published on
What is the Digital Operational Resilience Act (DORA) and how can Data-Centric Security Help?
In today’s dynamically evolving digital regulatory landscape, data security is more critical than ever. Data is the building block of any client’s journey, and a large portion of our financial lives are taking place in the digital realm. In line with this trend, financial institutions are undergoing systemic changes, digitalizing every aspect of their operations. This naturally means navigating a complex web of regulatory requirements to safeguard sensitive information and maintain customer trust. A key aspect of that is maintaining the operational resilience of digital services for financial institutions.
As the operational resilience of digital services becomes a matter of wider societal importance, the European Union has introduced the Digital Operational Resilience Act (DORA) as the single most comprehensive piece of regulatory legislation since GDPR. A McKinsey survey of financial institutions indicated that financial service institutions (FSI), depending on their complexity, will spend more than €15 million euros on average to achieve DORA compliance within the next year. Furthermore, the same study indicated that only a third of the organizations surveyed expressed confidence in meeting all DORA regulatory expectations by January 2025.
DORA is a complex regulatory framework that is still largely undefined (3 out of 10 Regulatory Technical Standards have been published), and the timelines for implementing DORA compliance are tight (January 2025). Bearing this in mind, the route to compliance is a challenging proposition. In this blog post we will examine how Seclore can help enterprises better prepare their organizations to meet or exceed known and anticipated elements of DORA.
What is DORA: Legislative Overview
The Digital Operational Resilience Act sets out detailed requirements for EU-based Financial Institutions on how to protect their business processes. It is a part of the EU’s initiative “An Europe fit for the digital Age”. It seeks to build on and harmonize regulations related to Information and Communications Technology (ICT), cyber risk management, incident reporting, resilience testing, and third-party risk management.

What is the Purpose DORA?
As a legislative agenda, DORA brings forward significant obligations to both FSIs and ICT Third-Party Service Providers (IT TPSPs). The regulation itself is designed to create a unified approach to managing data and technology to more effectively manage, monitor, and mitigate risks associated with the concentration of TPSPs and the high degree of interconnectedness of the financial sector.
Thematically, DORA focuses on several categories that FSIs and ICT TPSPs must address to achieve compliance.
- ICT Risk Management: Within the context of ICT Risk Management, DORA builds on the BASEL II Operational Risk Management Frameworks that have already been established in the financial services industry. Although extensive, because DORA regulations build on existing processes, the path to compliance in this category should require minimal effort from well-established FSIs. Small and medium-sized FSIs will likely have to invest more resources to comply, even when considering the principle of proportionality, which is one of the core aspects of DORA.
- Incident Reporting: DORA also looks to build on existing incident reporting requirements. Although most financial services institutions already have incident reporting mechanisms in place, DORA increases reporting immediacy (within 24 hours to competent authorities), and the granularity of incident reports. These two requirements will likely cause incident reporting teams to make significant process modifications to achieve compliance.
- Digital Operational Resilience Testing: DORA requires financial service entities to establish robust digital operational testing programs. The regulation mandates that FSIs undergo comprehensive digital operational resilience testing of critical and non-critical digital assets. Digital operational resilience testing should be conducted at least once a year for all systems, while critical or high-risk systems should be tested more frequently. However, due to the threat-led penetration testing regulatory technical standards (RTS) not being published yet, the commitment FSIs must make remains unknown. Given the increased rate of testing, and a wider range of required tests, this category will likely require significant investment.
- Third-Party Risk Management: DORA mandates an extensive and rigorous oversight framework for third-party service providers to ensure their operational resilience and the operational resilience of the broader system. The new framework will require extensive and frequent risk assessments, contract stipulations, and detailed reporting obligations. Compliance with this category of DORA will require substantial resource allocation and significant changes in end-to-end operational processes.
How Will DORA Be Enforced?
DORA enforcement is set to begin on January 17, 2025, which greatly compresses the amount of time organizations have to achieve a meaningful level of compliance. The enforcement of DORA will be driven by National Competent Authorities in each EU member state. DORA itself won’t be transcribed into local legislation like NIS 2, and the core regulation will, in its entirety, be applicable throughout the EU. The European Supervisory Authorities will play a pivotal role in harmonizing enforcement around the EU, coordinating National Competition Authorities (NCA) practices to maintain enforcement standards.
