DORA: The European financial sector in cybersecurity, 15,000 entities must comply

DORA: The European financial sector in cybersecurity, 15,000 entities must comply

1. A demanding framework for a strategic sector

The financial sector, undergoing full digital transformation, has become the prime target of cyberattacks.

Faced with this reality, the European regulation DORA (Digital Operational Resilience Act) comes into force in January 2025. It aims to harmonize digital security requirements for all financial entities in the European Union, by strengthening their operational resilience against cyber risks.

This text is part of the European Commission's digital strategy, with a clear objective: to guarantee the stability of the European financial system while promoting innovation.

# 2. Risk-based governance: a culture change

DORA imposes a risk-based governance approach, structured around five pillars. The first pillar, which is central, relies on implementing a comprehensive ICT risk management framework.

This includes:

  • Mapping of digital and physical assets,
  • Continuous assessment of vulnerabilities,
  • Definition of a digital resilience strategy.

📌 Responsibilities now rest with senior management:
Article 5 of the regulation stipulates that management is legally responsible for defining, approving and overseeing the cybersecurity strategy.

They must:

  • Determine the level of risk tolerance,
  • Decide on actions to be taken (risk reduction, acceptance or transfer),
  • Ensure DORA compliance at all levels of the organization.

The penalties provided are dissuasive: administrative sanctions, corrective measures, or even criminal sanctions, depending on the Member States. Cybersecurity thus becomes a strategic, ethical and reputational issue.

3. Strengthened requirements for the entire value chain

DORA concerns more than 21 types of financial entities, including banks, insurers, asset managers, investment firms, fintechs, payment service providers... But the text goes further: it also includes their IT service suppliers and subcontractors.

Thus, approximately 15,000 actors in the financial value chain will have to meet these obligations:

  • Implementation of a robust ICT risk management framework,
  • Development of an incident response plan,
  • Establishment of an ICT service provider register,
  • Regular digital resilience testing,
  • DORA audit to identify vulnerabilities and weaknesses,
  • Mechanisms for reporting major incidents to competent authorities within specific timeframes.

Entities must also assess the cyber posture of their subcontractors and justify the choice of service providers. The objective: to avoid systemic failures linked to weak links in the digital chain.

# 4. From DORA Compliance to Sustainable Cyber-Resilience

Beyond regulatory compliance, DORA is a strategic opportunity to build a global, cross-functional and sustainable cyber resilience. But this requires:

  • Close collaboration between internal teams (CISO, IT, Risk, Procurement),
  • Structured governance driven by management,
  • Dynamic risk mapping,
  • Support from specialists through an outsourced CISO or shared CISO, depending on the organization's resources and cyber maturity.

Financial entities must now:

  • Identify critical third parties,
  • Collect data on suppliers,
  • Conduct a cybersecurity audit or DORA audit to assess their preparedness,
  • Deploy a collegial approach to cyber risk at all levels of the company.

👉 This proactive approach makes it possible to transform a regulatory challenge into a lever for performance, trust and competitiveness.

# 5. How Data Comply One Supports You Towards DORA Compliance

At Data Comply One, we support financial sector players in their DORA compliance through a comprehensive and tailored offering, based on three pillars:

🔍 1. DORA Diagnosis and Audit

  • Automated DORA compliance analysis
  • Critical asset mapping
  • Cyber maturity assessment

🧑‍💻 2. Personalized DORA Support

  • Provision of an outsourced CISO or shared CISO
  • Development of cyber-resilience strategy
  • Remediation plan management

📊 3. Compliance Management Platform

  • Made in France tool, secure, sovereign
  • DORA obligations tracking and dashboards for management
  • Centralization of supplier registers, incidents, action plans

🎯 Our mission: enable you to meet your DORA obligations while showcasing your actions to authorities, clients and partners.

Conclusion: DORA, a Strategic Challenge for 2025

The DORA regulation marks a turning point for the financial sector: it requires concrete, measurable and governed digital resilience. It is not just about protecting yourself, but about knowing how to react, continue and bounce back. Companies that anticipate their DORA compliance and structure their cyber compliance will come out winners on all levels.

At Data Comply One, we transform regulatory complexity into concrete, pragmatic and manageable actions, with a simple objective: to make cybersecurity and compliance an asset, not a barrier.