The EU’s Digital Operational Resilience Act (DORA) is a shift in cybersecurity regulation from focusing on preventing cyberattacks to ensuring the ability to recover quickly and effectively from cyberattacks (a concept commonly referred to as cyber resilience). is shown.
DORA was adopted in November 2022 as part of the EU’s Digital Finance Strategy 2020, which sets the goal of Europe becoming the Digital Single Market for Financial Services.
It aims to improve the resilience of the financial sector to operational disruptions such as cyberattacks.
wide range
DORA was adopted in response to EU regulators’ concerns that the financial sector is not doing enough to mitigate cyber threats, according to Cyberzen co-founder Jean-Philippe Gaulier. It says.
“Specifically, EU regulators probably did not have big banks and insurance companies in mind when they drafted this bill, but they are the most well-prepared in the world when it comes to preventing and recovering from cyberattacks. As one of the more well-established companies, they were probably thinking of other, perhaps less regulated institutions, “that play a role in modern financial services,” he said. Information security.
DORA therefore applies to a wide range of financial institutions, including banks, insurance companies, investment firms, cryptocurrency exchanges and trading platforms, and their significant third parties.
five pillars
This regulation is based on five pillars:
- Cyber risk management
- Cyber incident management
- Digital operations resilience test
- third party risk
- Information sharing
The first three pillars include various actions to improve the resilience of financial institutions, such as developing risk management plans, incident response plans, recovery plans, and conducting regular audits and penetration tests. .
DORA also details what should be included in each process (risk management framework, incident reporting, etc.).
supply chain risk
DORA supersedes other cybersecurity laws in the EU, requiring financial service providers to comply with stricter rules covered by both versions of the Directive on Networks and Information Systems (NIS and NIS2). there is. For example, NIS requires businesses to report cyber incidents within 72 hours, while DORA-covered organizations must provide initial notification within 24 hours, additional interim reports within one week, and final reports within one week. Must be sent within one month.
But the most drastic change introduced by DORA is to address supply chain risks, said CREST EU Council President Rodrigo Marcos. Information security.
“So far, none of the organizations have any liability to third parties. It should be applied to critical third parties and updated regularly,” he said.
If a covered entity fails to comply with DORA, the European Supervisory Authority (ESA) can impose fines of up to €10 million ($10.8 million) or 2% of the financial institution’s global annual turnover, whichever is greater.
Inspiration
Marcos said DORA is great news for the financial sector.
“First, as suggested by Pillar 5, the bill will further facilitate cooperation among financial service providers within the bloc,” he explained. Because financial service providers and other industries are doing the same, and in the future, other sectors may adopt additional cyber resilience measures as well. Finally, I think it’s very likely that similar laws will be introduced in other jurisdictions, as happened with the General Data Protection Regulation (GDPR). ”
DORA technical standards will be published in early 2024 and the law will apply to EU member states from 17 January 2025.
Register for Information Security Europe | 20-22 June 2023