Digital Operational Resilience Act (DORA) | Key Trends & Insights 6 Months After Implementation

Discover how the integration of Artificial Intelligence (AI) into penetration testing is revolutionising cyber security. Learn how AI enhances threat detection, automation, and predictive analysis to fortify defenses and ensure cyber resilience.
Digital Operational Resilience Act Key Trends and Surprises Six Months After Implementation

Digital Operational Resilience Act: Key Trends and Surprises Six Months After Implementation

The Digital Operational Resilience Act (DORA) has been in force for six months, and its impact on the European financial sector-and the cyber security landscape-has been profound. As a leading cyber security partner, Cybergate International has observed key trends, unexpected challenges, and emerging best practices as organisations adapt to this new era of digital resilience.

What is DORA?

DORA is a landmark European Union regulation enacted to ensure that financial entities can withstand, respond to, and recover from any type of ICT-related disruptions and threats, including cyber attacks of all sorts.

Its scope covers not just banks and insurers, but also investment firms, fund managers, and their critical third-party ICT providers, setting a new, uniform standard for operational resilience across the sector.

Key Trends Since DORA’s Implementation

Shift from Prevention to Resilience

DORA marks a strategic shift in regulatory focus: from merely preventing cyber incidents to ensuring organisations can recover rapidly and maintain critical operations during and after an attack. This has driven financial entities to invest in robust incident response, disaster recovery, and business continuity plans, rather than relying solely on perimeter defenses.

Broader Scope and Uniform Standards

One of DORA’s most significant changes is its broad applicability. The regulation now covers a wide array of financial entities and their critical ICT service providers. This has created a level playing field, with uniform expectations for cyber risk management, regardless of company size or sector.

Increased Scrutiny of Third-Party Providers

DORA extends regulatory requirements to third-party ICT providers such as Managed Services Providers and Software Vendors, compelling financial institutions such as FinTECH, Banks and payments companies to assess and monitor the cyber resilience of their respective vendors.

This has led to more rigorous due diligence, contractual requirements, and continuous monitoring of supply chain risks-a trend Cybergate International has seen accelerate across its client base.

Standardised Incident Reporting

The act mandates a centralised, standardised approach to reporting ICT-related incidents. Organisations must now have systems in place for rapid detection, internal escalation, and external notification of cyber incidents, including submission of root cause reports within tight deadlines.

Surprises and Challenges

Implementation Complexity

Many organisations underestimated the complexity of achieving DORA compliance. The need to align legacy systems, processes, and vendor relationships with new regulatory requirements has proven more challenging than anticipated, especially for smaller firms and those with extensive third-party dependencies.

Penalties and Enforcement

The severity of DORA’s penalties has surprised some in the industry. Non-compliance can result in fines up to 2% of global turnover for financial institutions and up to €5 million for critical ICT providers, with additional daily penalties until compliance is achieved. In extreme cases, authorities can even order temporary shutdowns or suspensions.

Ongoing Regulatory Evolution

While DORA is in force, the detailed technical standards and supervisory guidelines are still being finalised, creating a moving target for compliance. Organisations must remain agile, monitoring regulatory updates and adapting their cyber resilience programmes accordingly.

Relevance to Cyber Security

DORA’s requirements align closely with Cybergate International’s core services:

Penetration Testing: Regular testing of digital assets to uncover vulnerabilities before attackers do.

Cyber Security Awareness Training: Educating staff to recognise and respond to threats, reducing the risk of successful phishing and social engineering attacks.

Incident Response Planning: Developing and testing response strategies to minimise disruption and ensure rapid recovery.

Third-Party Risk Assessments: Evaluating and monitoring the security posture of vendors and partners, a critical DORA mandate.

Looking Ahead

Six months in, DORA is already reshaping the cyber security priorities of financial entities across Europe. As regulatory expectations continue to evolve, organisations must prioritise operational resilience, invest in proactive cyber security measures, and foster a culture of continuous improvement.

Cybergate International stands ready to support businesses on their DORA compliance journey, leveraging over a decade of experience to identify risks, strengthen defenses, and ensure operational continuity in an increasingly complex threat landscape.