Third Party Risk Management
The most important thematic aspects of DORA are the Third-Party Risk Management compliance requirements. In this area, DORA builds on European Banking Authority regulations, Third Party Outsourcing, and the European Insurance and Occupational Pensions Authority (EIOPA) frameworks on ICT Security and Governance — which form the foundation of existing regulations regarding third-party services in the EU. DORA expands on these regulatory frameworks and exacts additional regulatory scrutiny regarding third-party risk management.
DORA includes specific provisions to enforce stringent third-party risk management practices. FSIs must conduct thorough due diligence before engaging third-party providers to ensure they adhere to high security and operational standards. DORA also assigns the burden of responsibility largely to FSIs, where they are “fully responsible for compliance of all obligations set under the DORA Regulation”.

Contracts with third parties must also include clear terms regarding service levels, data protection, and incident response protocols. Regular risk assessments and audits of third-party providers are required to continuously evaluate their compliance and resilience. Additionally, DORA mandates that critical third-party service providers be registered with European Supervisory Authorities (ESAs), enabling better regulatory oversight and coordination.
These provisions ensure that third-party relationships are managed proactively and that any risks are identified early. Lead Overseers will coordinate the bulk of the enforcement frameworks, with potential periodic penalties for noncompliance being up to 1% of daily turnover of the critical ICT third-party service provider. Other penalties involve the forced partial or complete termination of service agreements between FSIs and critical third-party providers.
Although not specified, it is likely that a number of designated critical and global third-party service providers will provide data-related services to financial institutions. To this extent Article 28 paragraph 7, subsection C states:
“Contractual service agreements may be terminated if…ICT third-party service provider’s evidenced weaknesses pertaining to its overall ICT risk management and in particular, in the way it ensures the availability, authenticity, integrity and, confidentiality, of data, whether personal or otherwise sensitive data, or non-personal data;”
This is why data security is likely to be an extremely important aspect of the Third-Party Risk Management RTS. The regulation’s general tone emphasizes increased scrutiny and oversight, putting an additional burden on organizations to protect data managed on behalf of FSIs, whether that data is on- or off-premises.
Ensuring robust data security measures are in place for third-party interactions is essential to prevent data breaches, unauthorized access, and other cyber threats that could compromise critical data. DORA’s stringent requirements for continuous monitoring, regular risk assessments, and secure contractual obligations with third parties aim to mitigate these risks. By enforcing high data security standards, FSI’s can safeguard sensitive data throughout their extended network of third-party relationships and enhance their overall operational resilience.
Key Challenges of DORA
Timeline
One of the primary challenges to implementing DORA is the short timeline set for compliance. With DORA coming into effect on January 17, 2025, FSIs and their third-party providers have a narrow window to achieve compliance. In practice, there will likely be some leniency in the compliance timeframe and the enforcement of the first legislative penalties (as was the case with GDPR). Despite this, the timeframe for compliance is extremely aggressive and poses a significant challenge.
This timeframe demands swift and comprehensive changes across multiple facets of an organization, including cybersecurity, risk management, data protection, and third-party oversight. A particular point of focus is that FSIs will need to overhaul existing contracts with third-party providers to achieve the desired yet ill-defined levels of compliance and resilience. In this context, it will become increasingly important to invest early in tools that can improve compliance with minimum lead time.
Lack of Clarity on Regulatory Technical Standards (RTS)
Another critical challenge in implementing DORA is the uncertainty surrounding the Regulatory Technical Standards (RTS) that have yet to be published. These standards are essential as they provide the detailed guidelines and specifications necessary to achieve compliance. Without clear RTS, FSIs and critical third-party providers are left in a state of ambiguity regarding their legal obligations. This uncertainty complicates the planning and execution of compliance strategies, as organizations cannot fully anticipate or address all the nuances of DORA’s mandates. The lack of finalized RTS makes it difficult for FSIs to develop and implement precise compliance frameworks. Organizations must make educated guesses and take provisional measures based on the general principles of DORA, which may need significant adjustments once the RTS are published.
Enforcement
One of the primary challenges is ensuring consistent and harmonized enforcement by national competent authorities (NCAs) across all EU member states. Each country’s regulatory body must interpret and apply DORA’s mandates uniformly, which requires substantial coordination and communication among the various authorities. Disparities in enforcement could lead to regulatory arbitrage, where entities exploit differences in national implementations to their advantage, undermining the regulation’s overall efficacy. Moreover, NCAs must be adequately resourced and equipped with the necessary expertise to conduct thorough inspections, audits, and compliance checks, which may be particularly challenging for smaller or less developed regulatory bodies.
