DORA – What you need to know

The purpose of the EU’s new Digital Operational Resilience Act (DORA) is to ensure the safety and security of the financial sector’s digital infrastructure. DORA outlines a framework of rules and requirements for financial institutions, market infrastructure providers, and digital service providers. Here are the top things organisations need to know about DORA. 

  1. Scope and Coverage – DORA aims to strengthen the digital operational resilience of the entire financial sector. This includes payment service providers, digital asset service providers, and market infrastructure providers, among others. 
  2. Cybersecurity and IT Risk Management –  Organisations need to have robust cybersecurity and IT risk management frameworks that ensure the safety and security of their digital systems and services. DORA emphasises the need for risk-based cybersecurity practices and threat intelligence sharing. 
  3. Incident Reporting – DORA mandates that organisations report significant incidents to relevant authorities. DORA aims to create a unified reporting system that enhances coordination and information sharing between financial institutions, market infrastructure providers, and digital service providers. 
  4. Outsourcing and Third-party Risk Management – DORA emphasises the need for organisations to assess, manage, and monitor the risks associated with outsourcing digital services to third-party providers. It recommends that organisations conduct due diligence assessments before outsourcing services. 
  5. Business Continuity Management – The proposal requires organisations to have effective business continuity management plans in place to ensure that they can withstand and recover from significant operational disruptions. 
  6. Testing and Scenario Planning – DORA emphasises the importance of regular testing and scenario planning to assess an organisation’s resilience to various operational risks, including cyber threats, technology failures, and natural disasters. 
  7. Supervision and Oversight – National supervisory authorities will have a supervisory role in ensuring that organisations comply with the new rules and requirements.  
  8. Incident Response and Remediation – Organisations should have effective incident response plans in place to detect, respond to, and remediate significant incidents. DORA emphasises the importance of cooperation and coordination between organisations and relevant authorities in incident response and remediation efforts. 

In conclusion, the Digital Operational Resilience Act is a comprehensive framework of rules and requirements aimed at ensuring that the digital infrastructure of the financial sector is safe and secure. Applicable from 17th January 2025, organisations will need to assess their digital operational resilience against the requirements and take appropriate measures to comply with the new rules.  

If you would like to know more about how to streamline your risk and compliance needs, contact us or request a free tailored demo today.

 

Recent News

Paralympics Ireland choose CalQRisk to streamline their Governance, Risk & Compliance efforts 

Paralympics Ireland has recently implemented the CalQRisk solution to streamline their Governance, Risk Management and Compliance efforts.  Paralympics ...
Read More

Changes to ISO 27001

ISO 27001 is an international standard that outlines the requirements for an information security management system (ISMS). It ...
Read More

DORA – What you need to know

The purpose of the EU’s new Digital Operational Resilience Act (DORA) is to ensure the safety and security ...
Read More

ILCU and CalQRisk form Alliance

The Irish League of Credit Unions (ILCU) has collaborated with CalQRisk to offer a best-in-class governance, risk management ...
Read More
Database

Top Cyber Risks in 2023

In 2023, there are several cyber risks of which organisations and individuals should be aware. These risks can ...
Read More
office meeting at sunrise

10 Things to Ask When Outsourcing / Choosing a Supplier

Many organisations choose to outsource critical functions or services to third parties/contractors. However, outsourcing the work does not ...
Read More
risk assessment

Top Risks for Charities in 2023

As charities work to address some of society’s most pressing issues, they are faced with a wide range ...
Read More
financial growth - money sprouting a seed

Featured Risk – Failure to appropriately address Climate Risk and broader ESG issues

Risk is the effect of uncertainty on objectives. Climate change, along with its broader environmental, social and governance ...
Read More

CalQRisk wins CIR Risk Management Product of the Year

CalQRisk, an Irish-developed software application, has won Risk Management Product of the Year in the recent Risk Management ...
Read More
Database

How to Prepare for Cyber Attacks

The potential for cyber-attacks is an ever-increasing concern. Daily, there are stories about organisations, both large and small ...
Read More