DORA, Resilience by Design 

 

 

 

Uncover the details of the Digital Operational Resilience Act (DORA) and understand its impact on regulations.

I was lucky enough to have taken the last week off, and I was supposed to be on holiday, but things did not work out like that. 

Rather than get frustrated, I decided to read, and since DORA is hot on everyone’s lips, I decided to dig a bit deeper. 

Like most people I started with the regulation, and it was challenging work, but at least it got me going. I then did a lot of research on what other DORA information is out there and in the process of doing so I came across Oliver Wyman. Their insights were clear and helpful. 

So now after reading and researching GDPR (General Data Protection Regulation), NIS2 and now DORA I am starting to see a model behind the regulations. DORA holds a light up to something we have all known for a long time and have chosen to either ignore or sideline. The simple truth is organisations have been running critical business services for years without understanding the true risk or putting the proper protection in place. Why? Because it is hard. 

To quote Oliver Wyman  

“Complying with DORA will not be easy – it requires a purposeful and deliberate business-led technology strategy, and an integrated risk management approach aligned to critical business services.” 

However, there is reason to be optimistic. 

The introduction of DORA finally gives financial institutions the push to do what should have been obvious. Let me set out for you what is required: Firstly, they need to identify critical business services through quantitative analysis, understand the true ALE and SLE for each and prioritize accordingly. 

Then they need to model out these critical business services, understand how they fit together, where they have dependencies, identify any single points of failure, and any concentration of risk with third parties 

Finally, they need to build recovery plans that are based on the full picture they have by then defined and really test those plans making sure they surface any weaknesses and that those critical services are fit for purpose. Any identified weaknesses should be raised to senior management. 

On an ongoing basis the business must then proactively monitor the services and continue to identify vulnerabilities, track incidents and if relevant report them to relevant bodies, which is one of the keys to the resilience that DORA will create – sharing information within the industry in trusted circles means each set of data strengthens the whole. 

In a world of cyber warfare, ransom attacks and geopolitical upheaval, we the public need to have faith in our financial institutions, we cannot afford another banking crisis as in 2008 and 2023. 

DORA gives us the roadmap for Resilient by design and using the business services as the centre you can build up a complete picture of health using the five pillars. Let Me run you through the 5 pillars of that design and key elements: 

 

Pillar 1 risk management and governance 

This is your foundation. With this layer you build you policies and processes, you identify your risk framework, your controls and governance to document the roles and responsibilities. Understanding what processes, you have in place, and which may need to be implemented. From incident management to backup policy, from Vulnerability scanning to Audit review. 

Key questions; do you have a quantitative risk process in place?; who is responsible for Business Continuity management?;  how do you monitor and detect unusual behaviour? 

If you are starting with DORA, performing a gap analysis either internally ,or with help, to understand what you do have and what is missing is a necessary first step. 

Trying to implement without this would not be advised. 

A highlight in pillar 1 is this: 

Financial entities shall use and maintain updated ICT systems, protocols, and tools.  

Now there is a requirement to use the right tools for the right job and they must be kept up to date. 

This is a great opportunity to look at your gap analysis and see if multiple requirements can be satisfied by consolidating onto a more modern platform-based software that can perform multiple processes on a single platform and share data. 

 

Pillar 2 ICT related incident reporting 

This is your front line of defence; this is where you are setting up early warning indicators to detect problems and alert the teams.  

If incidents do occur, you need to understand the scope and scale of an incident. Was there data loss? Which services were affected? Were financial counter parts affected? 

The goal here is to understand exactly what happened so that you can analyse and report major ICT related incidents to the relevant authorities quickly as well as feeding that information back into the problem and change process so that it does not happen again. 

To do this properly all information needs to be available, correlated and managed in a well-documented and practiced process. 

 

Uncover the details of the Digital Operational Resilience Act (DORA) and understand its impact on regulations.

 Pillar 3 Digital operational resilience testing 

This is where all the business strategy and IT technology needs to come together in a robust, resilient design, monitored and constantly updated model. This is where DORA starts to fit in the jigsaw of EU regulations. While GDPR is privacy by design and NIS2 is Security by design. DORA adds to the model by putting resilience at the heart of design architecture. 

Uncover the details of the Digital Operational Resilience Act (DORA) and understand its impact on regulations.

DORA defines a risk-based approach to operational resilience testing, with critical Business Services tested at least once a year. 

This needs to be done in detail as defined in Article 24  

  • The digital operational resilience testing program shall provide for the execution of a full range of appropriate tests.  
  • Including vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing, or penetration testing.  

This gives the Business Continuity team the focus and support for the valuable service they provide, creating visibility for the board and senior management ensuring that this is no longer just an IT issue. It affects the bottom-line profit and should be treated as such. 

Operational resilience and Business Continuity management are now front and center requiring the proper funding and tools. Understanding the complex interconnectivity of services, hardware, software, and vendors is no longer a job for spreadsheets. Having all relevant data brought together in a single place is the only way teams can make intelligent decisions, and that data must be accurate and current if companies are to truly protect their services. To keep pace with the changing view of the world, the teams must look to automate and cut down on the manual repetitive work allowing them to focus on the right place. 

If they fail, the company fails, it is that simple. 

 It is no surprise that focusing on adding value, and triaging the most critical work, will become increasingly important as systems and companies grow in the 21st century. 

