In the first quarter of this year, the Digital Operational Resilience Act, or DORA (from English), will come into force in the European Union, which is expected to encourage all financial institutions to strengthen their cybersecurity. The financial sector will have almost two years to comply with the new rules, as DORA will start to be applied 24 months after it comes into force, during which every financial professional will need to review their IT systems and likely invest in new programs.
Investing in cybersecurity should pay off as, for example, banks, insurance companies, and investment funds should become much more resilient to potential attacks. The management of financial institutions will need to reset their thinking due to the new rules, as lawmakers say they will ‘have the task of strengthening their company’s resilience to unexpected digital disruptions, in a dynamic way that continuously responds to the evolution of threats and vulnerabilities.’ This is also expected from financial professionals in every EU member state to prevent and mitigate cyber threats, and each country will transpose them into its legislation.
At the same time, relevant European supervisory bodies such as the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA) will develop technical standards for all financial institutions that they must adhere to – from banking to insurance to asset management. Then, the task of enforcing regulations and compliance should be taken over by the appropriate national bodies.
