Skip to content
Alcuse.com
Menu
  • Home
  • Arts Entertainments
  • Auto
  • Business
  • Cryptocurrency
  • Digital Marketing
  • Education
  • Finance
  • Gaming
  • Health Fitness
  • Home Kitchen
  • Legal Law
  • Lifestyle Fashion
  • Medicine
  • Pets
  • Real Estate
  • Relationship
  • Shopping Product Reviews
  • Sports
  • Technology
  • Tours Travel
  • Privacy Policy
  • Contact US
  • Sitemap
Menu

Almost half of UK banks set to miss DORA deadline

Posted on January 16, 2025

Although they have had two years to prepare for the incoming legislation, a study has today revealed that a significant minority of UK financial services organisations are set to miss the 17 January 2025 deadline to comply with the European Union’s (EU’s) Digital Operational Resilience Act (DORA).

According to the Censuswide survey commissioned by Orange Cyberdefense, 43% of British financial services organisations say they are still exploring DORA and will not be compliant for another three months at least, putting them at significant risk of regulatory fines.

The 200 UK chief information security officers and cyber decision-makers polled on Orange’s behalf overwhelmingly believed DORA would be beneficial and would significantly enhance overall resilience across the EU and its wider ecosystem.

Yet barriers to compliance persist, with respondents to the survey describing a plethora of issues – most of them relating to their own organisation rather than the DORA legislation. Orange found these issues include a lack of prioritisation in the wider organisation (28%), a short timeline to becoming compliant (25%), a lack of specific skills and knowledge (24%), and a lack of visibility into supply chains and third-party partners (23%). To overcome these, 97% said they were considering enlisting external support.

Some 84% said they had been given enough or more than enough budget to become compliant, and a parallel study from Rubrik Zero Labs today reported that about 47% of UK financial services organisations had spent over €1m (£842,000) on compliance measures.

DORA doesn’t mandate anything by way of revolutionary requirements. Most can be addressed by investing in comprehensive cyber risk assessments, integrated incident reporting, cyber resilience testing and cross-framework governance
Richard Lindsay, Orange Cyberdefense

“The regulatory landscape in the EU is heavily congested, with several overlapping standards and laws now in effect. There is a lot to navigate, and we’re increasingly seeing businesses taking a more reactive approach to compliance requirements once the threat of reprisals becomes tangible,” said Richard Lindsay, principal advisory consultant at Orange Cyberdefense.

“However, remaining non-compliant could have severe ramifications, with fines of up to 2% of global annual turnover and the potential of fines of over €1m for individual senior leadership.

“The threat landscape has never been more volatile. The financial services industry is an attractive target for bad actors, and the likelihood of breach has never been higher. By implementing the required changes, businesses can avoid unwelcome fines and negative publicity and, most importantly, build resilience against digital threats,” Lindsay added.

“DORA doesn’t mandate anything by way of revolutionary requirements. Most can be addressed by investing in comprehensive cyber risk assessments, integrated incident reporting, cyber resilience testing and cross-framework governance. But, as is always the case in cyber security, the clock is ticking.”

Orange additionally noted that given the formal introduction of DORA comes just three months after the EU stood up the Network and Information Systems Directive 2 (NIS2) in October 2024, the need to address broader cyber compliance demands and overlapping requirements in both sets of regulations may explain why the majority of respondents are feeling positive about DORA, despite anticipating delays in achieving compliance.

What is DORA?

At its core, DORA aims to strengthen cyber security at financial services organisations and improve sector resilience across Europe. It harmonises operational resilience rules that apply to 20 different types of financial entities, such as banks, insurance companies and third-party tech suppliers.

According to Brussels, regulation such as DORA has become necessary because the financial services industry’s dependence on IT and the tech ecosystem makes it acutely vulnerable to cyber disruption, and if not managed properly this can spill over into the wider economy.

DORA governs a number of areas, such as IT risk management frameworks, third-party risk monitoring and oversight of suppliers, operational resilience testing, cyber incident reporting, and information and intelligence sharing.

Sonatype’s vice-president of solution architecture, Mitun Zavery, said: “If GDPR taught us anything, it was that last-minute compliance efforts lead to headaches and half-measures. Like many EU laws, UK companies may be pulled into scope as the act extends beyond European financial institutions and deep into their software supply chains.

“This is a big problem for UK businesses whose European customers fall under the regulation’s purview. The stern financial penalties for non-compliance are enough motivation for EU financial institutions to tell partners, ‘If you aren’t compliant, we need someone who is’.

He added: “Rather than a burden, UK organisations should see DORA as an opportunity to streamline systems and processes by leveraging automation, reinforcing their software supply chains, and adopting a proactive approach to risk mitigation and vulnerability management. If DORA becomes like GDPR, then prioritising compliance now will open doors as forms of this standard are adopted in the UK.”

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • What should I expect from a Sexual harassment lawyer consultation?
  • What are the benefits of software composition analysis tools?
  • What is natural justice in unjust dismissal Canada?
  • Can users find factories on global sources website?
  • 구글 검색 누락 카페24도 생기나요?
  • 음식은 강남달토에서 빨리 나오는 편이야?
  • 강남 가라오케 중심가예요?
  • 강남호빠는 처음 가는 사람에게 추천되나요?
  • What questions should I ask an employment lawyer Toronto?
  • Can the TikTok API improve content strategy?
  • Is commercial energy management worth the investment in Bermuda Dunes CA?
  • Decen Masters: Crowdsourcing Alpha in an Automated World
  • Can a Locksmith near me install window security locks?
  • What is the cost of gutters installation?
  • Does termination pay apply to executive-level employees?
  • 해외스포츠중계는 스마트 TV에서 볼 수 있나요?
  • 무료 스포츠중계 사이트 오류 잦나요?
  • 오피 계약 해지 시 중개수수료는 어떻게 되나요?
  • Is transportation included with a Curacao jetski tour?
  • How is the EV charging industry supporting fleet electrification?

Archives

  • July 2026
  • May 2026
  • April 2026
  • March 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Arts Entertainments
  • Auto
  • Business
  • Cryptocurrency
  • Digital Marketing
  • Education
  • Finance
  • Gaming
  • Health Fitness
  • Home Kitchen
  • Legal Law
  • Lifestyle Fashion
  • Medicine
  • Pets
  • Real Estate
  • Relationship
  • Shopping Product Reviews
  • Sports
  • Technology
  • Tours Travel
Slot gacor hari ini
Slot online
TOTO SLOT
Slot
©2026 Alcuse.com | Design: Newspaperly WordPress Theme