Transmit Security is serving up unbeatable protection – and custom pickleball paddles at RSA 2025. Book a meeting to grab yours and take your security game to the next level!
Glossary
DORA (the Digital Operational Resilience Act) is EU regulation that sets requirements for the digital operational resilience of financial entities: ensuring banks, insurers, and other financial institutions can withstand, respond to, and recover from ICT (information and communication technology) disruptions and cyber threats. It harmonizes and strengthens operational-resilience and cybersecurity expectations across the EU financial sector.
DORA responds to the reality that financial services depend on technology, and that ICT failures and cyberattacks pose systemic risk. It aims to make the sector resilient by design.
DORA sets requirements across several areas: ICT risk management (frameworks to identify, protect against, detect, respond to, and recover from ICT risks), incident reporting (standardized reporting of major ICT-related incidents to regulators), digital operational resilience testing (including threat-led penetration testing for significant entities), third-party risk management (oversight of ICT service providers, including critical cloud and technology vendors), and information sharing on cyber threats. Compliance is mandatory for a broad range of EU financial entities and, notably, extends oversight to their critical ICT third-party providers.
DORA raises the bar for cybersecurity and resilience in EU financial services, making operational resilience a board-level, regulated concern rather than a purely technical one. Its focus on third-party risk is particularly significant, as it brings critical technology providers (including identity and security vendors) under greater scrutiny. For financial institutions, DORA means demonstrable resilience (robust security, tested incident response, and managed dependencies) is now a compliance requirement.
While DORA is broad (covering all ICT resilience), identity and access security are central to it. Strong authentication, access controls, and resilient identity infrastructure are core to protecting against and containing cyber incidents, and identity systems themselves must be resilient and secure to meet DORA’s operational-resilience expectations. The regulation reinforces investment in robust, well-managed identity and security capabilities as part of overall operational resilience, and its third-party provisions mean institutions will scrutinize the resilience of their identity and fraud vendors too.
What is DORA?
EU regulation requiring financial entities to strengthen their digital operational resilience against ICT disruptions and cyber threats.
What does DORA require?
ICT risk management, incident reporting, resilience testing, third-party (ICT vendor) risk management, and threat information sharing.
Who does DORA apply to?
A broad range of EU financial entities, and (notably) their critical ICT third-party service providers.
How does DORA relate to identity security?
Strong authentication, access control, and resilient identity infrastructure are central to the operational resilience DORA requires.
Related: GDPR · Zero Trust · Data Breach · IAM · PCI DSS