DORA - Digital Operational Resilience Act
DORA, an EU regulation effective January 2025, sets requirements on financial firms for digital operational resilience and incident reporting.
Summary: EU Regulation (2022/2554) on digital operational resilience in the financial sector. Mandatory for 20 categories of financial firms as of January 17, 2025. Regulates ICT risk management, incident reporting, and resilience testing.
Sources & References
- [1] Verordnung (EU) 2022/2554 - DORA - Amtsblatt der Europäischen Union
- [2] EBA - DORA Technical Standards - European Banking Authority
- [3] BaFin - DORA Informationsseite - Bundesanstalt für Finanzdienstleistungsaufsicht
Questions about this topic?
Our experts advise you free of charge and without obligation.
About the Author
Dipl.-Math. (WWU Münster) and doctoral candidate at the Promotionskolleg NRW (Hochschule Rhein-Waal), researching phishing awareness, behavioral security and nudging in IT security. Responsible for building and maintaining ISMS, leads internal audits to ISO/IEC 27001:2022 and advises as an external information security officer (ISB) in KRITIS sectors. Lecturer for Communication Security at Hochschule Rhein-Waal and NIS2 training lead at isits AG.
3 Publikationen
- Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries (2025)
- Self-promotion with a Chance of Warnings: Exploring Cybersecurity Communication Among Government Institutions on LinkedIn (2024)
- Exploring the Effects of Cybersecurity Awareness and Decision-Making Under Risk (2024)