Skip to main content
Hero background

The Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a unified framework for managing information and communication technology (ICT) risk across the financial sector. Adopted under Regulation (EU) 2022/2554, DORA strengthens operational resilience through standardized requirements for ICT risk management, incident reporting, resilience testing, third-party risk oversight, and governance. The regulation addresses a growing challenge across the financial sector: increasing reliance on digital technologies, interconnected systems, and external service providers. As financial institutions manage increasingly complex digital environments, secure and resilient communications are essential for protecting sensitive information, maintaining operational continuity, and enabling effective coordination during cyber incidents and service disruptions. 

Rather than relying on separate national requirements, DORA establishes harmonized operational resilience requirements across EU member states. The regulation applies to a wide range of financial entities, including banks, insurers, investment firms, payment institutions, electronic money institutions, and crypto-asset service providers. 

DORA establishes an oversight framework for designated critical ICT third-party service providers, recognizing the important role technology partners play in supporting essential financial services. By combining governance, operational controls, and regulatory accountability within a single framework, DORA helps financial institutions strengthen resilience against cyber threats, technology failures, and operational disruptions while maintaining the continuity of critical services. 

The Importance of DORA

Financial institutions operate within highly interconnected digital ecosystems. A disruption affecting a single system, supplier, or service provider can quickly impact multiple organizations and critical business processes. As cyber threats continue to evolve and technology dependencies increase, operational resilience has become a strategic priority rather than solely a technical responsibility. 

DORA establishes a common resilience framework that helps the financial sector prepare for, withstand, respond to, and recover from ICT-related disruptions. 

Key objectives include: 

  • Strengthening ICT risk management across financial institutions 

  • Standardizing cyber-incident classification and regulatory reporting 

  • Improving oversight of third-party ICT providers 

  • Supporting operational continuity during cyber incidents and service outages 

  • Promoting consistent supervisory expectations throughout the European Union 

The regulation also strengthens management accountability. Management bodies are required to oversee ICT risk strategies, allocate appropriate resources, and ensure operational resilience is integrated into enterprise governance. 

This approach recognizes that resilience outcomes depend on leadership involvement, effective risk management, and continuous operational readiness. 

Core Requirements of DORA

DORA is structured around five interconnected pillars. Together, these pillars establish measurable requirements for managing technology risk and maintaining operational continuity across the financial sector. 

1. ICT Risk Management 

ICT risk management forms the foundation of DORA. Financial institutions must establish governance frameworks that support the identification, protection, detection, response, and recovery of ICT-related risks. 

Core controls include: 

  • Asset inventories and data classification 

  • Secure development and change management 

  • Vulnerability and patch management 

  • Backup and recovery planning 

  • Business continuity and disaster recovery testing 

These controls provide visibility into ICT risks while helping maintain the availability and reliability of critical business services. Strong risk management practices also support informed decision-making by ensuring leadership teams have a clear understanding of operational dependencies and potential vulnerabilities. 

2. Operational Resilience Testing 

Resilience cannot be measured through policies alone. Organizations must regularly test whether security controls, recovery plans, and operational processes perform effectively under realistic conditions. 

Under DORA, resilience testing follows a risk-based approach that aligns testing activities with an organization's size, complexity, and risk profile. 

Common testing activities include: 

  • Vulnerability assessments 

  • Scenario-based exercises 

  • Tabletop simulations 

  • Threat-led penetration testing (TLPT), which simulates advanced cyber threats against critical systems 

Regular testing helps organizations identify resilience gaps before they disrupt critical financial services. It also provides measurable evidence that resilience controls are functioning as intended. 

Testing outcomes are documented, reviewed by management, and incorporated into continuous improvement initiatives that strengthen long-term preparedness. 

3. ICT Incident Reporting 

Timely and consistent reporting is a central component of DORA. 

Financial entities must establish formal procedures to detect, classify, escalate, and report significant ICT incidents. Standardized reporting improves transparency while enabling regulators to better assess risks across the financial sector. 

Critical reporting activities include: 

  • Incident classification 

  • Regulatory notifications 

  • Root cause analysis 

  • Corrective action planning 

  • Lessons learned documentation 

Beyond regulatory compliance, incident reporting supports organizational learning. Reviewing incidents and their underlying causes helps strengthen future response capabilities and improve resilience over time. 

