Insights

The EU’s Digital Operational Resilience Act (DORA)

DORA is a very large and complex piece of regulation. We’ve identified the following four key challenges faced by our clients as they move towards compliance.

1. What does ‘proportionate’ even mean?

DORA is designed to be a proportionate regulation – you take ‘proportionate’ steps to protect yourself, depending on your risks and the impacts your customers might face. This is, frankly, great news, and a welcome step away from control-focused regulation that essentially hands hackers a head-start into your security controls.

The difficulty is who decides what counts as proportionate for you? How can you be sure that the
regulator will agree with you that the steps you’ve taken are appropriate? And – the central question – do you understand your business sufficiently to answer these questions with absolute confidence

2. How do you balance risk with business opportunity?

DORA requires organisations to think carefully about the third parties on which they depend. For many of our clients this has meant letting go of some relationships of convenience. On the one hand, working with a single third-party who covers everything you need can make life much easier. On the other, it opens you up to potentially catastrophic risk should that supplier suffer damage.

As we see increasing interest from threat actors targeting supply chains to gain access to our clients’ networks, there’s also the concern that by diversifying your supply chain, you are in fact opening yourself up to even more opportunities for compromise and decreasing your resilience as a result. Are you just pushing dependencies further into your supply chain and out of sight, or are your back-up suppliers genuinely independent and giving you greater resilience?

3. Are your teams prepared for real threats?

Financial organisations are rarely dealing with manageable, simple IT estates, or facing easily defined threats, and this makes advanced penetration testing vital to the cyber security health of your business. DORA takes a step back from the checkbox penetration testing that has been required by previous regulations and frameworks (PCI DSS, ISO 27001, SOC reporting, and NIS, among others), and demands the bigger picture: what will the threat actors that matter most to you attempt to do on your network?

Consider whether you are working with providers that have sufficient experience across APT and
criminal threat actors to stay up to date on the different tools techniques and processes they will
deploy against you. Are your external consultants translating this experience into realistic, meaningful operations designed to test your network?

4. Who is reporting what, where, and when?

DORA introduces a number of reporting requirements, including a 24-hour window to submit an initial incident report to the regulator – which must include an indication of whether the incident is thought to be malicious, and potential cross-border impacts. Balancing planning with agility in your response teams will be key. SOCs and monitoring teams will need to know clearly who they escalate to, and the timelines that escalations must happen within. Everyone needs to know their responsibilities under DORA to avoid an incident being buried.

As you plan, consider how you are training and testing your SOC and monitoring teams. Are there key person risks or single points of failure? Are your technical teams developing at the same rate as the hackers? What assurance do your stakeholders need so that they can respond in the right way and with sufficient speed?

Your journey to compliance – Do security andopportunity have to be enemies?

DORA comes into force on 17 January 2025 – so there’s not much time left to begin executing on your strategy to be compliant. Our thinking around DORA has three major pillars (and if you ignore everything else in this article, these are the things to take away).

1. Foundations, foundations, foundations
How can you get proportionality right if you’re building your house on sand? It is vital to start with the basics. What data do you have, and how have you classified it? What processes are critical to your business? On which parties are you dependent? We all know that these questions are simple to ask and a lot harder to reliably and accurately answer, but confidently knowing the answers could save a lot of money, time, and effort in the medium to long term.

2. Communication from day 1
DORA compliance has already been, and will continue to be, a lot of work. Plan your reporting to the regulator now to make sure that you avoid having to build an evidence case in the event of an incident. Think today about how you are documenting the planning and work that has gone into your security and resilience programme. By building regulator-friendly documentation as you plan, you’ll side-step the panic when regulators ask for evidence of compliance later. You will also be able to share valuable information for your boards, risk committees, and stakeholders on demand.

3. Carpe diem (and the other opportunities)
DORA compliance isn’t just about DORA compliance. DORA requires financial organisations to start thinking about leading the way in operational resilience. Start looking for the carrots you can seize, as well as the sticks – this is an opportunity for your organisation to improve your resilience, which in turn will lead to increased customer and client trust. DORA can be a new marketing tool for you, as much as it is a regulatory obligation.

How can G3 help?

We take a risk-based approach to cyber security, identifying the risks that could produce severe financial, regulatory, reputational, or safety business impacts. Our analysis is always accompanied by an actionable plan for resolution.

  • Our targeted risk and maturity assessments are designed to give you assurance that you have the
    right foundations in place. We define your key risks and define the controls required to help you mitigate them within your risk tolerance. This can inform your decision-making, and provide a communicable document to show the regulator the process by which you have selected pragmatic and proportionate security controls. Our assessments balance security considerations with your business priorities to support a realistic approach to security across your organisation.
  • Our advanced threat attack simulations emulate the tactics, techniques, and procedures of
    advanced threats, simulating real threat movement through your networks, and helping you test your defence in depth. We help you understand which threat actors are most relevant to you, and what they can do to harm your business.
  • Our advanced penetration tests are designed to give you assurance in your SOC’s ability to respond within the required timelines for DORA. We test your SOC’s ability to detect us, but also their root cause analysis, to help you understand areas for growth and potential risks.

To discuss the issues raised in this article or for more information, please contact:

Kate O’Loghlen, Global Head of Cyber

kateologhlen@g3.co