
The European Union’s (EU) “Digital Operational Resilience Act” (DORA) is a new regulation designed to address growing cyber risks and thereby strengthen the resilience and security of financial services. It entered into force on January 16, 2023, and must be implemented by January 17, 2025. DORA applies to providers of information and communication technology (ICT) services that serve companies in the EU’s financial sector. ICT providers in Switzerland are also subject to DORA.
Pursuant to Article 2(1)(a)-(u) of DORA, the Regulation applies to the following financial institutions:
Credit institutions, payment institutions, account information service providers, investment firms, providers of crypto services, central securities depositories, central counterparties, trading venues, trade repositories, alternative investment fund managers, management companies, data provision services, insurance and reinsurance companies, insurance intermediaries, reinsurance intermediaries, occupational pension schemes, credit rating agencies, administrators of critical benchmarks, crowdfunding providers, securitization registries, and third-party ICT service providers.
DORA explicitly addresses ICT risks. It is intended to strengthen thedigitaloperational resilience of the entire European financial sector. In particular, DORA establishes rules for ICT risk management, incident reporting, operational resilience testing, third-party monitoring of ICT risks, agreements on information sharing, and cyber crisis and emergency drills.
In particular, DORA requires affected companies to systematically identify risks, implement protective and preventive measures, and detect and respond to incidents at an early stage. Recovery from incidents is also a key component of the requirements. Lessons should be learned from past incidents, and processes should be continuously improved and communicated transparently. For a financial institution, the obligations to be met might look something like this, for example:
An important aspect of DORA concerns the relationships between financial firms and ICT providers outside the EU, specifically in Switzerland. This aspect imposes relevant obligations on Swiss companies that collaborate with EU partners. Swiss companies must expect to face the following obligations:
Swiss companies operating in the financial sector are indirectly affected by DORA, particularly if they maintain business relationships with EU partners or operate subsidiaries and group companies in the EU. These companies must revise their internal policies and procedures for risk assessment and digital security to comply with DORA standards and meet regulatory requirements. DORA’s standards include, among other things, risk management, IT security requirements, risk management for third-party service providers, as well as training and awareness-raising (Art. 6 et seq. DORA). Specifically, this includes:
Risk management includes the obligation for companies to implement systematic procedures for identifying, assessing, and managing digital risks (Art. 6 DORA)
IT security requirements encompass measures to ensure the security of network and information systems, including the prevention and detection of cyber risks (Art. 9 DORA)
Risk management for third-party providers includes provisions for assessing and monitoring risks associated with the outsourcing of IT services and collaboration with third-party service providers (Art. 8(5) DORA)
Finally, the DORA stipulates that regular training and awareness-raising measures must be implemented for employees regarding digital security requirements and measures (Art. 13, para. 6, DORA).
DORA could also result in additional costs for Swiss companies, whether through investments in improved ICT systems and security measures or through employee training to ensure compliance. Companies that are unable to meet DORA’s requirements could face a competitive disadvantage, particularly compared to EU financial institutions that comply with the standards.
Overall, Swiss financial firms are facing regulatory adjustments and challenges as a result of DORA in order to meet the requirements for ICT risk management and digital security.
What are the consequences if companies or their IT service providers fail to implement the DORA requirements by the deadline (January 17, 2025) and the regulatory authorities discover this during their audits?
In such cases, the European Supervisory Authority may impose substantial fines of up to one percent of global daily revenue. In addition, financial institutions may be required to terminate contracts with service providers due to noncompliance with the requirements. This means that companies must always have alternative suppliers on hand to ensure the continuity of their services.
Under DORA, companies must take action in various areas. The first step should be a comprehensive assessment of their own DORA compliance. Often, companies already meet some of the new requirements, which is why a gap analysis is useful for identifying where action is needed. This analysis is part of the first set of measures in the Operational Resilience Framework. It involves reviewing and documenting current business processes and IT value chains. For example, companies should examine what impact the failure of a payment service provider would have on their ability to settle claims.
The second step of the framework focuses on cyber risk management. Here, the current level of IT and cyber maturity is first determined. This is followed by an assessment of vulnerability resulting from the integration of IT and operational technology (OT, which controls and monitors physical devices), always in relation to the core business, the identified value drivers, and relevant threat scenarios.
The third step focuses on IT service providers, the outsourcing of services, and the management of third-party risks. The goal is to ensure stable value chains, including documentation and controls. A contract registry of all service agreements (IT and non-IT) forms the basis for the governance framework. Resilience must also be ensured in environments with multiple providers and shared responsibility. The processes for managing incidents and the subsequent root cause analysis are coordinated.
What’s next? Swiss companies have until January 17, 2025, to implement DORA. In practice, companies often face typical hurdles on the path to DORA compliance. It is essential to ensure that the associated risks are adequately managed to guarantee timely implementation of DORA. It is particularly important to note that this regulation also applies to Swiss IT companies that offer their services to financial firms in Europe.
Do you have any questions about this topic, or would you like a personal consultation? Write to us—we’re happy to help.