DORA, one year on: what it really requires of finance, and why it reaches IT suppliers too
Not an attack, but the resilience framework the European financial sector must hold up under when incidents hit. Regulation (EU) 2022/2554 — DORA, the…
Topic · Compliance
The European rules governing security and data — and why they're not just red tape.
mediumFeatured dossierDORA, one year on: what it really requires of finance, and why it reaches IT suppliers tooRead the dossier →
Not an attack, but the resilience framework the European financial sector must hold up under when incidents hit. Regulation (EU) 2022/2554 — DORA, the…
Not an attack, but a deadline drawing closer. The Cyber Resilience Act — Regulation (EU) 2024/2847 — has been in force since 10 December 2024, but its…
The European legal framework rests on interlocking regulations and directives. The GDPR (Reg. EU 2016/679) governs the processing of personal data. NIS2 (Dir. EU 2022/2555) mandates security measures and incident-reporting obligations for operators in critical sectors. DORA (Reg. EU 2022/2554) does the same for the financial sector, with rules on digital operational resilience and critical ICT providers.
Compliance isn't filling in a form: it's a process. Risk analysis, proportionate technical and organisational measures, incident-notification procedures within set deadlines, governance with top-management accountability. NIS2 in particular shifts compliance from the IT department to the board.
The very measures the rules require — asset inventory, patch management, access control, response plans — are the ones that reduce real risk. Compliance done well isn't a cost separate from security: it is security, written down in a verifiable way.