Almost half of UK businesses reported spending over €1 million (£844,500) in the last two years on the implementation of regulations such as the EU’s Digital Operational Resilience Act (DORA) which comes into effect today.
The research, from cybersecurity firm Rubrik, found more than a quarter (28%) of the 350 chief information security officers (CISOs) surveyed across Europe had spent over €501,000 (£423,097) on their regulation efforts.
However, even after increasing their regulatory spending, over three-quarters (77%) of UK CISOs feel that their IT budget is not reflective of their board’s objectives to meet these new regulatory requirements.
“There is a critical gap between board-level understanding and reality,” said James Hughes, enterprise CTO at Rubrik.
“While regulators are increasingly stringent, many CISOs feel their budgets don’t adequately reflect the board’s commitment to compliance. This disconnect jeopardises not only organisations’ security posture but also their ability to meet evolving regulatory demands.”
The DORA legislation will introduce an enforced universal framework, with a focus on ICT risk management, that could transform the financial services and banking sectors, through mandating key provisions such as contractual safeguards and contingency planning.
To ensure best practices around operational resilience, DORA sets out requirements for regular testing of digital resilience and attack simulations, feeding into firms cyber-resilience plans with the hope of mitigating outside threats.
Despite these regulatory efforts UK CISOs still see looming threats, with ransomware continuing to be the greatest perceived threat to financial firms (46%), followed by third-party compromise (20%), and vulnerabilities in software supply chains (19%).
Those concerns aside, UK CISOs had more confidence in the security of the cloud than their European counterparts, with 73% feeling that their client, customer, partner and employee PII is secure in cloud environments.
The research also found that dealing with security pressures comes at some personal cost for CISOs, with 79% of these professionals reporting that it has had an impact on their mental health.
Well over half of CISOs (60%) said that meeting the new regulatory requirements such as DORA has added pressure to their role, with 23% considering moving to a less regulated sector.
Recommended reading
- What Potential Snags do Firms Face to Meet DORA Requirements?
- DORA Compliance | UK Supply Chain Doubts Persist
- 90% of Finance Functions to Deploy AI by 2026
“Given the increasing threat of ransomware and third-party compromise, the implementation of regulations is required and expensive,” said Hughes.
“Understanding what data is the most critical, where that data lives, who has access to it, is essential to identifying, assessing, and mitigating ICT risks. If good hygiene practices like these are not followed, organisations can now receive fines from the Financial Conduct Authority.”





