The financial sector faces growing threats to its stability as cyber threats, activists and climate-related disruptions intensify. According to the IBM Cost of a Data Breach Report 2024, the average cost of a breach in the financial industry has now reached $6.08m, 22% higher than the global average of $4.88m.
To respond to the challenge, The Digital Operational Resilience Act (DORA) came into effect in January, defining stringent standards that ensure resiliency across the finance sector. Applicable to institutions in the EU and non-EU companies providing services to EU financial firms, DORA stipulates multiple requirements including being prescriptive around ICT and cyber resilience.
Crucially, the regulation also stresses shared accountability. Banks and insurers are responsible for the preparedness of their third party suppliers, not just their own. This includes data center providers, and they must keep detailed records of their providers’ procedures and be ready to show evidence of risk mitigation measures. Therefore, as firms navigate DORA’s requirements, they need to consider both the security of the partners they work with as well as the tools that these partners can provide to help ensure resilience.
Risk management with data center providers
With responsibility shared between institutions and technology partners, DORA promotes a culture of proactive risk management to all stakeholders in the financial ecosystem. Compliance efforts must therefore involve close collaboration with critical suppliers, such as data center providers, as any operational failures within a data center could lead to financial services customers falling foul of the regulation. Consequently, data center operators with customers in the finance space must maintain secure, reliable and continuous services to meet DORA’s requirements, even in the face of disruptions.
To ensure their chosen data center provider can deliver on these needs, financial services firms must scrutinise the data center’s risk management and incident response strategies. In practical terms, this could involve running joint drills for cyber incident containment or ensuring reporting processes for security events are comparable. This can help finance firms to simplify potentially complex reporting requirements stipulated by the regulation.
Where cyber incidents do occur, firms are required under DORA to swiftly report to regulators the details of the breach and the root causes behind it. If reporting structures are simplified between the firm, its service providers and any other subcontractors involved, the relevant information can be relayed back to the regulator quickly and effectively.
Leveraging key tools for compliance
Close collaboration between third-party ICT providers, , and financial institutions serves to meet DORA’s audit standards, but the services and tools offered by providers can also enhance operational reliability for firms themselves.
For example, data centers operate secure environments. Physical barriers, biometric checks, CCTV and cyber security measures help to safeguard vital systems and keep sensitive financial data secure, enhancing risk management processes for DORA compliance.
Financial services firms can be reassured that redundant systems available in data centers operate with multiple power feeds and backup generators to ensure uninterrupted operations during power outages, equipment failures or other major incidents. Financial institutions can therefore avoid the risk of downtime and potential fines, which for non-compliance with DORA can be significant.
Further benefits arise from the scalable and distributed network connectivity offered by data center providers which can accommodate expanding traffic demands while retaining low-latency performance. This ensures financial institutions can deal effectively with peak transaction volumes during busy periods, maintain real-time data sharing and enable preparation for open finance initiatives.
Building a secure financial future
DORA represents a vital step in safeguarding the financial sector against modern threats. Fostering a culture of shared accountability and proactive risk management ensures that institutions and their technology partners are better prepared to address operational disruptions and regulatory demands. Collaboration with trusted data center providers plays a central role in meeting these requirements, enabling firms to leverage secure, scalable and resilient infrastructure to comply with DORA and mitigate risks effectively.
As financial organisations align their operations with DORA’s mandates, they can both enhance their ability to withstand immediate risks while at the same time laying the foundation to navigate future regulatory challenges. The integration of robust tools and trusted partnerships will position the financial sector for future resiliency.