Analysis
DORA for financial-sector CISOs: the resilience rulebook, explained
The EU Digital Operational Resilience Act explained: who it covers, the five pillars, ICT third-party oversight, and what changed for security leaders in finance.
TL;DR: DORA is the EU's operational-resilience rulebook for finance, directly applicable since January 17, 2025. It standardizes five things — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing — and, most consequentially, drags the financial sector's critical technology vendors under direct European supervision. For CISOs in finance, it converted resilience from a supervisory expectation into hard law with technical standards.
What are the five pillars?
ICT risk management. A documented framework owned by the management body: asset inventory, protection, detection, response and recovery, learning, and communication. DORA's governance language mirrors NIS2's — the board approves, oversees, and is accountable.
Incident reporting. Harmonized classification of ICT incidents and mandatory reporting of major ones to the competent authority on a staged timeline (initial, intermediate, final), with templates set by technical standards. The intent is one European reporting language instead of a patchwork.
Digital operational resilience testing. Every covered entity must test; significant ones must run threat-led penetration testing (TLPT) — regulator-supervised red-team exercises on live production systems, in the lineage of TIBER-EU — on a multi-year cycle.
ICT third-party risk. A register of all ICT service contracts, mandatory contract provisions (audit rights, exit plans, sub-outsourcing transparency), concentration-risk analysis, and — the novelty — designation of critical ICT third-party providers who are directly overseen by European supervisory authorities. The cloud providers your bank runs on are, for the first time, inside the regulatory perimeter themselves.
Information sharing. A legal basis for financial entities to exchange threat intelligence within trusted communities.
What does DORA change in practice for the CISO?
Three shifts. From policy to evidence: DORA's regulatory technical standards specify what the framework must contain; supervisors examine artifacts, not intentions. The contract register alone is a substantial data exercise for a large institution. From annual pen test to TLPT: threat-led testing against production, supervised by the regulator, is a different operational and political animal than a scoped assessment — it needs executive sponsorship and careful legal framing. From vendor questionnaires to vendor governance: exit strategies for critical providers must be real, documented, and tested, which forces uncomfortable questions about concentration on a single cloud or core-banking platform.
How should a financial CISO sequence compliance work?
Anchor on four artifacts supervisors ask for early: the ICT risk-management framework document with board approval minutes; the incident classification and reporting procedure mapped to DORA's criteria; the complete third-party register with contract-clause gap analysis; and the testing program, including the TLPT plan if the entity qualifies as significant. Where the institution already runs NIS2 or national outsourcing-guideline programs, map rather than duplicate — DORA generally supersedes as lex specialis for financial entities, and one integrated control set with two regulatory mappings beats two programs. The strategic read: DORA treats resilience as a market-stability issue, which means the CISO's budget conversation in finance now has a regulator standing silently behind it.
Frequently asked questions
- When did DORA start applying?
- DORA applies from January 17, 2025. It is an EU regulation, not a directive, so it applies directly across member states without national transposition.
- Who does DORA cover?
- Nearly the whole EU financial sector — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more — plus, for the first time, critical ICT third-party providers serving them, who come under direct EU oversight.
- How is DORA different from NIS2?
- NIS2 is a broad, cross-sector directive transposed nationally; DORA is a financial-sector regulation that applies directly and in more depth — including mandated resilience testing, detailed ICT incident reporting, and an oversight regime for critical technology vendors. For financial entities, DORA is the more specific rulebook and generally takes precedence.
Sources
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.