Addressing Third-Party Blind Spots in DORA Compliance – Intelligent CISO

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

DORA Compliance: Ensuring Resilience and Swift Recovery in Financial Services

Veeam’s Andre Troskie on DORA Compliance: A Guard Against Cyber Threats

In the evolving landscape of cybersecurity, Andre Troskie, EMEA Field CISO at Veeam, emphasizes the vital role of DORA (Digital Operational Resilience Act) compliance for financial services organizations. While acknowledging that DORA compliance won’t eradicate all cyber threats, Troskie asserts it serves to enhance organizations’ readiness and their ability to recover swiftly from attacks.

The financial services sector, accustomed to stringent regulations, is generally ahead in compliance efforts compared to other industries. Many firms have been building their cybersecurity strength over years of adhering to strict standards. However, Troskie warns that DORA’s requirements extend beyond internal protocols to encompass third-party suppliers—a common area where organizations stumble during initial audits.

A recent EY survey underscores this concern, revealing that 98% of financial services organizations partner with third-party vendors, who can represent significant compliance risks. To meet DORA’s demands, institutions must reevaluate and often renegotiate Service Level Agreements (SLAs) with these providers. Troskie notes that achieving this will necessitate collaboration across security, risk management, and legal teams.

While DORA compliance alone won’t make organizations invulnerable to cyberattacks, it is a significant step toward operational resilience. By enhancing incident response plans and ensuring continuous alignment with DORA requirements across all partners, organizations can minimize downtime costs—previously reported at $152 million for the sector.

Ultimately, while compliance with DORA is not a panacea for cyber security, Troskie reiterates its importance in demonstrating preparedness and fostering recovery capabilities. Financial services organizations must prioritize DORA compliance and work collectively with their third-party vendors to avert severe repercussions associated with non-compliance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cyberattackers exploit AI hype with phishing campaigns impersonating platforms like ChatGPT and Claude

Recent research from Microsoft Threat Intelligence reveals a surge in cyberattacks leveraging the hype surrounding artificial intelligence (AI). Cybercriminals are increasingly impersonating well-known AI...

Apple launches 2026 device lineup featuring foldable iPhone Duo and new Apple Watch models.

Apple Launches 2026 Device Lineup with Foldable iPhone Duo Apple has officially unveiled its 2026 device portfolio, introducing a range of innovative products including the...

September 2026 Patch Tuesday Addresses 22 Critical Vulnerabilities in Microsoft Products

September 2026 Patch Tuesday: A Critical Update for Microsoft Products This month, Microsoft addressed a staggering 22 critical vulnerabilities across its product suite, with significant...

Sea Machines to supply autonomy kits under contract with U.S. Special Operations Forces

Sea Machines Robotics has secured a five-year Indefinite Delivery Indefinite Quantity (IDIQ) contract to provide its autonomy kits to U.S. Special Operations Forces (SOF). The...