Data Security
Based on the number of articles addressing these issues, it’s clear that Data security and Cybersecurity are at the core of digital operational resilience. In order for FSIs to continuously and effectively serve their customers, they must first ensure that the critical data they create and manage is secure. Data-centric security may be necessary to adequately protect sensitive digital assets shared inside and outside the organisation in accordance with DORA regulations. Granular activity and usage information might also be required to meet audit requirements and understand the degree to which an FSI is in compliance.
How Can Seclore Help?
Although DORA itself is not a data security or data privacy regulatory framework, data security is at the core of digital operational resilience. Data underpins the operational resilience and integrity of FSIs, and securing critical data is essential for ensuring the continuous and effective functioning of FSIs in the EU. DORA requirements increase the level of rigor around data protection and emphasize the need for robust data management practices.
Seclore’s data-centric security platform can effectively contribute to an enhanced data security posture that contributes to a higher degree of compliance regarding specific DORA requirements. As there are several RTS’s still pending, it’s apparent that the full breadth of data security considerations related to DORA are unknown. However, even within the published RTS documentation, data security is at the forefront of DORA compliance requirements.
With this context in mind, we’ve identified a number of relevant data security DORA articles, and linked the associated requirements with Seclore’s data-centric security platform to highlight how Seclore supports our customers on their DORA compliance journeys. These are just some of the examples where Seclore can help achieve DORA compliance. Both compliance and data security are a journey, and Seclore is ready to support your organization’s data security requirements to make the path to DORA compliance a little easier.
Main Legislative Text
| ARTICLE 9 — Protection and Prevention | How Seclore can help |
| Financial entities shall use ICT solutions and processes that are appropriate in accordance with Article 4. Those ICT solutions and processes shall: | Seclore’s data-centric security platform helps organisations know, protect, and control their sensitive digital assets. |
| Ensure the security of the means of transfer of data; | Seclore provides persistent security to keep files protected in transit, prevent unauthorized access, and log related activities that help security teams detect and address unauthorized access or tampering. |
| Minimize the risk of corruption or loss of data, unauthorized access and technical flaws that may hinder business activity; | Digital assets protected by Seclore cannot be modified without permission or accessed by unauthorized users. Each interaction with the file is tracked and is auditable. |
| Prevent the lack of availability, the impairment of the authenticity and integrity, the breaches of confidentiality and the loss of data; | Seclore-protected files cannot be accessed by unauthorized users. Organisations can also apply dynamic watermarks to discourage breaches of confidentiality, and revoke access to any user with permission to access a file at any time. The platform can implement robust workflows to enable authenticated and authorized users to gain access when needed. |
| Ensure that data is protected from risks arising from data management, including poor administration, processing-related risks, and human error. | Seclore can automatically protect sensitive information based on classification or sensitivity labels. The platform also lets organizations view granular file-level activity information and risk insights to help spot nefarious or unauthorized activity. Information owners can protect emails and attachments, modify usage controls remotely, and revoke access to any file or email at any time. Seclore supports bulk administrative operations to reduce overhead and out of the box connectors coupled with flexible SDKs allow enterprises to avoid human error and roll out security at scale. |
| ARTICLE 11 — Data and System Security | How Seclore can help |
| The financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554 shall, as part of their systems, protocols, and tools, develop and implement safeguards that ensure the security of networks against intrusions and data misuse and that preserve the availability, authenticity, integrity, and confidentiality of data.(a) the identification and implementation of measures to protect data in use, in transit, and at rest;(b) the identification and implementation of security measures regarding the use of software, data storage media, systems and endpoint devices that transfer and store data of the financial entity;(d) the identification and implementation of measures that ensure the availability, authenticity, integrity, and confidentiality of data during network transmissions; | (a) Seclore-protected files are encrypted at rest, in transit, and in use, and provide granular file-level activity information to help identify unauthorized activity.(b) Whether a file is stored on a user’s device, third-party network, or cloud environment, protection and control can always be enforced. The solution covers endpoint, email, on-premises data stores, and more.(d) Seclore logs activity related to protected files to provide an auditable chain of custody and validate the integrity of protected files. |
| ARTICLE 12 — Backup Policies and Procedures | How Seclore can help |
| 1. To ensure the restoration of ICT systems and data with minimum downtime, limited disruption and loss, as part of their ICT risk management framework, financial entities shall develop and document:backup policies and procedures specifying the scope of the data that is subject to the backup and the minimum frequency of the backup, based on the criticality of information; | Seclore classification labels help organizations determine the criticality of information within enterprise systems.Classification-driven protection dynamically applies access and usage controls related to how sensitive data is, to protect on-site and off-site backups. |
