The European Union's Digital Operational Resilience Act (DORA) has taken full effect, imposing stringent cybersecurity requirements on over 22,000 financial entities across the EU. The regulation mandates ICT risk management, digital operational resilience testing, incident reporting within 4 hours, and comprehensive third-party risk management.
Financial institutions that fail to comply face penalties of up to 2% of annual global turnover. The regulation also introduces a framework for overseeing critical third-party ICT service providers, including cloud providers and software vendors.
Industry experts estimate that compliance costs for Tier 1 banks will exceed €50 million each, with significant investments required in security testing automation, incident response capabilities, and supply chain security programs.