Back to blog

DORA 2025: The Turning Point for Financial Cybersecurity in Europe

JA
Jean-Baptiste Artignan
CEO
February 9, 20244 min read
DORA 2025: The Turning Point for Financial Cybersecurity in Europe

At a time when cybersecurity is becoming an absolute priority for the financial sector, Regulation (EU) 2022/2554, known as DORA (Digital Operational Resilience Act), establishes a rigorous framework designed to strengthen the digital operational resilience of this sector.

The DORA Regulation was published in the Official Journal of the European Union on 27 December 2022 and entered into force on 17 January 2023.

This regulation establishes a detailed and comprehensive framework aimed at improving the digital resilience of financial entities within the EU, incorporating uniform measures for managing risks related to information systems and network security.

This regulation highlights the new requirements imposed on financial organisations, underlining the importance of cybersecurity awareness as an essential means of preventing cyberattacks.

Organisations affected by DORA

The regulation applies to a wide range of entities in the European Union's financial sector, including but not limited to banks, insurance companies, asset managers and payment service providers. These organisations play a crucial role in the economy and are therefore required to comply with high cybersecurity standards to protect customers' financial assets and personal data.

Scope

The date of direct application of DORA is set for 17 January 2025. By then, financial entities and ICT service providers must prepare to implement the requirements set out in this regulation. At the same time, the European Commission will publish delegated acts based on the final draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) submitted by the European Supervisory Authorities (EBA, EIOPA, ESMA). These texts will clarify certain DORA requirements and form a second layer of this new regulatory framework.

It is important to note that Directive (EU) 2022/2556, which accompanies the DORA Regulation, must also be transposed into national law by EU Member States by 17 January 2025. This directive aims to amend existing directives in order to align them with the new provisions of DORA, thus affecting a wide range of directives such as CRD IV, PSD2, BRRD, Solvency II and many others.

The financial entities covered by DORA encompass a broad range of financial sector players, including but not limited to credit institutions, investment firms, payment institutions, insurance and reinsurance undertakings, as well as ICT service providers operating within the EU. This regulation highlights the need for a proactive approach to ICT risk management and cybersecurity, focusing on entities' ability to withstand, respond to and recover from any significant operational disruption.

In summary, financial entities must actively prepare for the full application of DORA in January 2025 by assessing and adapting their current digital operational resilience practices and procedures to meet the requirements of this ambitious and comprehensive regulation.

New DORA cybersecurity obligations

The obligations introduced by the regulation include implementing information system risk management policies, conducting resilience testing, mandatory reporting of ICT-related incidents, and establishing frameworks for managing risks associated with third-party ICT service providers. These measures aim to ensure that financial entities have the tools and procedures needed to detect, prevent and respond effectively to cyber threats.

Cybersecurity awareness

The regulation places particular emphasis on the need to raise users' awareness of cybersecurity issues. It highlights the importance of organising regular training sessions and conducting employee awareness campaigns to familiarise them with IT security best practices and help them identify phishing attempts and other types of cyberattacks.

Phishing simulations

Phishing simulations are also encouraged as an effective way to assess and improve employee preparedness for cyberattacks. By creating realistic phishing scenarios, financial organisations can test their employees' vigilance and strengthen their ability to recognise and respond appropriately to fraudulent attempts via email or other digital channels.

The BlueSecure solution

In this context, a solution such as BlueSecure offers several advantages to help companies meet these requirements, including:

  1. Information system risk management: BlueSecure provides a platform to identify, assess and mitigate ICT risks related to user behaviour, thereby facilitating the implementation of a risk management framework that complies with DORA requirements.
  2. Cybersecurity incident reporting: By offering tools for tracking and rapidly reporting phishing-related incidents, BlueSecure helps financial entities comply with the reporting obligations imposed by DORA.
  3. Digital operational resilience testing: The solution includes simulation features and phishing attack testing to assess the company's ability to withstand attacks in accordance with the resilience testing required by DORA.
  4. Cybersecurity awareness: Through the deployment of micro-learning modules, interactive games and escape games for users, BlueSecure facilitates the sharing of cybersecurity information and best practices throughout the organisation.

 

By

JA

Jean-Baptiste Artignan

CEO

Share this article