Pillar 4 ICT Third Party Risk 

Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework and in accordance with key principles for ICT third party risk management issued by the regulatory authority.  Article 28 

Third party management has always been managed differently from internal risk. Historically procurement and cost management have driven decisions, now, however, after the war in Ukraine and the supply chain difficulties that resulted, third parties are being looked at in a whole new light. 

Thanks to DORA Article 27 , how companies contract and maintain an understanding of what data is processed and at which locations is as important as cost. The obligations of collaboration in the face of an ICT incident mean that third parties need to be fully engaged with clear processes to resolve problems fast. 

So that’s why DORA is hot on Third party risk! What caught everyone out with the supply chain crisis on the back of the war in Ukraine was a lack of understanding of where and how their business-critical services were delivered. Leading to situations where, while the services were spread out, no one truly saw the concentration of risk. Company A gets their supplies from company B & C, resilience with separate sources, right? The problem was companies B & C used company D for parts, result … broken supply chain. 

With this new regulation, companies and third parties are required to dig deeper and truly understand the complete view of the supply chain and where there is a concentration of risk. 

Concentration risk 

  • When performing the identification and assessment of ICT concentration risk, financial entities shall take into account whether the conclusion of a contractual arrangement in relation to the ICT services would lead to any of the following: contracting with an ICT third-party service provider that is not easily substitutable or having in place multiple contractual arrangements in relation to the provision of ICT services with the same ICT third-party service provider or with closely connected ICT third-party service providers.  

Article 29 

So now while looking at supplier risk, companies must also now look closer at whether they are “putting all their eggs in one basket” where they cannot replace a supplier with another and mitigate the risk accordingly. 

 

Pillar 5 Information Sharing 

 To stay resilient to the changing state of the world you need good intelligence. Financial institutions are targets for cyber criminals and targeted attacks; in essence they are at war every day without you even knowing it. 

To quote Sun Tsu  

“Military intelligence is the key to war; without it, you cannot win.” 

Pillar five is all about bringing the financial institutions together; to share the vulnerabilities and attacks they have had in a carefully controlled way so that all can learn from it and the whole is greater than the sum of its parts. 

If one falls, they could all fall, so this pillar pushes for better communication to prevent such an event.  

There are already tools available to share information anonymously in what are called trusted circles, and one of the biggest challenges DORA will face will be who should decide what to share, when they should share and how they communicate. The regulation does not say how, only that they should. 

Proportionality principle 

If everything above now has you in a cold sweat, and sounds like an impossible task, there is a ray of hope. 

Yes, this is serious; and yes, this is important with real investment needed in time, resources, and tools. There is no getting away from that, and there should not be because it is too important to do half measures. 

However, the EU does understand that not all financial institutions are equal. 

Article 4 the Proportionality principle states: 

  1. Financial entities shall implement the rules laid down in Chapter II in accordance with the principle of proportionality, taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations.
  2. In addition, the application by financial entities of Chapters III, IV and V, Section I, shall be proportionate to their size and overall risk profile, and to the nature, scale and complexity of their services, activities and operations, as specifically provided for in the relevant rules of those Chapters.
  3. The competent authorities shall consider the application of the proportionality principle by financial entities when reviewing the consistency of the ICT risk management framework on the basis of the reports submitted upon the request of competent authorities pursuant to Article 6(5) and Article 16(2). 

 In other words, the bigger the institution and the bigger the services that are being provided the more effort needs to be taken to protect it based on its risk.  

Conclusion 

DORA demands a lot of the financial industry – and for good reason. When a crisis hits, it creates a knock-on effect and dominos fall. This became real with Leman Brothers and later with Silicon Valley Bank. To make companies take notice, the EU have set the financial penalties 

In relation to financial penalties, entities found to be in violation of the Act’s requirements may face fines of up to 2% of their total annual worldwide turnover or, in the case of an individual, a maximum fine of EUR 1,000,000. The amount of the fine will depend on the severity of the violation and the financial entity’s cooperation with authorities. 

Financial entities that fail to report major ICT-related incidents or significant cyber threats as required under DORA may also face fines. Third-party ICT service providers designated as “critical” by the European Supervisory Authorities (ESAs) may face fines of up to EUR 5,000,000 or, in the case of an individual, a maximum fine of EUR 500,000 for non-compliance with the Act’s requirements. The ESAs will have the authority to impose these fines. 

 Now this might look scary, but like everything in this world we need motivation to get started when something looks too big to tackle. DORA is big yes, but it is probable that a large amount of what your company is doing today can be used or revamped to support compliance with DORA. You will only know how big the job is in front of you if you start the gap analysis and map the road ahead. 

DORA entered force on 16th of January 2023 and will apply from 17th of January 2025. 

With the right support from senior management, the right team, tools, and the right roadmap, being compliant with DORA is possible. Remember it’s all about protecting the critical business services of your company. It’s not too late, start the conversation today. 

Disclaimer: This content was not produced using AI but is the random outpouring of my brain which I hope was of use to someone. 

 

 

 

Author

  • Lee has worked in the IT industry for over 23 years. He is ServiceNow architect with over 14 years ServiceNow Experience. For the last five years he has specialised in Integrated Risk Management. As a Certified specialist, trainer and solutions consultant, Lee has Worked with some of the biggest and smallest companies in the world helping the with their IRM journey. He currently acts as the Head of Solutions Consulting and a ServiceNow Architect at Wrangu.

    View all posts