The DORA (Digital Operational Resilience Act) regulation, issued at the end of 2022 and applied as of 17 January 2025, aims to generally increase digital resilience in the financial sector of the European Union.
It applies, following a principle of proportionality, to a range of organisations defined as “financial entities”, which includes, among others: credit institutions, payment institutions, crypto-asset service providers, insurance undertakings, insurance intermediaries, credit rating agencies.
Highlights
The first point on which DORA is based is ICT risk management. In this context, the recommendations follow the best practices already known in the sector. It starts with governance, with the request to financial entities to define policies that aim to assume and maintain high standards of ICT security: this can be achieved by assigning roles and responsibilities, creating business continuity strategies, audit plans, communication channels with ICT service providers and, of course, supplying adequate financial resources. From a technical point of view, these policies will necessarily include the identification of ICT assets and information assets, the creation of backup policies to support business continuity activities, as well as anomaly detection tools and staff training activities.
A second aspect concerns ICT-related incident management, classification and reporting. In this respect, guidelines have been created to classify ICT incidents in relation to the impact they can have on financial entities. Major incidents must therefore be reported to the competent authorities, who can use them to issue alerts and compile statistics, in order to assess the vulnerabilities and ICT threats to which the financial sector is subjected. Similarly, financial entities can report, on a voluntary basis, ICT threats that they believe are significant for the entire industry.
Subsequently, the regulation focuses on digital operational resilience tests. These include, mainly:
- Vulnerability scans
- OSINT analysis
- Network security assessment
- Physical security reviews
- Source code reviews
- Scenario-based testing
- Performance tests
- Penetration testing
DORA requires that these tests are preferably carried out by third parties, so as to ensure their independence, or at least that conflicts of interest are avoided. It is also necessary to define policies to prioritise corrective actions and ensure that the deficiencies identified during the tests are correctly addressed. As far as frequency is concerned, microenterprises have the freedom to carry out the tests by weighing, on the one hand, the resources and time that can be assigned to these activities, and on the other hand, the urgency and criticality of the information assets. The other financial entities must instead ensure that their ICT resources are tested at least annually.
In addition, with the exception of some exempt organizations, they must carry out TLPT (Thread-Led Penetration Test) activities at least every three years, unless otherwise provided by the national authorities. These tests are based on threat scenarios and are aimed at evaluating some or all essential functions, acting directly on the ICT resources supporting them and on production systems, applying criteria to mitigate the possible impacts on activities. If there are ICT services that support essential functions entrusted to third-party providers, they may also be included in the scope. If these have a potential impact on more than one financial entity, pooled tests are performed. At the end of the tests, the financial entities and the entities carrying out the tests draw up summaries of the results, containing the corrective plans and documentation of the tests carried out, which they send to the authorities in order to obtain a certificate of correct execution. The main guideline for TLPTs is TIBER-EU, which we have already discussed in this article. As indicated in TIBER-EU, the subjects in charge of carrying out the tests are preferably third parties and must have proven technical skills, with experience in the field of Red Team Assessment. In the same way, they must have a high reputation, through official certifications or the application of codes of ethics, ensuring proper management of data deriving from tests and professional insurance coverage.
A fourth point refers to the management of ICT third-party risk. Given the widespread need for financial entities to use ICT services from third-party providers, it is required that the relevant contracts be negotiated in such a way as to achieve minimum levels of performance and security, allowing them to be resolved in the event of deficiencies and violations.
The fifth, and last, topic concerns the same topic: the establishment of oversight authorities for critical ICT service providers. The oversight aims to identify suppliers that could have an impact on the stability of financial entities, and on which they depend for the proper performance of critical activities. Oversight authorities are responsible for investigating them, irrespective of them being located inside or outside the EU, requesting documentation and providing recommendations to improve their performance and security. If they find violations or delays in the implementation of the recommendations by suppliers, they also have the right to impose penalty payments.
How to facilitate DORA compliance with the ZAIUX Suite
The DORA regulation requires a rather regular execution of ICT security testing activities. These should be supported by advanced technologies in order to allow the staff in charge, whether internal or external, to ensure effectiveness, independence and a limited effort, both in terms of money and time. The ZAIUX Suite can be a valuable ally in the challenge of performing regular and accurate tests.
ZAIUX® Evo, the most realistic Breach & Attack Simulation platform, is able to test the resilience of Active Directory infrastructures to targeted and evasive attacks. It has an easy-to-use web interface, requires no specialized skills, and is fully automated, from the early enumeration stages to the generation of a report containing findings and recommendations for mitigation actions. It can therefore be a one-stop solution for Penetration Test activities, also thanks to a scalable licensing model that makes it convenient to perform repeated tests, so as to validate the application of corrective actions. Entities with less investment capacity can also benefit from ZAIUX Evo, using automation to reduce the typical costs of manual consulting without sacrificing the execution of in-depth tests, which go beyond a traditional Penetration Test.
The second product of the Suite is ZAIUX® Framework, an advanced Command-and-Control tool that allows a Red Team to perform TLPT tasks without having to worry about being detected by EDR and other defense systems. By leveraging ZAIUX Framework, operators are able to simulate a realistic attack from the outside, injecting malware into Windows and Linux machines, leveraging a range of ready-to-use functions and programming their own custom attack modules, coping with even the most advanced engagements.
The two solutions are also able to interact, allowing Red Teams to optimize their activities and obtain the maximum result with minimum effort, thus helping to make the financial sector, but not only, safer.
What are you waiting for?