What the Digital Operational Resilience Act Means for You

Milan Shetti

Par Milan Shetti

4 min de lecture

We’re at a critical time for digital transformation. Every business in some form or another is looking to adopt and integrate emerging technologies—whether that’s artificial intelligence, hybrid cloud architectures or advanced data analytics—to help achieve a competitive edge and reach key operational goals. But while there’s plenty of excitement and change underway, security risks and vulnerabilities have continued to follow right alongside that innovation. Cyber-attacks and data breaches can wreak havoc in a business’ IT systems, resulting in massive costs to fix the damage and a long-lasting impact to customers that could hamper a company’s growth for years to come.

As security risks grow more complex, government agencies are putting an emphasis on new regulations to help lay out what businesses need to do to protect their IT infrastructure while also establishing IT security standards. Things like the California Consumer Privacy Act (CCPA) or the General Data Protection Regulation (GDPR) have already had a tremendous impact on the urgency around prioritizing security infrastructure.

With that backdrop, let’s take a look at one of the newer security policies set to bring even more change to the way we think about, and approach, IT security—the Digital Operational Resilience Act (DORA). This piece of legislation in the European Union (EU) requires companies to be compliant by January 2025, meaning businesses have just under one year to ensure they’re prepared.

But what exactly does this policy mean for IT security? And how can businesses ensure they’re ready?

 

What is DORA?

Introduced in 2020—and later enacted in 2022—DORA aims to establish a consistent and common level of digital operational resilience across financial services firms in—or doing business with—the EU. The ultimate goal here being to develop an approach that fosters a standardized structure of technological development. The regulation requires EU financial entities and their critical ICT providers to adopt comprehensive information and communications technology (ICT) risk management capabilities into their security processes. Compliance with DORA will require full adherence to five critical areas of focus outlined in the regulation:

  • Gestion des risques liés aux TIC – Ce guide établit un cadre standard pour ce que les organisations doivent faire en réponse à un incident de sécurité des TIC.
  • Signalement des incidents majeurs liés aux TIC – La réglementation définit la manière dont les organisations devront désormais classer et signaler les incidents de sécurité liés aux TIC.
  • Tests de résilience opérationnelle numérique – Établit des lignes directrices pour tester les stratégies de récupération existantes afin d’identifier les vulnérabilités potentielles.
  • Partage d’informations et de renseignements – Exige que les entreprises s’engagent dans le partage d’informations sur les cybermenaces et les vulnérabilités dès qu’elles sont identifiées.
  • Gestion des risques liés aux tiers en matière de TIC – Les entreprises sont chargées de s’assurer que tout fournisseur tiers est en phase avec ses capacités de sécurité et de résilience numérique.

So, who needs to adhere to DORA? While it’s an EU policy with ramifications for EU businesses, the impact will undoubtedly affect businesses worldwide. DORA puts a heavy focus on financial organizations in the EU – from banks to insurance companies – but those are not the only businesses that will need to adhere to the policy. Any business that works with EU-based banks, insurers, or financial organizations will also need to maintain compliance, even if they are not actually based in the EU.

 

Getting prepared

Time is quickly running out for businesses to get their IT and mainframe security infrastructure ready to comply with the regulations specified in DORA. So, with no time to waste, where should they get started? There are several key areas to improve risk management, including:

  • Define clear roles and responsibilities: DORA outlines that management bodies will be expected to maintain an active role in adapting their ICT risk management framework and overall operational resilience strategy.
  • Implement a periodic review of ICT Business Continuity Policy and ICT Disaster Recovery Policy: Implementing a regular review cadence for ICT business continuity and disaster recovery policies is crucial for effective risk management oversight. According to DORA, “financial entities shall regularly review their ICT Business Continuity Policy and ICT Disaster Recovery Plan taking into account the results of tests carried out in accordance with recommendations stemming from audit checks or supervisory reviews.”
  • Consistently review budget related to fulfilling digital operational resilience needs: Preparing for a new set of regulations requires the right resources. As an example, DORA requires a crisis management function that implements clear procedures to manage internal and external crisis communications.
  • Implement ICT security tools and processes: Any DORA-focused preparations need to take tools and processes into account. Organizations need to consider legacy systems like the mainframe as well as vulnerabilities that might be leaving the business exposed to excessive risk.

Moving forward, businesses will need to take a much closer look at the IT environments they utilize. Regular penetration testing, integrity assessments, compliance assessments, and vulnerability management, like Rocket® z/Assure® Vulnerability Analysis Program, will be critical to maintaining the sort of rigorous compliance that is required by DORA. With the right solutions and processes in place, businesses can be proactive about spotting vulnerabilities in their IT environments and ensure they are faced head-on before a breach can occur.

Is your IT security infrastructure ready for future regulations? With Rocket Software, rest assured you'll have the technology, expertise, services, and support for digital operational resilience and robust risk management oversight.

Articles connexes

Security & Compliance

Interface utilisateur Secure Host Access Rocket Secure: mises à jour 2025-2026

3 minutes de lecture
Les mises à jour de l'interface Secure Host Access de Modern Rocket en 2025 et 2026 améliorent l'ergonomie, la configuration IAM, les rapports d'audit, le suivi de la conformité et la sécurité des hôtes [...]
Security & Compliance

Premiers pas avec Rocket Secure Host Access: de l’installation à la session en direct

3 minutes de lecture
Découvrez comment démarrer avec l'accès hôte Rocket Secure et apprenez-en davantage sur le déploiement, l'intégration avec votre système IAM existant et la mise en production de votre premier serveur.
Security & Compliance

Rocket Secure Host Access: Installation centralisée en 5 étapes

3 minutes de lecture
Déployez Rocket Secure Host Access dans toute votre entreprise grâce à une installation centralisée, une intégration IAM, des contrôles de conformité et une sécurité prête pour l'audit.