UK financial services firms are scrambling to comply with DORA regulations
Lack of prioritization and tight implementation schedules mean many aren’t compliant
More than four-in-ten UK financial services firms look set to miss the deadline for compliance with the new Digital Operational Resilience Act (DORA) tomorrow.
Companies failing to comply with the regulations could face fines of up to 2% of worldwide daily turnover for as long as six months.
However, while nearly nine-in-ten UK CISOs and senior security decision makers believe that DORA will be beneficial, 43% said they won’t be compliant for at least three months.
"The regulatory landscape in the EU is heavily congested with several overlapping standards and laws now in effect," said Richard Lindsay, principal advisory consultant at Orange Cyberdefense, which commissioned the research.
"There is a lot to navigate, and we’re increasingly seeing businesses taking a more reactive approach to compliance requirements once the threat of reprisals becomes tangible."
"However, remaining non-compliant could have severe ramifications, with fines of up to 2% of global annual turnover and the potential of fines of over €1m for individual senior leadership."
The challenges in implementation varied from organization to organization, but included a lack of prioritization, the short timeline involved, a lack of skills, and a lack of visibility over supply chain or third-party partners, each cited by around a quarter of respondents.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
To deal with these issues, virtually all said they planned to call on external support.
Budgetary constraints weren't highlighted as an issue, with 84% of respondents saying they had allocated funds ahead of the deadline. Around three-quarters have reallocated funding from other business areas, and around half have pulled in staff members from other projects.
In the longer term, though, two-thirds of CISOs and senior security decision makers believe that DORA will significantly increase cybersecurity costs.
The new regulations include more than 500 individual requirements, with businesses expected to implement essential protection, detection, containment, recovery, and repair measures.
RELATED WHITEPAPER
Rules contained in the legislation place a strong emphasis on ICT risk management, incident reporting, operational resilience testing, and oversight of ICT third-party risks.
PwC has estimated that more than 22,200 financial bodies and IT service providers fall under the scope of the act. However, the EU is expected to take a targeted approach to any breaches, focusing on larger players and significant breaches.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Broadcom eyes security, performance boosts with vDefend and Avi Load Balancer updatesNews Enhancements to VMware vDefend and VMware Avi Load Balancer use AI-powered automation to help secure private cloud environments
-
How business leaders are using the Dell Pro 7 and Dell Pro 5Sponsored Thanks to flexibility and a range of spec options, the Dell Pro 7 and Pro 5 laptops can suit a variety of business leaders across a mix of workplaces
-
Reports: UK could consider regulation amidst growing 'rogue AI' concernsNews New AI minister said regulation is on the table, but only if public safety is at risk from AI
-
Three things you need to know about the new EU AI Act rulesNews From this week, organizations operating in the EU have a new set of obligations around AI content and transparency
-
Startup founders lament 'regulatory friction' despite EU simplification effortsNews Entrepreneurs are spending a fortune on compliance, and it’s forcing some to consider relocating
-
SecurityHQ names Aaron Hambleton as VP of product and servicesNews Industry veteran will lead product and service innovation across the provider's cybersecurity portfolio
-
Big tech looks set to swerve AI regulations – at least for nowNews President Trump may be planning an executive order against AI regulation as the European Commission delays some aspects of AI Act
-
Empowered employees strengthen financial sector digital resilienceIndustry Insights Intelligent, bespoke employee cybersecurity training and awareness is critical for DORA compliance
-
Three things you need to know about the EU Data Act ahead of this week's big compliance deadlineNews A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack.
-
The second enforcement deadline for the EU AI Act is approaching – here’s what businesses need to know about the General-Purpose AI Code of PracticeNews General-purpose AI model providers will face heightened scrutiny