DORA in the Financial Sector: Why Digital Resilience Is More Than Just IT Security

From a Set of Rules to an Operational Management and Control Model

DORA in the Financial Sector – Why Resilience Is Becoming a Management Challenge

From a Set of Rules to an Operational Management and Control Model

DORA has been in effect since January 17, 2025. For financial institutions, this means that digital resilience is no longer just an issue for the IT department; it has become a matter of corporate governance.

The Digital Operational Resilience Act shifts the focus from isolated IT security to demonstrable resilience in digital operations. It is not just a matter of whether systems are protected. It is about whether an institution understands its risks, detects incidents, has established reporting procedures, can test recovery processes, and can provide robust evidence to management and regulators.

At first glance, that sounds technical. But it’s only half technical. The other half is governance.


Symbol for Oversight and Governance

Image source: AI-generated | Description: "Icon image for oversight and governance"

Why DORA Is More Than Just IT Security

For a long time, many companies viewed IT security primarily as a matter of protection: firewalls, access rights, backups, patches. All of these are important. And they’re still all valid.

However, DORA demands more: risks, controls, assets, providers, incidents, and tests must be integrated from a technical perspective—not as a loose collection of individual measures, but as an operational system.

This makes digital resilience a management task. The governing body must be more closely involved in strategy, reviews, and risk appetite. Roles must be more clearly separated: management, the control function, and internal audit must not disappear into a friendly fog of overlapping responsibilities.

In other words: DORA doesn't just ask whether a policy exists. DORA asks whether the policy works in practice.

Asset Transparency as a Foundation

A key issue is transparency regarding ICT systems, applications, and dependencies. Institutions need to know which systems they use, which business processes depend on them, and which vendors are involved.

Without this perspective, risk management remains incomplete. After all, you can only protect, test, and restore what you know.

This is particularly challenging in the financial and insurance sectors. Many processes rely on internal systems, cloud providers, software service providers, specialized platforms, and other third-party ICT service providers. DORA places greater emphasis on these dependencies within the context of governance and oversight.

Tests, incidents, and evidence must work together

Digital resilience isn't something you see in an organizational chart. It becomes apparent when a crisis strikes.

That is why incident management, resilience testing, recovery, and communication play a central role. Institutions must be able to detect, classify, and address incidents, and report them in serious cases. At the same time, backup, restart, and restore processes must be tested regularly.

What matters is not just that tests are conducted. What matters is what comes of them: findings must be documented, prioritized, and translated into concrete improvements.

In this way, the ability to provide evidence itself becomes the focus of control. Policies, exceptions, reviews, findings, decisions, and controls must be verifiable. Not because documentation is particularly appealing, but because without evidence, robust control cannot be achieved.

Third parties are becoming part of the resilience issue

DORA does not apply only to internal systems. Third-party ICT service providers and critical providers are also coming under greater scrutiny.

Contracts, provider management, exit strategies, and the Register of Information thus become practical building blocks of resilience. Companies must be able to identify which service providers are relevant for which functions and where critical dependencies arise.

This is particularly important because modern financial processes rarely take place entirely in-house. The cloud, platforms, software providers, and specialized service providers have long been part of day-to-day operations. If you don’t manage them properly, you’re failing to manage part of your own risk.

What Matters Now

When it comes to implementation, the goal is not to produce as many documents as possible. The key is to establish a viable operating model.

In practical terms, this means:

  • Clarify the scope and roles
  • Identify ICT Assets and Critical Dependencies
  • Consolidate Providers and the Register of Information
  • Implement Incident and Reporting Procedures
  • Planning Recovery and Switchover Tests
  • Prioritize and Track Findings
  • Establish Management Reporting and an Evidence Model

This isn't purely an IT task. Nor is it purely a legal project. DORA lies exactly where governance must become practical: at the intersection of IT, information security, compliance, risk management, business units, and management.

Conclusion

DORA is more than just IT security. DORA is an operational framework for management, control, and compliance in the financial sector's digital operations.

Those who view DORA merely as an additional regulatory requirement will, above all, generate more documentation. Those who view DORA as a governance task can build digital resilience in a more structured, verifiable, and management-friendly way.

K11 helps companies translate regulatory requirements into robust implementation programs—from embedding governance and conducting gap assessments to documentation, reporting channels, and management reporting.