{"id":1475,"date":"2025-07-20T11:57:08","date_gmt":"2025-07-20T11:57:08","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/07\/20\/most-european-financial-firms-still-lagging-on-dora-compliance\/"},"modified":"2025-07-20T11:57:08","modified_gmt":"2025-07-20T11:57:08","slug":"most-european-financial-firms-still-lagging-on-dora-compliance","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/07\/20\/most-european-financial-firms-still-lagging-on-dora-compliance\/","title":{"rendered":"Most European Financial Firms Still Lagging on DORA Compliance"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/32483240-27a8-4f36-ac60-9d465c05a5d5.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of James Coker\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Most European financial services organizations are still not meeting requirements set out in the EU\u2019s Digital Operational Resilience Act (DORA), six months after the law came into effect.<\/p>\n<p>This is according to research by Veeam, which found that 96% of financial companies it surveyed in this region believe their current level of data resilience falls short of DORA compliance.<\/p>\n<p>Financial services firms also reported facing significant unforeseen challenges around DORA compliance. Nearly half (41%) said their IT and security teams have faced increased stress and pressure as a result of the regulation, while 37% are dealing with higher costs passed on by ICT vendors.<\/p>\n<p>In addition, 20% have yet to secure the necessary budget to meet DORA requirements.<\/p>\n<p>Over a fifth (22%) of respondents felt that DORA\u2019s design could have been improved to assist compliance, such as improved simplification, clarification and more detailed third-party risk guidance.<\/p>\n<p>DORA officially entered into force on January 17, 2025. The legislation places new cyber resilience requirements on financial services organizations, including banks, insurance and investment companies. Third-party IT providers within the financial industry are also in scope.<\/p>\n<p>While DORA is an EU law, it also applies to many global organizations that operate in the region.<\/p>\n<p>Regulators have the power to impose huge penalties for non-compliance, up to 2% of global annual turnover or \u20ac10m ($11.6m), whichever is higher.<\/p>\n<p>Third-party organizations may also face fines of up to 1% of their average daily global turnover for each day of non-compliance, for up to six months.<\/p>\n<p><em>Read now: DORA Compliance Costs Soar Past \u20ac1m for Many UK and EU Businesses<\/em><\/p>\n<h2><strong>Third-Party Risk Management the Biggest Challenge<\/strong><\/h2>\n<p>Third-party risk oversight was viewed as the hardest DORA requirement to implement, cited by 34% of respondents. This is likely as a result of the vast number of third-party networks used in the financial services industry.<\/p>\n<p>A fifth (20%) said they still have not implemented DORA-compliant third-party risk oversight.<\/p>\n<p>Many organizations reported still being in the process of implementing other key DORA requirements, including:<\/p>\n<ul>\n<li>Recovery and continuity testing (24%)<\/li>\n<li>Incident reporting processes (24%)<\/li>\n<li>Appointing a DORA implementation lead (24%)<\/li>\n<li>Digital operational resilience testing (23%)<\/li>\n<li>Backup integrity and secure data recovery (21%)<\/li>\n<\/ul>\n<h2><strong>DORA Now a Top Organizational Priority<\/strong><\/h2>\n<p>The study, published on July 17, found that 94% of organizations now rank DORA compliance higher in their organizational priorities than they did in the month before the rules came into effect.<\/p>\n<p>Additionally, 40% described DORA as a \u201ctop digital resilience priority,\u201d while half said that requirements have been integrated into their broader resilience programs.<\/p>\n<p>Andre Troskie, Field CISO EMEA at Veeam, commented: \u201cOf course, meeting the requirements is key, but DORA was also about getting organizations to assess their resilience holistically \u2013 and in that aspect, it seems to be succeeding.\u201d<\/p>\n<p>The Veeam study surveyed 404 senior IT decision makers or heads of compliance at financial service companies with over 500 employees across the UK, France, Germany and the Netherlands.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Most European financial services organizations are still not meeting requirements set out in the EU\u2019s Digital Operational Resilience Act (DORA), six months after the law came into effect. This is according to research by Veeam, which found that 96% of financial companies it surveyed in this region believe their current level of data resilience falls<\/p>\n","protected":false},"author":2,"featured_media":1476,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1475","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1475-e75b4809-37e8-40ec-9ffc-68a99c80f654-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/1475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=1475"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/1475\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/1476"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=1475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=1475"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=1475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}