4. Third-Party ICT Risk Management 

Third-party providers support many of the technologies and services that financial institutions rely on every day. As dependency on outsourced ICT services continues to grow, robust supplier oversight becomes increasingly important. 

DORA requires institutions to maintain visibility into ICT provider relationships and actively manage risks throughout the supplier lifecycle. 

Key controls include: 

  • Vendor due diligence 

  • Audit and access rights 

  • Service-level requirements 

  • Exit planning 

  • Continuous performance monitoring 

These measures help reduce concentration risk, improve accountability, and strengthen the resilience of critical supplier relationships. 

Effective third-party governance also helps ensure essential services remain available during disruptions affecting external providers. 

5. Information Sharing 

In highly interconnected financial ecosystems, cyber threats can create cascading operational impacts across institutions, suppliers, and essential services. Threat actors frequently target multiple institutions using similar tactics, techniques, and procedures. 

Recognizing this challenge, DORA encourages participation in trusted information-sharing arrangements that support collective resilience across the financial sector. 

Effective information-sharing practices include: 

  • Sharing cyber threat intelligence with trusted industry communities 

  • Exchanging indicators of compromise and emerging threat information 

  • Incorporating shared intelligence into detection and response processes 

  • Maintaining confidentiality and data protection safeguards 

By improving visibility into evolving threats, information sharing helps organizations strengthen preparedness, accelerate detection, and improve response effectiveness. 

Collective awareness can contribute to stronger resilience across the broader financial ecosystem. 

Benefits of DORA

Implementing DORA helps financial institutions establish a more consistent and measurable approach to resilience while improving regulatory readiness. 

Key benefits include: 

  • Improved cyber resilience across critical financial services 

  • Greater consistency in ICT risk management programs 

  • Enhanced oversight of third-party providers 

  • Faster incident detection and response 

  • Stronger governance and executive accountability 

  • Improved audit readiness through documented evidence 

  • Harmonized compliance across EU member states 

The benefits extend beyond compliance requirements. DORA encourages organizations to align cybersecurity, operational continuity, risk management, and governance practices within a single framework. This integrated approach can improve decision-making, strengthen operational preparedness, and support the continuity of essential financial services during disruptive events. For leadership teams, DORA provides a structured roadmap for managing technology risk while supporting long-term organizational resilience. 

DORA Use Cases

Organizations implementing DORA often adopt technologies, governance processes, and operational controls that strengthen resilience while supporting compliance objectives. 

Endpoint Security and Device Management 

Endpoint protection and centralized device management help reduce ICT risk by maintaining visibility, control, and policy enforcement across enterprise environments. 

Relevant capabilities include: 

  • AI-powered endpoint protection 

  • Unified endpoint management 

  • Centralized compliance reporting 

Incident Detection and Response 

Continuous monitoring and rapid response capabilities help identify cyber threats, contain attacks, and support DORA incident reporting requirements. 

Relevant capabilities include: 

  • Managed detection and response 

  • Threat hunting 

  • Incident investigation 

  • Evidence collection 

Secure Crisis Communications 

During ICT disruptions, secure communications support coordination among executive leadership, operational teams, and regulatory stakeholders. 

Relevant capabilities include: 

  • Secure voice communications 

  • Encrypted messaging 

  • Emergency notifications 

  • Crisis communication platforms 

Third-Party Risk Management 

Third-party oversight programs help maintain visibility into supplier risk throughout the vendor lifecycle while supporting regulatory documentation requirements. 

Relevant capabilities include: 

  • Vendor inventories 

  • Contract management 

  • Continuous supplier monitoring 

  • Audit documentation 

Operational Resilience Testing Programs 

Regular resilience testing helps validate recovery capabilities and identify opportunities for improvement before disruptions occur. 

Relevant capabilities include: 

  • Scenario-based testing 

  • Recovery exercises 

  • Penetration testing 

  • Business continuity validation 

  • Disaster recovery assessments 

 

BlackBerry for Secure Communications

For Environments Where Failure Isn’t an Option

BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.

Explore BlackBerry Secure Communications solutions