DORA Checklist: Moving Toward Compliance

The January 17th deadline has come and gone, and it’s estimated that 99% of impacted organizations are out of compliance with the European Union’s Digital Operational Resiliency Act (DORA). DORA aims to improve and regulate the digital resiliency of a wide range of financial entities, including credit institutions, investment firms, insurance companies, payment institutions, and others within the EU’s financial sector. These organizations must start down the path of digital resilience and show progress toward compliance with DORA standards in the months ahead—or face the repercussions.

Here’s a breakdown of the steps toward digital resilience and risk management of Financial Institutions as mandated by DORA:

1. Establish Risk Management Framework
Financial organizations are required to define clear policies, procedures, and governance structures for managing Information and Communications Technology (ICT) risks—and keep them updated. Organizations are required to regularly assess risks related to the ICT systems and services that are critical to operations, including cybersecurity, data integrity, and service availability. They are also encouraged to define and document their objectives related to business continuity and operational resilience.

2. Ensure Third-Party Risk Management
As a foundational requirement of DORA, organizations must evaluate the risks posed by third-party service providers, such as cloud service providers, and ensure contracts are aligned with DORA’s resilience requirements. As part of this, DORA regulations suggest continuously monitoring third-party services to ensure compliance with agreed-upon standards and the organization’s established security requirements. And to limit disruption, organizations should have contingency measures in place for critical third-party services in case of service disruptions or failures.

3. Implement Incident Reporting Mechanisms
Under DORA, financial organizations must develop a clear protocol for identifying, reporting, and responding to ICT-related incidents. They are required to establish procedures to promptly report incidents to relevant authorities and ensure recovery procedures are in place to restore services after an incident, including the ability to track recovery progress.

4. Implement Better Data Protection and Confidentiality
To avoid, or lessen the impact of, an incident, DORA clearly defines preventative data security measures for better resilience. Encryption plays a key role in ensuring the confidentiality, integrity, and availability of private and controlled data in the face of cyber threats and ICT incidents. To achieve compliance with DORA, organizations must implement strong end-to-end encryption for sensitive data at rest (e.g., stored on servers, databases), in transit (e.g., transmitted over networks, including communication between clients and servers), and in use (e.g., used and queried as part of daily operations). This becomes even more critical as organizations expand their reliance on AI and other technologies that access and utilize sensitive data, making it essential to view DORA-compliant deployment options that support secure processing across the full data lifecycle.

 

“The use of any innovative technology, including artificial intelligence, should comply with Union data protection law, including the data protection principles of data accuracy, data minimization, fairness and transparency, and data security, such as state-of-the-art encryption.”

 

5. Create a Recovery and Business Continuity Plan
Establish a comprehensive business continuity plan that outlines how the organization will maintain or resume operations during and after a major disruption. Regularly test and revise the business continuity and disaster recovery plans to ensure they remain effective and up to date.

6. Maintain Documentation and Reporting
All this effort doesn’t mean much if organizations can’t show their progress. First, organizations should establish internal auditing processes to verify that your organization adheres to DORA’s requirements and to identify areas for improvement. Maintain detailed documentation for all ICT risk management processes, incidents, testing, and third-party management in order to remain in compliance with DORA. Regularly report to regulatory authorities as required by DORA, ensuring transparency in your organization’s resilience efforts.

Achieving compliance with DORA involves a holistic approach to managing ICT risks, strengthening cybersecurity, ensuring data security and privacy, building robust incident management processes, and ensuring third-party resilience. DORA’s requirements for ICT risk management align with best practices for data confidentiality, where encryption is a primary tool to mitigate risks related to unauthorized access to sensitive data.

Perhaps the biggest hurdle for DORA compliance is the low adoption of robust encryption technologies. Even those who are at the forefront of data encryption are heavily focused on data at rest and in transit—while in use data remains in plaintext and, therefore, at increased risk of exposure. DORA is the first major cybersecurity regulation to impose a specific mandate around encryption in use, which means organizations are going to have to catch on quickly.

By implementing strong encryption for data at rest, in transit, and in use, financial institutions can better protect against cyber threats, ensure data integrity, and meet the regulatory requirements set forth by DORA. Paperclip SAFE® always-encrypted technology can help your organization on this path to resiliency and compliance. Schedule an appointment with a compliance and security expert today.

 

Subscribe to Our Newsletter

This field is for validation purposes and should be left unchanged.
Select the Paperclip solution you are interested in.