act), which is structured around five pillars, is one of them.
With the countdown underway ahead of its effective implementation and transposition in each EU member state (on January 17, 2025, exactly two years after its entry into force), the level of preparedness among the various entities involved appears to be uneven. While large institutions have been anticipating this issue and preparing for it for several years, many smaller institutions are not as far along and are watching the deadline and the risk of penalties approach with concern.
With just a few weeks left until the deadline, there’s still time to tackle the issue with a realistic plan of action based on a reverse schedule… but above all, to change our perspective on DORA. While the framework it provides undeniably imposes constraints on businesses—and even more so on CIOs— it also presents a genuine opportunity to shift perspectives on the management of risks related to ICT ( information and communication technologies) and may even serve as a catalyst for accelerating digital transformation.
What are the intentions behind DORA and why was it set up?
As its name suggests, the DORA regulation aims to support and frame the digital operational resilience of the financial sector. In a way, DORA is an extension of the NIS2 Directive(Network and Information Security Directive 2), which aims to strengthen the Cybersecurity and resilience of infrastructures in many sectors, with a greater emphasis on business continuity for critical financial services.
Of course, most companies and institutions in the financial sector did not wait for DORA to implement measures to prevent and manage risks, particularly those related to ICT, with cyber risk at the top of the list. This focus on ICT risks is all the more justified given that the system has, in the past, been severely tested and destabilized by unforeseen incidents and undetected vulnerabilities.
Even more recently, in the summer of 2024, a bug in the update of a component used by numerous applications worldwide caused a global blackout affecting the proper functioning of many applications, notably financial ones, thus revealing the fragility and dependence of the system (in the absence, however, of any malicious intent).
This recent development perfectly illustrates the laudable intention behind the European regulator’s DORA initiative: an incentive to shift paradigms. Specifically , when a risk occurs—whether it is a simple disruption, an incident, or an attack— the directive aims to ensure that affected companies are aware of the situation and can prepare to withstand, respond to, and recover from it—not merely to be able to defend themselves. In other words, proactively “tackling” the issue rather than remaining in a defensive posture, based on the assumption that the occurrence of identified risks is more than likely. This is a necessary step to preserve the stability of the financial system at the European and even international levels.
From this premise stems a new vision of IT risk governance, in which the CIO obviously has a key role to play, alongside risk management and internal control.
Does DORA represent a simple regulatory constraint or a real opportunity for IT?
DORA regulations require financial institutions to strengthen their organization, processes and technologies to prevent and cope with ICT risks, and ensure optimum Incident management. While this is undeniably a sound, common-sense move to strengthen system resilience, the scale of the issue is far from negligible. Paradoxically, however, some CIOs seem more concerned about the risk of non-compliance (and the associated penalties) than about their management’s inadequate preparation for the risks involved.
Of course, the extra workload involved for the entities concerned cannot be underestimated. On the face of it, it may seem easy to implement, thanks to its division into 5 distinct pillars, but putting it into practice proves to be far more complex, with numerous ramifications (reflecting the complexity of the financial system’s particularly extensive and interconnected information systems), and all the more so when the maturity linked to processes and documentation is not the most advanced in the organization. One point in particular is attracting the attention of CIOs, and could be the Achilles’ heel of organizations: a href=”#title5″>Tracking third parties – IT service providers.
However, beyond the imperative of meeting compliance requirements and showing “white hat”, DORA can be seen as an opportunity to accelerate the organization’s Digital transformation.
How can DORA help accelerate digital transformation?
The need for compliance may therefore make it imperative to accelerate certain projects or adopt new technologies that might otherwise be postponed were it not for the threat of severe penalties—particularly financial ones—imposed by the regulator. Put another way: the investment—which is often substantial and sometimes struggles to garner sufficient attention when it is championed “only” by the CIO and has no immediate business impact may be easier to justify in decision-making when faced with a non-compliance threat raised by internal audit, which often has the full attention of senior management.
DORA can be applied to a wide range of projects:
- Strengthening Cybersecurity, and in particular implementing operational resilience tests to prevent cyber attacks.
- In-depth analysis of cloudification strategies to optimize data management and business continuity.
- Automation of ICT incident management to improve fault detection and handling.
- Better identification and consideration of third-party risks and vulnerabilities.
Even when dictated by regulatory constraints, these Projects are nonetheless global assets for the information system as a whole, driving greater operational efficiency and performance (improved organizational agility and responsiveness) while reducing costs.
More generally, these digital resilience measures have a positive impact on an organization’s global competitiveness. What’s more, for international groups, DORA encourages and offers the opportunity for financial institutions toharmonize their ICT risk management rules on a supranational scale. This raises the level of operational resilience for the entire organization, a dynamic that is all the more relevant given the widespread globalization of financial systems.
In an industry as critical and competitive as banking and insurance, the ability to ensure business continuity in the event of an incident or crisis, and to demonstrate a robust, secure, and resilient information system, builds trust and credibility and thus directly benefits customer satisfaction. That could make all the difference. On the other hand, a system failure could have serious consequences, particularly in terms of reputation.
How does DORA offer an opportunity to reconcile Manage project risks within the organization?
Logically, all banking, financial and insurance institutions have Teams dedicated to internal control – the weight of European regulations and the requirements of national prudential and supervisory authorities make this a necessity. Nevertheless, the control of specific ICT-related risks often remains a blind spot – or at least less precise – in their actions. The main reasons for this are
- insufficient technical mastery of this type of risk and its criticality (which is precisely why the CISO function exists);
- the difficulty of accurately mapping all the stakeholders involved. In this respect, the identification and supervision of all ICT service providers is – according to the sector’s CIOs – particularly complex, and made even more difficult by the incidence of shadow IT, which tends to make some suppliers and their potential vulnerabilities invisible (even to the IT department itself).
