CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Quantum Technologies

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Banca Ifis

Laura Quaroni, Head of Privacy & Security

DORA: A New Era for Cyber Security

On 16 January 2023, the DORA Regulation came into force; the Digital Operational Resilience Act (DORA regulation) aims to consolidate and harmonize the main cybersecurity requirements at the European level with reference to digital operational resilience in the financial sector, addressing banks, insurance companies, cryptocurrency service companies, financial institutions and their critical suppliers.

The regulation affects a wide range of corporate subjects and will be binding starting from 17 January 2025 (24 months after its publication in the Official Journal of the European Union). By that date, banks, insurance companies and cryptocurrency operators will have to adapt their cyber security safeguards.

The DORA Regulation is in force; it is advisable to plan and start an adaptation process.

All actors falling within the scope of the DORA Regulation must prepare to implement the regulation, developing or updating their own incident reporting procedures in line with the new regulatory requirements.

The regulation presents various ‘pillars’ that companies will have to consider, and in particular in the area of governance and internal organization, ICT risk management, incident management, and ICT supplier management.

Financial entities will have to adopt internal cybersecurity governance and a control system such as to guarantee effective and prudent management of all ICT risks in order to achieve a high level of digital operational resilience. They will also need to have a structured, comprehensive and well-documented cyber risk management framework in place.

Numerous provisions have been introduced regarding the management of incidents related to ICT services. In particular, regarding the reporting of related incidents, financial entities will have to establish and implement a management process to monitor and record ICT related incidents, classify them and report them to the competent authorities.

In order to mitigate the risks deriving from the dependence of financial entities on third-party service providers, specific supervisory powers are envisaged to be conferred on the financial supervisory authorities.

Financial entities will have to adopt internal cybersecurity governance and a control system such to guarantee effective and prudent management of all ICT risks in order to achieve a high level of digital operational resilience.

Therefore, in addition to providing a Europe-wide surveillance framework for third-party providers of critical ICT services, key contractual aspects will be harmonized to ensure that financial firms monitor third-party cyber risks. Furthermore, to ensure adequate monitoring of technology service providers that perform a critical function for the functioning of the financial sector, a ‘lead’ supervisory authority will be defined for each critical third-party ICT service provider. Therefore,the DORA Regulation is particularly onerous even for the suppliers of critical services to these companies.

It is true that the latest report of the World Economic Forum (Global Security Outlook 2023) warns companies against third-party risk in the geopolitical context since the latest known incidents have heavily involved the supply chain.

In full awareness of the opportunities that the DORA Regulation offers,Banca IFIS has launched a regulatory impact analysis, envisaging a multidisciplinary team that involves resources from various internal functions,technical and organizational, legal and control functions. This path aims to accelerate the evolution of models and tools in order to ensure compliance with applicable regulations in force (Supervisory Regulations, DORA, etc.), to the definition of a sustainable path towards compliance, based on adaptation logic progressive, to the prioritization of interventions, also on the basis of initiatives in progress in the cyber security field.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://quantum-technologies.cioapplicationseurope.com/leadership-perspective/dora-a-new-era-for-cyber-security-nid-3417.html