Is DORA the dawn of a new era for cybersecurity compliance in the EU's financial sector?
Antonio Giannino,
Francesca Valenti and
Federico Sertori
Additional contact information
Antonio Giannino: Managing Partner, AmagisTech, Italy
Francesca Valenti: Legal Counsel, AmagisTech, Italy
Federico Sertori: Legal & Compliance Officer, Cargolux Italia, Italy
Journal of Financial Compliance, 2024, vol. 8, issue 1, 32-42
Abstract:
This paper aims to set out the application of Regulation (EU) 2022/2254, the Digital Operational Resilience Act (DORA), to analyse its main obligations, its impacts on the current financial ecosystem and on the future culture around cybersecurity in the financial sector. The paper focuses on the main pillars around which the regulation has been built, and its aim is to assist compliance officers and non-technical personnel to assess the impact of DORA within their organisation. The authors offer an overview of DORA because the first step to address the implementation of a new regulation is having a clear view on all areas involved and the intensity of the changes. DORA will require a deep review of current documentation and processes: legal departments will have to ensure the agreements in place with IT providers comply with the new requirements, which entails new processes and the ability to follow the new contractual obligations; risk officers will need to work closely with the IT department, middle-back office and the compliance department to ensure they are all proactively involved in the implementation and monitoring of the new processes and that such procedures and the IT tools integrated are constantly suitable to serve the organisation's need. Furthermore, management will be involved in DORA implementation and will bear responsibility for information and communication technology topics and, consequently, it will be incentivised to pay attention to and invest in information security. Meanwhile, carrying out a pre-assessment at organisational level to understand business impacts and drafting an implementation plan so as to be ready for January 2025, when DORA comes into effect is highly recommended.
Keywords: cybersecurity; compliance; European digital finance package; financial industry (search for similar items in EconPapers)
JEL-codes: E5 G2 K2 (search for similar items in EconPapers)
Date: 2024
References: Add references at CitEc
Citations:
Downloads: (external link)
https://hstalks.com/article/8666/download/ (application/pdf)
https://hstalks.com/article/8666/ (text/html)
Requires a paid subscription for full access.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:aza:jfc000:y:2024:v:8:i:1:p:32-42
Access Statistics for this article
More articles in Journal of Financial Compliance from Henry Stewart Publications
Bibliographic data for series maintained by Henry Stewart Talks ().