Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Dictionary
Dictionary
min read

DORA

DORA strengthens financial companies against digital threats

What is DORA?

DORA, or the Digital Operational Resilience Act, is an EU regulation designed to make financial companies better equipped to handle digital threats. It came into effect on January 17, 2025, ensuring that banks, insurance companies, investment firms, and other financial entities can manage and recover from IT issues, such as cyberattacks or system failures.

Think of DORA as a digital safety net that protects financial institutions and ensures they can continue to operate even during attacks or technical problems.

Requirements of DORA:

  • ICT risk management: Companies must have systems to identify and manage risks related to information technology. For example, a bank needs a plan to protect customer data from hacking.

  • Incident handling: Companies must have plans to detect, manage, and report IT incidents. If an insurance company discovers a data breach, they must have procedures to stop the attack and inform affected customers.

  • Resilience testing: Companies must regularly test their systems to ensure they can withstand digital attacks. An investment firm might simulate a cyberattack to see how their systems respond.

  • Third-party risk management: Companies must control risks arising from partnerships with other IT providers. A bank must ensure that its IT suppliers also have strong security measures.

  • Information sharing: Companies must share information about threats and incidents with other relevant parties. When a bank discovers a new type of malware, they should inform other banks about the threat.

Sicra and DORA

Sicra offers services that help financial entities meet the requirements of DORA. This includes vulnerability monitoring, incident handling, and infrastructure security to ensure the business can withstand and recover from digital threats.

Services:

Read more about "regulatory requirements and compliance" here >

Read more about "security testing" here >

Read more about "security monitoring and incident handling" here >

Related Terms: Artificial intelligence (AI), Artificial general intelligence (AGI), CISO-for-hire, Compliance, Cyber insurance, Cyber Kill Chain, Cybersecurity, Data breach, Expert systems (AI), GDPR, ISO/IEC27001, NIS2, NSM, Pentesting, Security classification, SOC, Zero Trust, SLA, Threat intelligence, Security audits, Machine learning (AI), Neural networks and deep learning (AI).

Need Assistance?

We are happy to have a non-binding conversation.

Contact us

Tailored cybersecurity for institutions and enterprises that allows for innovation, growth, and fearless performance.

Get in touchCall us +47 648 08 488
Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact

Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Rosenholmveien 25, 1414
Trollåsen. Norway

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
Sicra Footer Logo
Sicra © 2024
Privacy Policy