Six months after the EU’s Digital Operational Resilience Act (DORA) came into effect, about 96% of EMEA financial services organisations still feel their current level of data resilience falls short.
This is according to a survey commissioned by Veeam Software, which gathered insights from senior IT decision makers at financial services companies in the UK, France, Germany, and the Netherlands, underscoring the ongoing challenges faced by the sector as it adapts to DORA – a framework introduced by the EU to strengthen the financial sector’s cybersecurity posture.
While DORA has been embedded as a strategic priority across the financial sector, many organisations are still navigating the path to full compliance.
The survey found that 94% of organisations surveyed now rank DORA higher in their organisational priorities than they did in the month before the deadline, with 40% calling it a current “top digital resilience priority.”
Half of the respondents said DORA requirements have been integrated into their broader resilience programs, while 39% reported it remains a central focus.
Even with 94% of organisations clear on the steps they need to take, many are facing unforeseen challenges.
About two in five (41%) report increased stress and pressure on IT and security teams, while 37% are dealing with higher costs passed on by ICT vendors.
Just under a quarter (22%) believe that the volume of digital regulation is becoming a barrier to innovation or competition, and a fifth (20%) have yet to secure the necessary budget to meet DORA requirements.
“It’s promising to see that most organisations have embraced and feel confident about meeting DORA’s requirements,” said Edwin Weijdema, field CTO EMEA at Veeam.
“Achieving compliance is an important first step in ensuring your organisation is resilient but given today’s complex threat landscape there’s more to do. New Veeam research shows that many financial institutions still see a gap in their overall resilience and face challenges in securing the necessary budget, even as DORA grows in strategic importance.
“The journey to operational resilience is ongoing, and it’s clear that prioritising data resilience remains critical for organisations’ long-term success.”
Despite this prioritisation, many organisations are still working to meet key DORA requirements, with about a quarter (24%) having not established recovery and continuity testing, and a further 24% not implementing incident reporting.
About one in four (24%) have not identified a DORA implementation lead, while 23% have not conducted digital operational resilience testing, and about a fifth (21%) have not ensured backup integrity and secure data recovery.
The most challenging DORA requirement? Third-party risk oversight, with 34% of organisations citing it as the hardest to implement – despite only 20% yet to do so. There are many possible reasons for this, from the limited visibility many organisations have into their third-party operations to the sheer scale of third-party networks.
Recommended reading
- What Potential Snags do Firms Face to Meet DORA Requirements?
- DORA Compliance | UK Supply Chain Doubts Persist
- UK CISOs Face Budget Pressures as DORA Enforcement Begins
“It’s interesting to see that third-party oversight has emerged as a particular pain point for organisations,” Andre Troskie, Field CISO EMEA at Veeam said.
“Over a third named it the most challenging to implement, and many called for additional guidance on establishing it in the first place. An often-overlooked facet of data resilience, it’s promising to see that organisations are interrogating their defences to this degree – which is exactly what it was designed to do.
“Of course, meeting the requirements is key, but DORA was also about getting organizations to assess their resilience holistically – and in that aspect, it seems to be succeeding.”
Additionally, 22% of organizations felt that DORA’s design could have been improved to aid compliance, with calls for simplification, clarification, and more detailed third-party risk guidance.





