It’s over a year since DORA’s application date, this article opens our DORA insight series. It sets out the five capabilities every financial services firm needs to demonstrate under DORA. Over the forthcoming weeks Cyberfort security and compliance experts will explore each pillar in depth giving their insights, thoughts and recommendations for security professionals who are responsible for implementing and managing this regulatory standard in their organisation.
Most financial services firms are not starting their DORA journey from a position of weakness. They already have security teams, incident response processes, supplier oversight, testing programmes and governance forums. What DORA has done is expose the gap between having these capabilities and being able to demonstrate that they work consistently, under pressure, and with board-level accountability.
That distinction matters because DORA is not a technology regulation. It is an operational resilience regulation.
Regulators are not asking whether an organisation owns the right tools. They are asking whether it can prove it understands its ICT risks, responds effectively to disruption, manages third-party dependencies, tests resilience in a meaningful way, and contributes to the wider resilience of the financial services ecosystem.
Organisations that approach DORA as a compliance exercise will almost certainly produce an
unnecessary large quantity of documentation. Organisations that get the greatest value from it will use it as an opportunity to build lasting operational resilience capabilities.
Across all the conversations with financial services firms at Cyberfort over the past year, one consistent theme emerges. Success under DORA is not determined by individual controls or isolated projects. It is determined by five interconnected organisational capabilities.
Capability 1: ICT Risk Management
Everything starts with governance. Most firms can demonstrate strong operational security controls; vulnerability management, monitoring, asset inventories, incident response plans. What is often harder to demonstrate is how ICT risk is effectively governed, owned and managed at board level.
DORA places direct responsibility on senior leadership for the management of ICT risk. That means organisations need more than technical capability. They need a documented framework that explains:
- How ICT risks are identified and assessed
- How risk appetite is defined and approved
- Who owns material risks
- How mitigation activities are tracked
- How the board receives and acts upon risk information
The key question is not “do we manage ICT risks?” It is “can we demonstrate how the organisation makes risk decisions, and prove those decisions align with documented and accepted business risk tolerances?” Without that foundation, every other DORA capability becomes significantly harder to sustain.
Capability 2: Incident Detection, Classification and Reporting
Most firms are relatively good at detecting incidents. The challenge is what happens next.
DORA’s requirements go beyond identifying suspicious activity or responding to technical events. Organisations must be able to classify incidents consistently, assess their severity accurately, determine cross-border and regulatory significance, and report major incidents against a genuinely tight clock – an initial notification within hours of classification, followed by further reports within days and weeks.
This is where many organisations discover that their existing incident processes were designed to support operational response rather than regulatory decision-making. An incident bridge call might successfully coordinate technical remediation, but can it determine severity using documented criteria, assess cross-border relevance, demonstrate why a classification decision was made, and produce an auditable record of root cause and remediation?
The difference between detection and classification is often where the greatest DORA related gap exists. Building a repeatable and defensible incident classification process is one of the most valuable investments financial services firms can make.
Capability 3: Operational Resilience Testing
Testing is not new. What DORA changes is the purpose of testing.
Traditional security testing often focuses on systems, applications or infrastructure. DORA shifts attention towards the resilience of critical and important business services. The key question becomes – can this service continue to operate during a realistic disruptive event?
Answering that requires more than vulnerability scans and penetration tests. Organisations must understand which systems support critical functions, which third parties those functions depend upon, how failures could propagate across services, and whether resilience assumptions have actually been validated under realistic scenarios.
For a sub-set of larger, designated organisations, this also means Threat-Led Penetration Testing. For every organisation in scope of DORA, it means moving beyond testing technology in isolation and towards testing business resilience as a whole. In many ways, testing is where assumptions become evidence.
Capability 4: Third-Party Risk Management
Few financial services organisations operate independently. Critical functions increasingly rely on cloud providers, managed service providers, software vendors and complex supply chains, and DORA recognises that operational resilience cannot exist if third-party dependencies remain poorly understood.
Most firms already have supplier management processes. The challenge is gaining visibility into critical supplier dependencies, concentration risk, fourth-party exposure, contractual obligations and exit readiness.
A supplier register can tell you who your providers are. A resilience-focused third-party risk programme tells you what happens if one of them fails. That distinction is becoming increasingly important as regulators place greater emphasis on systemic risk and concentration within the financial services technology ecosystem.
Capability 5: Information and Intelligence Sharing
The final capability is often the most misunderstood. Many organisations view threat intelligence as something they consume. DORA encourages organisations to view intelligence sharing as something they actively participate in – contributing to, and benefiting from, sector-wide resilience initiatives.
The rationale is straightforward. No individual financial services firm has complete visibility of the threat landscape. Attackers routinely target multiple organisations using similar techniques, dependencies and infrastructure. Sharing intelligence helps firms identify threats faster, improve detection capabilities and strengthen resilience across the sector.
The most mature organisations establish formal processes for consuming threat intelligence, feeding it into detection and testing activities, sharing appropriate indicators and insights, and maintaining audit trails of participation. The result is not simply compliance. It is a stronger collective defence capability.
Why these capabilities matter together
It is tempting to treat DORA’s pillars as separate workstreams. In reality, they are closely connected. A risk management framework informs incident classification. Incident data helps shape resilience testing. Testing identifies third-party dependencies. Third-party risks influence governance decisions. Threat intelligence improves every stage of the process.
The organisations making the greatest progress are not building five separate programmes. They are building one operational resilience capability that integrates and embeds governance, response, testing, supplier oversight and intelligence sharing into a single operating model.
Final thoughts
The most important question for financial services leaders one year into DORA is not whether they are compliant today. It is whether their organisation could confidently demonstrate resilience tomorrow.
The firms that succeed will be those that move beyond documentation and focus on capability: governance that can withstand scrutiny, incident processes that work under pressure, testing that reflects real-world threats, supplier oversight that reveals hidden dependencies, and intelligence sharing that strengthens both the organisation and the wider sector.
DORA provides the framework. The challenge, and the opportunity, is turning that framework into resilience that can be demonstrated, measured and relied upon when it matters most.
In this DORA series
Over the next five articles, we go deeper into each of these capabilities in turn:
- ICT Risk Management: building board-owned governance and risk oversight.
- Incident Management and Reporting: creating consistent and defensible incident classification.
- Digital Operational Resilience Testing: proving resilience through realistic testing.
- ICT Third-Party Risk Management: managing concentration risk and supplier dependency.
- Information and Intelligence Sharing: strengthening resilience through collaboration and shared insight.
For more information about Cyberfort’s DORA compliance and operational resilience services, contact us at [email protected] and one of our experts will be in touch.





















