La loi sur la résilience opérationnelle numérique (DORA) est entrée en vigueur le 17 janvier. Elle prévoit des lignes directrices exhaustives et un cadre réglementaire détaillé régissant la manière dont toutes les entités du secteur des services financiers exerçant leurs activités dans l’Union européenne doivent assurer la résilience de leurs données face à des perturbations imprévues.
La loi DORA reconnaît également une réalité largement admise par les professionnels de la cybersécurité, à savoir qu’il ne s’agit plus de savoir si une cyberattaque aura lieu, mais quand. Cette législation cruciale apporte un nouveau niveau de rigueur et de responsabilité au secteur des services financiers, qui continuera à évoluer afin de préserver la stabilité de l’écosystème financier de l’Union européenne et du monde entier.
De nombreux secteurs du secteur des services financiers, au-delà des banques traditionnelles et des établissements de crédit, relèvent désormais du champ d’application de la DORA, notamment les prestataires de services de paiement, les entreprises d’investissement, les plateformes de négociation, les assureurs et les prestataires tiers de services liés aux technologies de l’information et de la communication (TIC).
Those that are new to this level of regulation may struggle to comply, as indicated by European financial regulators’ DORA “Dry Run Exercise.”1 They also likely will face additional scrutiny by interconnected customers, partners and other stakeholders as a new operational risk. Non-compliance no longer means just the potential for a very large fine but also reputational damage and liability for a company, its directors, and its partners.
While it remains to be seen how quickly financial regulators act, DORA represents a shift from guidelines for data readiness and cyber resilience to enforcement of it. Given the expansive nature of DORA, which significantly broadens the EU’s financial regulation of IT, regulators, lacking unlimited expertise and resources, may face challenges enforcing all aspects of DORA immediately. As a result, regulators are likely to adopt a targeted approach, focusing on the most critical and visible areas of noncompliance.
Les priorités des établissements financiers
A top priority for DORA compliance is the submission of accurate and technically compliant registers of information. Financial regulators have emphasized that registers will be a primary focus of enforcement, and they expect organizations to submit them early in 2025. Submitting an accurate register that details the organization’s most significant IT providers may be more beneficial than submitting incomplete information about all of its IT providers.2
For data protection leaders and CIOs, DORA is a call to action to examine legacy systems and consider whether they are capable of withstanding today’s cyberthreats and can deliver the performance required for efficient, rapid service recovery.
Au-delà de l’identification et de la cartographie des systèmes, applications et charges de travail clés auprès de leurs fournisseurs TIC respectifs, les organisations doivent examiner attentivement les capacités essentielles qui permettent de protéger, de défendre et de restaurer ces systèmes. Parmi ces capacités essentielles, on peut citer :
- Data protection and cyber recovery
après sinistre informatique : dans le cadre de la directive DORA, il est essentiel de disposer de capacités de reprise rapide afin de minimiser l’impact opérationnel d’une attaque. La seule façon d’atteindre le RTO (délai de reprise des opérations) ultra-court et extrêmement strict requis pour les systèmes critiques consiste à effectuer la reprise à l’aide de snapshots immuables basés sur le stockage. Ces snapshots doivent être stockés en toute sécurité dans un référentiel isolé (ou virtuellement « air-gapped »).
- Early-warning threat detection
Identifying and remediating potential cyberthreats earlier is an important aspect of data protection and readiness. The capability to continuously scan data to detect anomalies and identify threats like ransomware and malware in real time and automate remediation is essential for faster containment of an attack.
- Isolated recovery environments (IRE) or cleanrooms for resilience testing
Establishing a completely self-contained IRE, where data can be restored for forensic and application analysis and validated as clean before returning to production, speeds recovery. IREs also allow organizations to continuously test and improve cyber recovery practices for organizational readiness.
- Scalability and performance
Businesses will continue to evolve their services, face new regulatory requirements, and deal with emerging cyberthreats. It’s important to consider a solution’s ability to scale as data requirements change across distributed, hybrid environments while maintaining high-performance speeds for data protection and recovery.
La conformité en toute confiance
Organizations that delay establishing robust capabilities to meet DORA and other evolving resilience regulations – such as PSD2, NIS2, APRA CPS 230, and the European Cyber Resilience Act coming into effect in 2026 – may find themselves with mounting challenges to overcome. They also may find themselves at competitive disadvantage to firms that can demonstrate their ability to remain resilient in the face of disruptions in the global financial ecosystem.
Working with partners that understand the regulation’s resilience requirements and deploying robust solutions can help enable organizations to be compliant and better prepared to meet new regulatory challenges and defend their data environment against emerging threats.
Pure Storage and Commvault have come together to build a joint solution, modular in design, that helps financial institutions enhance their cyber resilience practices and address key pillars of DORA for incident response and resilience testing. The solution is built by integrating the leading cyber resilience capabilities of Commvault® Cloud with the highly secure, high-performance Pure Storage platform. Learn more about the solution and our commitment to cyber resilience ici.
Êtes-vous prêts pour l’informatique ?
Readiness reflects mature cyber resilience, where technology, people, and processes work seamlessly to enable continuous business in the face of any cyber challenge. Evaluate your organization’s cyber resilience with Commvault’s l’évaluation de la maturité cybernétique.
1 Principales conclusions de l’exercice de simulation des AES de 2024, Autorité bancaire européenne, 17 décembre 2024.
2 Countdown to DORA – Four Takeaway Points from Regulators’ December Statements, Skadden, Arps, Slate, Meagher & Flom, LLP, Jan. 3, 2025