Site navigation

What Potential Snags do Firms Face to Meet DORA Requirements?

Ben Stickland

,

DORA compliance
In this contributed piece, Ben Stickland, Senior Hive Member at ethical hacking firm CovertSwarm, explores the impending challenges of DORA and NIS2 compliance, with a focus on Threat-Led Penetration Testing (TLPT) and essential steps for financial institutions to prepare.

Two years in the making, the EU’s Digital Operational Resilience Act (DORA) finally comes into effect on 17th January 2025, and while NIS2 has already come into effect, impacted entities will have to provide certain information to their ‘competent authority’ by 17th April 2025.

Despite deadlines already in place or looming, only a third of banking organisations are confident in their ability to meet DORA’s regulatory expectations by January 2025 – a worrying statistic considering the penalties for non-compliance. For example, NIS2 can levy fines of up to 10 million euros or 2% of worldwide annual turnover.

With many UK firms needing to prepare imminently for the requirements of NIS2 and DORA, we need to explore the Threat-Led Penetration Test (TLPT) process and the last minute complications to watch out for before the looming evaluation.

TLPT, a Key Regulatory Requirement Under Both DORA and NIS2, Can Take up to a Year to Complete

Both DORA and NIS2 pieces of legislation make a number of requirements for Threat-Led Penetration Testing (TLPT) or ‘advanced cyber security testing’ –  the requirement for intelligence-based red teaming exercises to be performed at least every 3 years against all companies impacted by DORA.

This is a rigorous testing exercise designed to simulate real-world cyber-attacks and assess the robustness of systems in a way that traditional pen testing doesn’t. It mirrors other existing schemes such as TIBER-EU and CBEST, which many financial institutions will already be familiar with.

The DORA requirements around TLPT include a range of pre and post-testing requirements, such as:

  • Performing a threat intelligence assessment to scope the red teaming engagement.

  • Performing a range of post-test exercises.

  • Reporting on findings following the conclusion of testing.

Once all of these subsidiary elements are considered, the full TLPT process will likely take at least a year to complete, with a minimum of 12 weeks dedicated to actual test execution.

DORA’s TLPT will systematically target the ‘significant’ institutions with enhanced testing

Following the release of the final ‘Draft Technical Standards’ document in July 2024, it is clear that there will be a significant commonality between TIBER-EU and DORA, with the authors of the report stating the TLPT will ‘mirror [TIBER-EU] as much as possible’.

This is good news for companies already familiar with TIBER, as they should be able to easily adopt DORA’s TLPT, with only minor modifications – a saving grace since there is no transitional period for DORA compliance, as banks have had since January 2023 to prepare.

It has also been highlighted that only those institutions which ‘carry a certain degree of systemic importance’ will be expected to perform the TLPT.

While no specific sizing or guidelines are given, they clarify that the regulatory technical standards is a minimum expected standard, but that the largest and most significant organisations will be expected to go above what is detailed; likely to be more regular, or more detailed testing.

Banks With ICT Connections May be Entitled to New Joint Testing Scheme 

A joint testing concept is being introduced, allowing the burden of testing to be shared among the financial entities using the same intra-group ICT service provider. However, each financial entity must still be tested individually to ensure their systems are resilient.

Additional information is given on how testing is handled with financial entities spanning multiple EU member states, with testing being coordinated by the ‘home’ state.

The final release of these standards is due on 17th January 2025, which will provide final confirmation on how DORA will be implemented.

Banks Should be Planning to Ensure the Best Outcomes From Any Subsequent Testing

It is key for all UK banks that interact with EU-based firms to prepare for all outcomes when it comes to TLPT, but this preparation should be tailored for each organisation. For example, this should take into consideration the relative strengths and weaknesses of the whole estate, plus the organisation’s exposure to adversarial simulation.

Typically, I’d recommend that firms start with an introductory red team engagement to assess their security posture and identify areas that would benefit from more targeted assessments.


Recommended reading


Following this, specific assessments would be determined to improve the security posture of various areas. These assessments could be delivered as an assumed breach or as a purple team exercise, depending on the nature of the test cases. Commonly this would involve tests focused on key attacker actions, such as gaining initial access, privilege escalation and lateral movement.

In parallel, ongoing perimeter assessment activities may be conducted to improve resilience to phishing or vishing attempts, as well as generally hardening the perimeter against attack.

Ultimately, whichever preparation plan is chosen to meet the DORA requirements, it should be constantly reviewed and updated, ensuring that it accurately reflects any potential threat intelligence developments or changes within the estate.

Ben Stickland

Senior Hive Member, CovertSwarm

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data