Il Digital Operational Resilience Act (DORA) è entrato in vigore il 17 gennaio, introducendo linee guida esaustive e un quadro normativo dettagliato sulle modalità con cui tutti gli enti che prestano servizi finanziari nell’Unione europea devono garantire la resilienza dei dati di fronte a interruzioni impreviste.
La DORA riconosce inoltre una realtà ampiamente condivisa dai professionisti della sicurezza informatica, ovvero che non si tratta più di chiedersi se si verificherà un attacco informatico, ma quando. Questa normativa fondamentale introduce un nuovo livello di rigore e responsabilità nel settore dei servizi finanziari, che continuerà a evolversi per salvaguardare la stabilità dell’UE e dell’ecosistema finanziario globale.
Molti settori dell’industria dei servizi finanziari, oltre alle banche tradizionali e agli istituti di credito, rientrano ora nell’ambito di applicazione del DORA, tra cui i fornitori di servizi di pagamento, le società di investimento, le piattaforme di negoziazione, gli assicuratori e i fornitori terzi di servizi nel settore delle tecnologie dell’informazione e della comunicazione (TIC).
Those that are new to this level of regulation may struggle to comply, as indicated by European financial regulators’ DORA “Dry Run Exercise.”1 They also likely will face additional scrutiny by interconnected customers, partners and other stakeholders as a new operational risk. Non-compliance no longer means just the potential for a very large fine but also reputational damage and liability for a company, its directors, and its partners.
While it remains to be seen how quickly financial regulators act, DORA represents a shift from guidelines for data readiness and cyber resilience to enforcement of it. Given the expansive nature of DORA, which significantly broadens the EU’s financial regulation of IT, regulators, lacking unlimited expertise and resources, may face challenges enforcing all aspects of DORA immediately. As a result, regulators are likely to adopt a targeted approach, focusing on the most critical and visible areas of noncompliance.
Quali sono le priorità delle organizzazioni finanziarie
A top priority for DORA compliance is the submission of accurate and technically compliant registers of information. Financial regulators have emphasized that registers will be a primary focus of enforcement, and they expect organizations to submit them early in 2025. Submitting an accurate register that details the organization’s most significant IT providers may be more beneficial than submitting incomplete information about all of its IT providers.2
For data protection leaders and CIOs, DORA is a call to action to examine legacy systems and consider whether they are capable of withstanding today’s cyberthreats and can deliver the performance required for efficient, rapid service recovery.
Oltre a identificare e mappare i sistemi, le applicazioni e i carichi di lavoro chiave presso i rispettivi fornitori di servizi ICT, le organizzazioni dovrebbero valutare attentamente le capacità fondamentali che proteggono, difendono e ripristinano tali sistemi. Tra le capacità critiche figurano:
- Data protection and cyber recovery
informatico. Ai sensi del DORA, le capacità di Recovery rapido sono fondamentali per ridurre al minimo l’impatto operativo di un attacco. L’unico modo per raggiungere l’RTO più rigoroso e ultracorto richiesto per i sistemi critici è quello di effettuare il Recovery utilizzando snapshot immutabili basati su storage. Questi snapshot devono essere archiviati in modo sicuro in un repository isolato (o virtualmente “air-gapped”).
- Early-warning threat detection
Identifying and remediating potential cyberthreats earlier is an important aspect of data protection and readiness. The capability to continuously scan data to detect anomalies and identify threats like ransomware and malware in real time and automate remediation is essential for faster containment of an attack.
- Isolated recovery environments (IRE) or cleanrooms for resilience testing
Establishing a completely self-contained IRE, where data can be restored for forensic and application analysis and validated as clean before returning to production, speeds recovery. IREs also allow organizations to continuously test and improve cyber recovery practices for organizational readiness.
- Scalability and performance
Businesses will continue to evolve their services, face new regulatory requirements, and deal with emerging cyberthreats. It’s important to consider a solution’s ability to scale as data requirements change across distributed, hybrid environments while maintaining high-performance speeds for data protection and recovery.
Conformità con fiducia
Organizations that delay establishing robust capabilities to meet DORA and other evolving resilience regulations – such as PSD2, NIS2, APRA CPS 230, and the European Cyber Resilience Act coming into effect in 2026 – may find themselves with mounting challenges to overcome. They also may find themselves at competitive disadvantage to firms that can demonstrate their ability to remain resilient in the face of disruptions in the global financial ecosystem.
Working with partners that understand the regulation’s resilience requirements and deploying robust solutions can help enable organizations to be compliant and better prepared to meet new regulatory challenges and defend their data environment against emerging threats.
Pure Storage and Commvault have come together to build a joint solution, modular in design, that helps financial institutions enhance their cyber resilience practices and address key pillars of DORA for incident response and resilience testing. The solution is built by integrating the leading cyber resilience capabilities of Commvault® Cloud with the highly secure, high-performance Pure Storage platform. Learn more about the solution and our commitment to cyber resilience qui.
Sei pronto per la cibernetica?
Readiness reflects mature cyber resilience, where technology, people, and processes work seamlessly to enable continuous business in the face of any cyber challenge. Evaluate your organization’s cyber resilience with Commvault’s il Cyber Maturity Assessment.
1 Risultati principali dell’esercitazione di simulazione delle autorità di vigilanza europee (ESA) del 2024, Autorità bancaria europea, 17 dicembre 2024.
2 Countdown to DORA – Four Takeaway Points from Regulators’ December Statements, Skadden, Arps, Slate, Meagher & Flom, LLP, Jan. 3, 2025