The Digital Operational Resilience Act (DORA) was formally put into place by the EU last year as a regulatory framework to strengthen the financial sector’s resilience against information communication technology risks, placing a responsibility on financial institutions and their service providers to ensure maximum security and minimum incident.
Sparked by a range of cybersecurity incidents hitting a plethora of Europe’s financial institutions, the EU took a look at the industry and noticed a pattern of market consolidation in key vendors and the enhanced security risks inherent in an increasingly interconnected, co-dependent system.
Financial services institutions are being recognised as critical infrastructure that must continue to operate despite any cyber incident disruptions. The importance of the finance sector makes it a major liability: massive organisations often concentrate their supply chain to a few key vendors, and financial institutions are associated with a major pay off for threat actors seeking a lucrative target.
These factors drove the EU to institute DORA, building on existing legislation to create a framework of responsibility across the entire financial sector supply chain. It specifically targets ICT services, with a specific focus on third party suppliers.
Since DORA was adopted and put into place in January 2025, financial services have been scrambling to catch up and implement the new legal requirements, ranging from auditing to enhanced cybersecurity testing.
Financial firms felt skills and budget squeezes ahead of DORA coming into force, and even with the regulations in full effect, companies operating in Europe are often behind on their compliance. This was certainly the case for DORA with PwC noting that only a very small share of firms had integrated DORA requirements into day-to-day operations by mid-2025.
Further, the effectiveness of the legislation is difficult to ascertain. Even with a major breach on a financial institution – which are rarely straight forward – intense investigations and post-incident analysis would be required across complex supply chains to ascertain if an incident occurred due to negligence under the scope of the Act.
As more firms fully adopted the frameworks required under the act, the EU finally designated 19 firms that would be classified as critical third-party computing providers, which would bring them under enhanced scrutiny. These firms have been identified as integral to Europe’s financial sector, particularly to their ICT environments, and include the likes of Google Cloud, AWS, Microsoft, and the Tata Consultancy. Under DORA, they will face enhanced legal requirements to ensure their integral offerings are secure.
A year in, however, and DORA seems to have made little ripples in the tech regulatory world besides stressing out the IT and security departments of financial institutions.
The strict EU requirements are not necessarily unnecessary, but difficult to track and prove for assessment by regulatory bodies. Security leaders in the financial sector seem to hold juxtaposing ideas surrounding DORA; it serves as both an important push for bold security strategies, setting a fire under weary feet dealing with evolving risks and legacy technology, but equally, it squeezes budgets, presenting regulatory and governance comprehension challenges.
Is DORA just another box to tick in the long list of EU regulations facing firms? In two, ten, five years will it hold up against transforming technology and a sprawling risk ecosystem? One year in with DORA, where do we stand?
Complexity Leaves Adoption Uneven
“One year on from DORA’s enforcement, Europe’s regulatory landscape has shifted. Between DORA, the EU AI Act, and NIS2, organisations now operate within a more unified, accountability-led framework that demands real transparency, traceability, and algorithmic accountability,” Martin Reynolds, field CTO and at Harness said.
And it’s true – the regulatory landscape has gotten more complex when it comes to regulation, with the EU trying to cover its legal bases if firms are found to slip up when it comes to securing key infrastructure. Besides these security and tech focussed legislations, big tech continues to come under scrutiny in the EU with digital markets and digital services regulations
“One year on since DORA came into effect, barriers to full compliance persist,” Soniya Bopache, SVP and General Manager at Arctera, said. “ Despite its emphasis on early detection, accurate reporting, and strong data integrity, navigating legislation with over 1,000 specific requirements is no easy feat, especially given many firms continue to grapple with complex IT environments.
“Balancing legacy systems with new and emerging technologies can often hinder comprehensive defence strategies, especially at a time when the threat landscape is rapidly growing more sophisticated,” Bopache added.
While DORA may be a “welcome and necessary first step” in securing the financial services ICT supply chain, “adoption has been uneven,” Chris Hosking, AI and cloud security evangelist at SentinelOne said.