To remedy this situation, the collaboration of the Internal Control – CISO – CIO trio is essential. That’s why some – like Wavestone, which calls it a “holistic approach to ICT risk management” – see DORA as an opportunity to reconcile ICT risk management within a global approach and coherent, unified governance: risk assessment, particularly for Cybersecurity, Business continuity AND IT services, Reporting.
To succeed, this unified governance must be based on 2 essential levers:
1. Capitalize on the “CIO-RSSI-internal control” trinity
All three play a key role in the successful implementation of DORA. Effective compliance management relies on a thorough understanding of how all of the company’s operations and their ecosystem function, in order to identify the ICT-related risks and threats that could affect it. A comprehensive inventory is essential (even though it will subsequently be refined through a criticality assessment).
In highly digitized organizations such as those in the banking and insurance sectors, the Internal Control department will undoubtedly need the expertise and input of the CIO and CISO to identify IT risks and assess their potential impact, and determine their respective levels of criticality.
A new form of governance must therefore be put in place, and we mustn’t overlook the opportunity this presents for the IT team to position itself as a strategic, constructive and proactive partner, to deal with these issues with the responsibility they deserve.
2. Strengthen the internal culture around risks and operational resilience, and benefit from better listening by management.
Quite naturally, the new governance structure that will be put in place to meet DORA requirements should increase the attention paid to the issue of risk, for all levels of the company. If many stakeholders are mobilized on the subject, it’s because it’s important and deserves attention. While the issue of IT risks is not always considered in the light of its potential impact, this is an opportunity to drive real change in the organization, which cuts across all entities, since ICTs permeate every stratum and component of the company, and to promote a culture of risk – and better still – of resilience.
In both cases, this is a clear opportunity for the CIO to reinforce its collaborative dimension, to demonstrate its openness and ability to “evangelize” the most technical subjects for the benefit of the organization.
What are the particular issues involved in Tracking third-party suppliers for DORA?
CIOs are paying particular attention to one of the five pillars of DORA: managing the risks associated with critical ICT service providers (such as cloud or technology service providers, which are widely used by all companies, especially those in the financial sector).
These ICT suppliers, otherwise referred to as ” third parties ” in the regulation, must be assessed and regularly audited in line with DORA’s resilience standards. It is up to them to prepare for this, but above all it is up to the financial organizations to ensure that they are doing so, and to be able to take the appropriate measures in the event of non-compliance.
DORA implies the implementation of a rigorous supplier monitoring framework, and strict contract management including reinforced resilience and security clauses to ensure that critical suppliers are as compliant as the financial entities themselves.
This adds a further layer of complexity to the already dense and complex tracking of suppliers and contracts within the CIO, due to the number of contractors, the technical nature and specific features of contracts (terms of commitment, SLAs, termination or non-renewal clauses, etc.), and sometimes the dependence on certain particularly critical suppliers.
Although it is not alone in this area (alongside the Audit-Compliance and Purchasing Departments in particular), the CIO will inevitably be in the driver’s seat when it comes to creating, maintaining and sharing an exhaustive register of suppliers, determining their criticality in relation to the organization’s IS, monitoring and evaluating periodic audits, and reporting on them.
A number of CIOs in this sector capitalize on Abraxio’s Vendors module for tracking purposes, sharing the resulting repository with other stakeholders in their organization. In addition to centralization and the ability to easily share relevant data with all parties concerned, the result is a real-time financial view of the impact of a particular Contractor on Projects or activities undertaken by the CIO. A key asset in securing this Vendor relationship management, in the perfect spirit of the DORA directive and expectations.
What are the key points to remember about DORA?
Effective date: January 17, 2025
Possible sanctions for non-compliance: financial penalties, commercial restrictions, increased surveillance by regulatory authorities.
The 5 pillars and key obligations of the regulation:
- Manage project risks: put in place robust policies to identify, assess and manage risks related to information and communication technologies, including governance systems; in particular, strengthen Cybersecurity and continuous monitoring systems to deal with cyberthreats.
- Operational resilience of information systems: implement procedures to ensure continuity of services in the event of disruption, including monitoring, detection and management of ICT incidents.
- Third-party supplier monitoring: review and tracking of ICT service outsourcing contracts to supervise and manage ICT risks from third-party suppliers, notably by imposing contracts requiring resilience and security of the systems supplied.
- Incident management and communication: Tracking and classification of incidents, implementation of appropriate corrective measures, procedures for rapid reporting and declaration of incidents to the relevant regulatory authorities.
- Regular digital resilience tests and audits to ensure compliance, with regular procedure updates.
What are the six priority work areas if your organization is not yet ahead of DORA?
- Take the existing situation in terms of ICT risk management within the organization as a starting point , to assess the gaps in meeting DORA compliance requirements; based on this analysis, draw up realistic action plans in line with the implementation timetable.
- Develop processes that are sustainable and viable over time : Work on and implement the relevant policies, procedures and controls to deal with any changes that may occur in the “ICT” perimeter; acquire the relevant tools to achieve this.
- Initiate and schedule resilience and penetration tests without delay to get a good assessment of your system.
- Optimize identification and management of risks associated with third-partycontractors (Third Party Risk Management – TPRM)
- Ensure that procedures and documentation are up to date and operational to guarantee incident tracking and response, and business continuity or recovery.
- Raising awareness of risks and Cybersecurity among all employees at all levels of the organization (particularly through training).


