The Digital Operational Resilience Act (DORA) has officially gone into effect today, January 17th, 2025, impacting all European Union (EU) financial services organizations and their Information and Communications Technology (ICT) suppliers. We know that this regulation has far-reaching implications, yet for many, there is still a question of relevance and criticality for US businesses.
The immediate focal point is that DORA is an EU regulation and as an EU regulation, it has no impact on organizations outside of the EU borders. Here’s where we don’t want to confuse EU governing body enforcement with impact to business operations. On the surface, it is correct to assume that if you do not operate within the EU zone—consisting of 27 countries with more than 448 million inhabitants—you are not controlled by the EU regulators. Not so fast. It’s more accurate to state that you are not directly controlled by the EU regulators.
Let’s break this down further so you’re not blindsided by DORA regulations. First of all, DORA is about resiliency of critical data. Much of the data leveraged by financial services organizations is no longer contained within the four walls of that organization. By extension, much of the data isn’t even contained within the confines of the country where that financial services organization is headquartered. A lot of the data we use has globalized even if our business is very much localized.
The DORA regulations address this globalization of data through the recognition of ICT suppliers. There are a number of ICT supplier definitions on the internet, which means you may or may not align as an ICT supplier to DORA-accountable organizations. Here are a few simple questions that may help you determine if you should pay attention to DORA:
- Does your business operate as a financial services organization?
- If yes, you may have DORA accountability, see question #2
- If no, you may not have DORA accountability, see question #2
- Do you have offices, clients or partners who operate within the EU?
- If yes, and you’re a financial services company, you have DORA accountability.
- If yes, and you’re not a financial services company, you may have DORA accountability. See question #3
- If no, you may have DORA accountability, see question #3
- Do you receive services from an EU located financial services organization?
- If yes, you may have DORA accountability if they share controlled data with your organization. Consult with the compliance department at your financial services partner.
- If no, you may have DORA accountability, see question #4
- Do you provide services to an EU financial services organization?
- If yes, but you are not part of their critical operations, and you do not handle any critical, controlled, or private data, you may not have any DORA accountability. Consult with the compliance department at the financial services partner.
- If yes, and you are part of their critical operations, especially if you handle any of their critical, controlled, or private data, you have DORA accountability. Consult with the compliance and cybersecurity leads at the financial services partner.
Now, you may not be under EU jurisdiction which means that you’re probably not going to have a EU DORA auditory knocking on your door anytime soon. Although, as an EU financial services third-party provider or ICT service provider, you will probably start receiving audit notices from your financial services partner or client in the near future.
As part of the resiliency requirements of DORA the EU financial services provider will have to prove resiliency into your operation. No, being out of DORA compliance will not result in a fine to your organization. But if you’re not compliant, then your partner/client is not compliant. The resulting impact may be a reduction or complete loss of business.
Now, let’s assume that you’re not an EU regulated financial services organization, and you don’t do business with any EU financial services organizations, partner, or customers. Does this mean that DORA doesn’t concern you? The answer may surprise you.
Remember when GDPR was first introduced? It was easy to state, “We don’t operate in the EU so we don’t have to comply with GDPR.”. Well, now we have a growing list of data privacy laws here in the U.S. that are all based on GDPR wording. GDPR set a global precedent, and DORA is likely to do the same. For those organizations that recognized GDPR early, the transition to regulations such as CCPA in California was relatively easy. Organizations who ignored GDPR are still struggling to catch up to the new U.S. regulations. DORA is much the same way.
We should look at DORA as a foreshadowing of U.S. regulations to come. There are key pieces to the DORA regulations that are coming to a regulation near you. The demand is increasing for better resiliency due to increased data theft, manipulation, and ransomware attacks. We all know that we outsource much of our data operations to third-party providers, such as SaaS operational platforms, cloud data storage & archive providers, data analytics (BI) providers, security operations centers, payroll services, billing services, health insurance processing services, and client relationship management (CRM) tools. These third-party organizations have become critical to the resiliency strategy. Given the amount of private and sensitive data they house, it is imperative that they properly protect that data from breach or operational disruption.
I recommend that US organizations embrace DORA as a guide for sound data resilience strategies. The ultimate purpose of DORA is to keep your operations safe from any disruption related to a cyber-threat. Make sure the critical data in your care is always secure and available when you need it. If you outsource operations and data to third-party vendors, make sure they’re securing your interest in a manner equal to or better than you would protect it yourself. Don’t rely on simple questionnaires; audit the answers and make them demonstrate the protections they’ve put in place.
One of the key DORA requirements relates to data encryption, and specifically encryption of critical data in use. DORA is the first regulation to identify that core database data must be protected in all three phases: encryption at rest, encryption in transit, and encryption of data-in-use.
Paperclip has more than 30 years of experience managing and protecting data, and we created SAFE® specifically for the protection of data-in-use. SAFE assures that all private and critical data remains encrypted at all times, even while actively supporting business operations. Designed for flexibility, SAFE integrates easily with operational applications through the application’s API layer, and can also be licensed directly into the platform itself. In both deployment models, data-in-use encryption remains seamless to end users and does not disrupt normal operational workflows, making it easy to view SAFE pricing and evaluate SAFE as part of a secure, scalable data protection strategy.
To learn more about Paperclip and the SAFE technology, visit www.paperclip.com/safe or contact me directly at cwalter@paperclip.com.