“Many organisations are still treating DORA as a paper exercise, while real-world risk is being driven by sprawling SaaS and cloud environments, poor visibility of ICT assets, and growing dependence on complex software supply chains.
“At the same time, firms are struggling to accurately investigate and classify incidents quickly enough, particularly when attackers rely on social engineering rather than technical compromise.”
Further, getting prepared is no easy feat, and the price tag is hefty.
“One year into DORA, many banks have paid through the nose to improve operational resilience – investing in new monitoring capabilities, better system visibility, and speeding up incident reporting. But it’s still early days, and only time will tell if these often-rushed modernisation efforts have done enough to avoid costly non-compliance fines,” Steve Round, co-founder and president at SaaScada, said.
Unchallenged, What Does the Future of DORA Hold?
In just its first year, DORA has had little time to fully cement itself in the EU financial ecosystem, let alone be enforced as the result of a cyber incident.
“With DORA only a year old, there have been no notable breaches or enforcement actions. But this is just the calm before the storm, as transforming – and regulating – the operational resilience of an entire industry and tech ecosystem doesn’t happen overnight,” Jonathan Gill, CEO of Panaseer, a cybersecurity firm, said.
“Less than half (48 percent) are truly confident that cybersecurity reports to the board, risk teams, and regulators are clear and comprehensive. Whilst two-thirds (67 percent) lack full visibility into how effectively their security controls are working and only 29 percent are confident the security team knows their true risk level,” Gill added, noting the varied preparedness among financial institutions facing the DORA.
As technology advances and security risks shift and expand, keeping up with regulation is even more vital – but will DORA soon be old news?
“Research shows up to 45% of AI-generated code contains vulnerabilities, with issues ranging from hallucinated dependencies to language-specific failures. When development accelerates but testing, governance and security don’t keep pace, the result isn’t innovation; it’s exposure,” Reynolds said.
“In the age of AI, DORA serves as an important reminder that velocity without verification is risk,” he added.
Recommended reading
- What Potential Snags do Firms Face to Meet DORA Requirements?
- European Financial Services Are Behind on DORA Compliance
- DORA Compliance | UK Supply Chain Doubts Persist
- UK CISOs Face Budget Pressures as DORA Enforcement Begins
What Can Firms Do To Meet DORA Where It’s At?
Financial firms can continue to face existing and future risks, essentially: battling legacy tech liabilities whilst preparing for AI threats.
“By adopting a multi-faceted approach, organisations can not only overcome these challenges, they can gain a strategic advantage. Adopting tools that deliver full visibility across data environments enables fast, accurate incident reporting across hybrid and multi-cloud infrastructures,” Bopache advised.
“Embedding a strong culture of compliance, extending to third-party providers and reinforced through regular testing of response plans and continuous staff training, will be critical. Those that act proactively will not only reduce the risk of substantial penalties, but also strengthen trust, resilience, and operational continuity in an increasingly complex digital landscape.”
In essence, this can look like switching “to a more integrated, intelligence-led approach to compliance,” Gill said.
For many financial institutions, modernisation will be key in keeping up with evolving threats and expectations.
“The banks that started by modernising their core systems and improving overall data quality are in the best possible position,” Round said. They now have access to real-time insights that are boosting resilience, but also making it easier to launch personalised products and features faster, earning customer trust and increasing their share of wallet.
“On the other hand, those that have treated DORA as a box-ticking exercise will keep paying for the same problems, year after year.”
But DORA itself may need a level of transformation to keep up and hold firms accountable. Tracking compliance and understanding the liabilities that lead to security incidents is complicated and also requires cyber and data skills, excellent data practices, and meaningful compliance.
“To remain effective against today’s fast-moving threats, DORA will need to keep evolving – with a stronger focus on measurable security outcomes and how organisations actually operate, rather than box-ticking compliance,” Hosking said.





