You don't have javascript enabled.

Just one day to go till DORA: Are financial institutions ready?

With just one day to go until the Digital Operational Resilience Act (DORA) comes into force, financial institutions across Europe are making last-ditch efforts to meet its rigorous compliance requirements.

  • Editorial Team
  • January 16, 2025
  • 4 minutes

As the clock counts down to the January 17 deadline, Europe’s financial institutions are scrambling to meet the requirements of the Digital Operational Resilience Act (DORA). Designed to safeguard the sector against digital disruptions, DORA represents a seismic shift in regulatory expectations, leaving no room for complacency.

High Stakes for Financial Institutions

First proposed in 2022, DORA mandates financial entities to implement robust protections against ICT-related incidents. The penalties for non-compliance are steep: up to 2% of global turnover, alongside personal liabilities for executives.

“Regulations such as DORA are essential for financial institutions to maintain stability and mitigate operational risks,” says Chris Royles, EMEA CTO at Cloudera. However, the path to compliance has been fraught with challenges, particularly as firms grapple with the complexities of hybrid cloud systems.

“Hybrid cloud architectures,” Royles explains, “have emerged as a crucial strategy for financial institutions to navigate DORA while maintaining innovation and operational efficiency. This model provides the most flexibility, scalability and security of customer and business data, helping organizations adapt to regulatory changes while optimizing costs and ensuring business continuity. But hybrid cloud architectures can add more stress to an already complex system.”

Lauren Walters, Security Evangelist at Panaseer, underscores the challenge further: “CISOs need a reliable, centralized inventory that provides actionable insights – a golden source of truth data that includes all assets, controls, owners, criticality, and business context.”

 This is crucial for identifying vulnerabilities, prioritising fixes, and demonstrating a clear understanding of risk and resilience to both the board and regulators.” 

Third-Party Risks Dominate Concerns

One of DORA’s standout features is its stringent requirements for third-party risk management. Financial institutions must ensure their ICT providers meet high resilience standards, a task that has triggered a flurry of contract renegotiations across the sector.

“Building resilience means more than box ticking,” says Lee Wright, Senior Security Consultant at tmc3. “ DORA zeroes in on security maturity, requiring organizations to demonstrate robust processes and practices, rather than just meeting baseline standards.”

This emphasis on third-party oversight has created particular headaches for smaller firms with limited resources. Meanwhile, larger institutions, though better prepared, are leaving no stone unturned as the deadline looms.

A Challenge for Fintechs and Beyond

The regulation’s implications stretch far beyond traditional financial services, with fintechs and emerging players in the digital finance ecosystem feeling the heat.

Marios Joannou, Head of Digital Risk and Privacy at payabl, sees DORA as a pivotal moment: “DORA signals the end of the ‘move fast and break things’ era that accelerated growth but often left critical resilience gaps, exposing institutions and markets to significant operational risks. While it may look cyber security oriented, the reality is that DORA addresses a wide range of risks.

For all players, the message is clear: resilience is no longer optional. Joannou adds: “The harmonization of resilience rules between the UK and the EU reduces the need to navigate divergent frameworks. At the same time, dual compliance frameworks still create significant operational obstacles.

No Time for Grace

Unlike previous regulatory rollouts, DORA offers no grace period. As Bob Wambach, VP Product Portfolio at Dynatrace, points out: “Europe remains a key market for many of the UK’s largest banks and insurers, so compliance is essential to maintain trust and strengthen their relationships with customers. A failure to meet the same standards as banks in Europe risks creating a two-tier market divided into providers that are resilient by default and those that represent a risk to the customers that rely on them.

The stakes extend beyond compliance. Institutions must prove they can respond to disruptions swiftly and effectively. Wambach warns that checkbox approaches to compliance will fall short: “Organizations must prioritize continuous testing and real-time anomaly detection to mitigate risks before they escalate into incidents.”

The Final Hours

As institutions enter the final stretch, the pressure to meet DORA’s demands is palpable. Yet, for those that succeed, the regulation offers more than protection against penalties. By aligning operational frameworks with DORA’s stringent requirements, financial entities can enhance trust, operational stability, and even competitiveness.

“DORA is a continuous process – not a one off project,” says Wright. “If a business doesn’t understand which users are accessing what systems and why, or what controls they have in place, or where their most critical assets are, they’re never going to be able to deliver a good security framework.

For Europe’s financial sector, January 17 is not just a deadline—it’s a defining moment. The coming days will reveal which institutions are prepared to lead in a new era of digital resilience and which are left playing catch-up in a landscape where resilience is not just an advantage but a necessity.