| 7. When recovering from an ICT-related incident, financial entities shall perform necessary checks, including any multiple checks and reconciliations, to ensure that the highest level of data integrity is maintained. These checks shall also be performed when reconstructing data from external stakeholders, to ensure that all data is consistent between systems. | Seclore protects the integrity of sensitive digital assets to ensure data has not been modified in case of loss or compromise. It also gives organisations detailed telemetry and activity information with full audit trails to validate the integrity of data between systems. |
| ARTICLE 21 — Access Control | How Seclore can help |
| As part of their control of access management rights, financial entities shall develop, document, and implement a policy that contains all the following:(b) the segregation of duties designed to prevent unjustified access to critical data or to prevent the allocation of combinations of access rights that may be used to circumvent controls; | Seclore lets information owners customize access controls by user, group, domain, location, and other attributes , and authenticates users each time they access protected digital assets. Access rights are persistently applied regardless of how many times a protected file is duplicated, or transferred. Access to protected digital assets can also be set to expire on a certain date/time, remotely modified, or instantly revoked. |
RTS Third Party ICT Service Policy
| Article 1 — Overall Risk Profile and Complexity | How Seclore can help |
| The policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (the ‘policy’) shall consider the size and the overall risk profile of the financial entity, and the nature, scale and elements of increased or reduced complexity of its services, activities and operations, including elements relating to:(d) the nature of the data shared with the ICT third-party service provider; | Seclore digital asset classification helps organisations identify, label and categorise sensitive digital assets. With appropriate classification labels in place, organisations can achieve a high degree of visibility and certainty about the nature of data shared with ICT third-party service providers.Seclore’s Risk Insights dashboard shows a macro view of risks, and how third parties are handling protected assets. This information can be fed into security analytics and reporting tools to help track and manage third-party risk. |
RTS Risk Management Framework
| ARTICLE 6 — Encryption and Cryptographic Controls | How Seclore can help |
| 2. Financial entities shall design the policy on encryption and cryptographic controls referred to in paragraph 1 based on the results of an approved data classification and ICT risk assessment. That policy shall contain rules for all the following:(a) the encryption of data at rest and in transit;(b) the encryption of data in use, where necessary;(c) the encryption of internal network connections and traffic with external parties;For the purposes of point (b), where encryption of data in use is not possible, financial entities shall process data in use in a separated and protected environment, or take equivalent measures to ensure the confidentiality, integrity, authenticity, and availability of data. | Seclore-protected files are encrypted at rest, in transit, and in use with symmetric (AES-256) and asymmetric (RSA 2048) encryption. Seclore also supports custom encryption protocols.With Seclore’s data-centric security platform, organisations can apply persistent access and usage controls to sensitive digital assets to ensure the confidentiality, integrity, and authenticity of protected digital assets. |
| ARTICLE 35 — Data, System and Network Security | How Seclore can help |
| The financial entities referred to in Article 16(1) of Regulation (EU) 2022/2554 shall, as part of their systems, protocols, and tools, develop and implement safeguards that ensure the security of networks against intrusions and data misuse and that preserve the availability, authenticity, integrity, and confidentiality of data.(a) the identification and implementation of measures to protect data in use, in transit, and at rest;(d) the identification and implementation of measures that ensure the availability, authenticity, integrity, and confidentiality of data during network transmissions;(e) process to securely delete data on premises, or that are stored externally, that the financial entity no longer needs to collect or store; | (a) Seclore persistently protects and encrypts digital assets wherever they are, whether that’s at rest, in transit, or in use. Protected digital assets remain visible to, and under the direct control of information owners wherever they go, which significantly reduces the risk of data misuse or theft.(d) Seclore-protected files can only be accessed by authorized users. Organisations can also view activity information for protected digital assets to ensure sensitive data remains confidential.(e) Entities can validate that data is destroyed, and revoke access to protected digital assets stored externally to effectively delete data they no longer need to store. |
Conclusion
Although much is still unclear about the operational enforcement of DORA, what is clear is that this is a regulation that significantly increases the level of regulatory scrutiny FSIs and Third-Party Providers are subject to. The way data is managed, protected, and used is likely to be at the center of this enhanced oversight framework and Seclore can help organizations better prepare for this level of scrutiny. Giving organizations visibility and control over their sensitive digital assets, in addition to a granular understanding of user activity related to this data are both invaluable tools in achieving DORA compliance. Whether data is on prem or in a third-party cloud, Seclore’s data-centric security platform allows organizations to stay in control of their sensitive data wherever it exists.
